Kontrola logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Kontrola logu
prosil bych o kontrolu logu.
Dekuji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Klášter at 2014-01-03 23:27:16
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 370 GB (78%) free of 477 GB
Total RAM: 1961 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:27:21, on 3.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\ViewPower\ViewPower.exe
C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\trend micro\Klášter.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Klášter\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: ViewPower.lnk = C:\Program Files (x86)\ViewPower\ViewPower.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: Viewpower - Acresso - C:\PROGRA~2\VIEWPO~1\TOMCAT~1.EXE
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8866 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\SysWow64\IntelCpHeciSvc.exe
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\viakaraokesrv.exe
C:\PROGRA~2\VIEWPO~1\TOMCAT~1.EXE -zglaxservice Viewpower
"C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe" -Xms25165824 -Xmx134217728 -Xrs -classpath "C:\Program Files (x86)\ViewPower\jre\lib\catalina-ha.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-data-req.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jsr80.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina-ant.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-logging.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\spring-beans.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\SNMP-Network.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\console.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\derby.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\AdventNetLogging.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jaxen-full.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jamod-1.2-SNAPSHOT.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\concurrent.jar;C:\Program Files (x86)\ViewPower\jre\lib\jsp-api.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-dbcp.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\mail.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\snmp4j-1.11.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\cfdataservicesadapter.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\backport-util-concurrent.jar;C:\Program Files (x86)\ViewPower\jre\lib\servlet-api.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-juli.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\dom4j-1.6.1.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\AdventNetSnmp.jar;C:\Program Files (x86)\ViewPower\jre\lib\annotations-api.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-acrobat.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-httpclient-3.0.1.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\log4j-1.2.14.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\saxpath.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-opt.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\spring-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\cfgatewayadapter.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\RXTXcomm.jar;C:\Program Files (x86)\ViewPower\jre\lib\el-api.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-lang.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-proxy.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper-el.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\viewpower.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jaxp.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-data.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-remoting.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-codec-1.3.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-i18n-es.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\snmp4j-1.11-javadoc.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-coyote.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper-jdt.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina-tribes.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\acrobat-core-charset.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\acrobat-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-common.jar;C:\Program Files (x86)\ViewPower\lax.jar;" com.zerog.lax.LAX "C:/Program Files (x86)/ViewPower/TomcatWrapper.lax" "C:/Windows/TEMP/lax98F4.tmp"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-2a5c0287-7294-4452-8702-e34e3505d43f -SystemEventPortName:HostProcess-eaead8de-14e9-40bf-93cc-2365da61e3b9 -IoCancelEventPortName:HostProcess-7ae8ac4f-b85e-4572-b0dc-2c3400238e8f -NonStateChangingEventPortName:HostProcess-6e455028-4163-419a-84a3-f118a6f8bf52 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:3d45d0a9-199e-4feb-9323-e8a1f9b15c46 -DeviceGroupId:WpdFsGroup
"taskhost.exe"
taskeng.exe {7A4E561F-00BF-4D6E-8A6A-9571A0449085}
taskeng.exe {EC1FAA77-1433-40AE-90F3-E7E46CFB1EFE}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe" /auto
"C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe" /STARTUP
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe"
C:\Windows\Explorer.EXE
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
"C:\Windows\SysWOW64\rundll32.exe" "C:\Users\Klášter\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
"C:\Program Files (x86)\ViewPower\ViewPower.exe"
"C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe" -classpath "C:\Program Files (x86)\ViewPower\jre\lib\catalina-ha.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-data-req.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jsr80.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina-ant.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-logging.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\spring-beans.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\SNMP-Network.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\console.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\derby.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\AdventNetLogging.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jaxen-full.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jamod-1.2-SNAPSHOT.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\concurrent.jar;C:\Program Files (x86)\ViewPower\jre\lib\jsp-api.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-dbcp.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\mail.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\snmp4j-1.11.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\cfdataservicesadapter.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\backport-util-concurrent.jar;C:\Program Files (x86)\ViewPower\jre\lib\servlet-api.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-juli.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\dom4j-1.6.1.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\AdventNetSnmp.jar;C:\Program Files (x86)\ViewPower\jre\lib\annotations-api.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-acrobat.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-httpclient-3.0.1.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\log4j-1.2.14.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\saxpath.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-opt.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\spring-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\cfgatewayadapter.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\RXTXcomm.jar;C:\Program Files (x86)\ViewPower\jre\lib\el-api.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-lang.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-proxy.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper-el.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\viewpower.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jaxp.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-data.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-remoting.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-codec-1.3.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-i18n-es.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\snmp4j-1.11-javadoc.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-coyote.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper-jdt.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina-tribes.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\acrobat-core-charset.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\acrobat-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-common.jar;C:\Program Files (x86)\ViewPower\lax.jar;" com.zerog.lax.LAX "C:/Program Files (x86)/ViewPower/ViewPower.lax" "C:/Users/Klášter/AppData/Local/Temp/laxDD91.tmp"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /systemstart /autostart
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\Klášter\Documents\Michal\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\Driver Booster Update.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "extensions.enabledItems" - "{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.25"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll
C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\extensions\
adsremoval@adsremoval.net
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-12-30 1372864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-12-30 1372864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-07-12 6308736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-12-30 1138536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-12-30 1372864]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-12-30 1372864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-12-30 1138536]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-11-07 171992]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-11-07 399832]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-11-07 442328]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]
"NextLive"=C:\Windows\SysWOW64\rundll32.exe [2009-07-14 44544]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2011-04-06 3024896]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"IObit Malware Fighter"=C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [2013-12-13 1573184]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-12-30 3764024]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
ViewPower.lnk - C:\Program Files (x86)\ViewPower\ViewPower.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-11-07 442880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-01-03 22:52:44 ----D---- C:\Program Files\trend micro
2014-01-03 22:52:42 ----D---- C:\rsit
2014-01-03 22:38:25 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-01-03 22:33:35 ----D---- C:\Windows\Migration
2013-12-30 17:13:14 ----D---- C:\IObit
2013-12-30 13:18:30 ----A---- C:\Windows\system32\drivers\aswstm.sys
2013-12-29 15:51:30 ----D---- C:\Users\Klášter\AppData\Roaming\newnext.me
2013-12-29 15:50:19 ----D---- C:\Program Files (x86)\Seznam.cz
2013-12-29 15:50:00 ----D---- C:\Users\Klášter\AppData\Roaming\Seznam.cz
2013-12-13 03:05:04 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-13 03:05:04 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-13 03:05:04 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-13 03:05:02 ----A---- C:\Windows\system32\wmp.dll
2013-12-13 03:03:21 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-12-13 03:03:20 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-13 03:03:20 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-13 03:03:20 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-13 03:03:20 ----A---- C:\Windows\system32\ieui.dll
2013-12-13 03:03:19 ----A---- C:\Windows\system32\ieUnatt.exe
2013-12-13 03:03:19 ----A---- C:\Windows\system32\iesetup.dll
2013-12-13 03:03:19 ----A---- C:\Windows\system32\iernonce.dll
2013-12-13 03:03:19 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-12-13 03:03:19 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-12-13 03:03:19 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-13 03:03:17 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-12-13 03:03:17 ----A---- C:\Windows\system32\mshtml.dll
2013-12-13 03:03:17 ----A---- C:\Windows\system32\jscript9diag.dll
2013-12-13 03:03:16 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-12-13 03:03:16 ----A---- C:\Windows\system32\ieapfltr.dll
2013-12-13 03:03:15 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-13 03:03:15 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-13 03:03:15 ----A---- C:\Windows\system32\wininet.dll
2013-12-13 03:03:15 ----A---- C:\Windows\system32\iertutil.dll
2013-12-13 03:03:14 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-13 03:03:14 ----A---- C:\Windows\system32\urlmon.dll
2013-12-13 03:03:13 ----A---- C:\Windows\system32\ieframe.dll
2013-12-13 03:03:12 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-13 03:03:11 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-13 03:03:10 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-13 03:03:10 ----A---- C:\Windows\system32\jscript9.dll
2013-12-12 17:01:07 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-12 17:01:07 ----A---- C:\Windows\system32\msieftp.dll
2013-12-12 17:01:06 ----A---- C:\Windows\system32\win32k.sys
2013-12-12 17:01:04 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-12 17:01:04 ----A---- C:\Windows\system32\tzres.dll
2013-12-12 17:00:55 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-12 17:00:55 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-12 17:00:54 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-12 17:00:54 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-12 17:00:53 ----A---- C:\Windows\system32\drivers\portcls.sys
2013-12-12 17:00:53 ----A---- C:\Windows\system32\drivers\drmk.sys
2013-12-12 17:00:52 ----A---- C:\Windows\system32\scrrun.dll
2013-12-12 17:00:52 ----A---- C:\Windows\system32\cscript.exe
2013-12-12 17:00:51 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-12 17:00:51 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-12 17:00:51 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-12 17:00:51 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 06:09:13 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2013-12-04 03:07:17 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-12-04 03:03:42 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-12-04 03:03:42 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\url.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-12-04 03:03:35 ----A---- C:\Windows\system32\elshyph.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\wextract.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\webcheck.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\vbscript.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\url.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\pngfilt.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\occache.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msrating.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msls31.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\mshtmler.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\mshtmled.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\mshta.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msfeedssync.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msfeeds.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\licmgr10.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\jsIntl.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\jscript.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\inseng.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\imgutil.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\iexpress.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\iesysprep.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\iepeers.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\iedkcs32.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\ieapfltr.dat
2013-12-04 03:03:34 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\icardie.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\dxtrans.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\dxtmsft.dll
======List of files/folders modified in the last 1 month======
2014-01-03 23:27:20 ----D---- C:\Windows\Temp
2014-01-03 23:25:15 ----RD---- C:\Program Files (x86)
2014-01-03 23:24:36 ----D---- C:\Windows\system32\config
2014-01-03 23:23:33 ----A---- C:\Windows\SYSWOW64\log.txt
2014-01-03 23:22:04 ----D---- C:\Windows
2014-01-03 23:21:00 ----D---- C:\Windows\System32
2014-01-03 23:18:56 ----D---- C:\Windows\inf
2014-01-03 22:52:44 ----RD---- C:\Program Files
2014-01-03 22:43:19 ----SHD---- C:\Windows\Installer
2014-01-03 22:43:18 ----HD---- C:\Config.Msi
2014-01-03 22:43:14 ----D---- C:\Windows\Microsoft.NET
2014-01-03 22:41:14 ----RSD---- C:\Windows\assembly
2014-01-03 22:39:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-01-03 22:38:25 ----D---- C:\Windows\SysWOW64
2014-01-03 22:34:48 ----D---- C:\Windows\SYSWOW64\en-US
2014-01-03 22:34:48 ----D---- C:\Windows\system32\en-US
2014-01-03 22:33:35 ----SD---- C:\ProgramData\Microsoft
2014-01-03 22:28:28 ----D---- C:\Windows\system32\drivers
2014-01-03 22:28:15 ----D---- C:\Windows\system32\catroot
2014-01-03 22:28:09 ----D---- C:\Windows\system32\DriverStore
2014-01-03 22:26:42 ----SHD---- C:\System Volume Information
2014-01-03 22:20:37 ----D---- C:\Windows\SoftwareDistribution
2014-01-03 22:13:27 ----D---- C:\Windows\system32\Tasks
2014-01-03 16:11:30 ----D---- C:\Windows\Tasks
2014-01-02 08:40:14 ----D---- C:\Windows\Prefetch
2014-01-01 22:39:54 ----D---- C:\Windows\system32\catroot2
2014-01-01 22:35:45 ----D---- C:\Windows\debug
2013-12-30 13:17:50 ----A---- C:\Windows\system32\aswBoot.exe
2013-12-30 12:03:13 ----D---- C:\ProgramData\ProductData
2013-12-21 00:11:36 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-12-16 03:03:03 ----D---- C:\Windows\system32\MRT
2013-12-16 03:01:36 ----A---- C:\Windows\system32\MRT.exe
2013-12-14 05:50:02 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2013-12-13 04:01:18 ----D---- C:\Windows\rescache
2013-12-13 03:23:26 ----D---- C:\Windows\winsxs
2013-12-13 03:21:23 ----D---- C:\Program Files\Windows Media Player
2013-12-13 03:21:23 ----D---- C:\Program Files\Internet Explorer
2013-12-13 03:21:23 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-13 03:21:23 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-13 03:21:22 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-13 03:21:22 ----D---- C:\Windows\system32\cs-CZ
2013-12-13 03:04:40 ----D---- C:\ProgramData\Microsoft Help
2013-12-11 16:18:44 ----D---- C:\Users\Klášter\AppData\Roaming\Skype
2013-12-11 06:09:22 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-12-05 23:14:35 ----D---- C:\Windows\Panther
2013-12-05 23:14:35 ----D---- C:\Windows\Logs
2013-12-04 03:22:53 ----D---- C:\Windows\SYSWOW64\migration
2013-12-04 03:22:52 ----D---- C:\Windows\system32\migration
2013-12-04 03:22:52 ----D---- C:\Windows\PolicyDefinitions
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-10-24 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-12-30 207904]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-05-22 17720]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-10-24 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-12-30 1034464]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-12-30 422216]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-12-30 78648]
R3 aswStm;aswStm; \??\C:\Windows\system32\drivers\aswStm.sys [2013-12-30 79672]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-11-07 5363200]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-12-28 76912]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2011-03-29 2157680]
S3 FileMonitor;FileMonitor; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2013-03-23 23048]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2013-02-10 19456]
S3 RegFilter;RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2013-11-19 34848]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-02-10 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2013-02-10 30208]
S3 UrlFilter;UrlFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [2013-11-19 23016]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 winusb;Služba WinUSB; C:\Windows\system32\DRIVERS\WinUSB.SYS [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-12-30 50344]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
R2 IMFservice;IMF Service; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2013-11-11 341824]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-22 326168]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2011-03-29 27760]
R2 Viewpower;Viewpower; C:\PROGRA~2\VIEWPO~1\TOMCAT~1.EXE [2011-10-10 116224]
R3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-11-07 279000]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-23 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11 257416]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-23 136176]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-10-05 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Dekuji
Logfile of random's system information tool 1.09 (written by random/random)
Run by Klášter at 2014-01-03 23:27:16
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 370 GB (78%) free of 477 GB
Total RAM: 1961 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:27:21, on 3.1.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\ViewPower\ViewPower.exe
C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\trend micro\Klášter.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKCU\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
O4 - HKCU\..\Run: [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Klášter\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: ViewPower.lnk = C:\Program Files (x86)\ViewPower\ViewPower.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 7 (AdvancedSystemCareService7) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: Viewpower - Acresso - C:\PROGRA~2\VIEWPO~1\TOMCAT~1.EXE
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 8866 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\SysWow64\IntelCpHeciSvc.exe
"C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\viakaraokesrv.exe
C:\PROGRA~2\VIEWPO~1\TOMCAT~1.EXE -zglaxservice Viewpower
"C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe" -Xms25165824 -Xmx134217728 -Xrs -classpath "C:\Program Files (x86)\ViewPower\jre\lib\catalina-ha.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-data-req.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jsr80.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina-ant.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-logging.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\spring-beans.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\SNMP-Network.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\console.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\derby.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\AdventNetLogging.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jaxen-full.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jamod-1.2-SNAPSHOT.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\concurrent.jar;C:\Program Files (x86)\ViewPower\jre\lib\jsp-api.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-dbcp.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\mail.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\snmp4j-1.11.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\cfdataservicesadapter.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\backport-util-concurrent.jar;C:\Program Files (x86)\ViewPower\jre\lib\servlet-api.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-juli.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\dom4j-1.6.1.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\AdventNetSnmp.jar;C:\Program Files (x86)\ViewPower\jre\lib\annotations-api.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-acrobat.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-httpclient-3.0.1.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\log4j-1.2.14.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\saxpath.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-opt.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\spring-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\cfgatewayadapter.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\RXTXcomm.jar;C:\Program Files (x86)\ViewPower\jre\lib\el-api.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-lang.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-proxy.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper-el.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\viewpower.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jaxp.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-data.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-remoting.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-codec-1.3.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-i18n-es.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\snmp4j-1.11-javadoc.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-coyote.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper-jdt.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina-tribes.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\acrobat-core-charset.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\acrobat-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-common.jar;C:\Program Files (x86)\ViewPower\lax.jar;" com.zerog.lax.LAX "C:/Program Files (x86)/ViewPower/TomcatWrapper.lax" "C:/Windows/TEMP/lax98F4.tmp"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-2a5c0287-7294-4452-8702-e34e3505d43f -SystemEventPortName:HostProcess-eaead8de-14e9-40bf-93cc-2365da61e3b9 -IoCancelEventPortName:HostProcess-7ae8ac4f-b85e-4572-b0dc-2c3400238e8f -NonStateChangingEventPortName:HostProcess-6e455028-4163-419a-84a3-f118a6f8bf52 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:3d45d0a9-199e-4feb-9323-e8a1f9b15c46 -DeviceGroupId:WpdFsGroup
"taskhost.exe"
taskeng.exe {7A4E561F-00BF-4D6E-8A6A-9571A0449085}
taskeng.exe {EC1FAA77-1433-40AE-90F3-E7E46CFB1EFE}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe" /auto
"C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe" /STARTUP
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe"
C:\Windows\Explorer.EXE
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
"C:\Windows\SysWOW64\rundll32.exe" "C:\Users\Klášter\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
"C:\Program Files (x86)\ViewPower\ViewPower.exe"
"C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe" -classpath "C:\Program Files (x86)\ViewPower\jre\lib\catalina-ha.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-data-req.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jsr80.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina-ant.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-logging.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\spring-beans.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\SNMP-Network.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\console.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\derby.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\AdventNetLogging.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jaxen-full.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jamod-1.2-SNAPSHOT.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\concurrent.jar;C:\Program Files (x86)\ViewPower\jre\lib\jsp-api.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-dbcp.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\mail.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\snmp4j-1.11.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\cfdataservicesadapter.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\backport-util-concurrent.jar;C:\Program Files (x86)\ViewPower\jre\lib\servlet-api.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-juli.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\dom4j-1.6.1.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\AdventNetSnmp.jar;C:\Program Files (x86)\ViewPower\jre\lib\annotations-api.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-acrobat.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-httpclient-3.0.1.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\log4j-1.2.14.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\saxpath.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-opt.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\spring-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\cfgatewayadapter.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\RXTXcomm.jar;C:\Program Files (x86)\ViewPower\jre\lib\el-api.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-lang.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-proxy.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper-el.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\viewpower.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\jaxp.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-data.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-remoting.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\commons-codec-1.3.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-i18n-es.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\snmp4j-1.11-javadoc.jar;C:\Program Files (x86)\ViewPower\jre\lib\tomcat-coyote.jar;C:\Program Files (x86)\ViewPower\jre\lib\jasper-jdt.jar;C:\Program Files (x86)\ViewPower\jre\lib\catalina-tribes.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\acrobat-core-charset.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\acrobat-core.jar;C:\Program Files (x86)\ViewPower\WebContent\WEB-INF\lib\flex-messaging-common.jar;C:\Program Files (x86)\ViewPower\lax.jar;" com.zerog.lax.LAX "C:/Program Files (x86)/ViewPower/ViewPower.lax" "C:/Users/Klášter/AppData/Local/Temp/laxDD91.tmp"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe" /systemstart /autostart
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\Klášter\Documents\Michal\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\Driver Booster Update.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "extensions.enabledItems" - "{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.25"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.9.900.170 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll
C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\extensions\
adsremoval@adsremoval.net
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-12-30 1372864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-12-30 1372864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-07-12 6308736]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-12-30 1138536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-12-30 1372864]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2013-12-30 1372864]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2013-12-30 1138536]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2013-11-07 171992]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2013-11-07 399832]
"Persistence"=C:\Windows\system32\igfxpers.exe [2013-11-07 442328]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 7"=C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2013-10-28 2283296]
"NextLive"=C:\Windows\SysWOW64\rundll32.exe [2009-07-14 44544]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2011-04-06 3024896]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04 958576]
"IObit Malware Fighter"=C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [2013-12-13 1573184]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-12-30 3764024]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]
C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
ViewPower.lnk - C:\Program Files (x86)\ViewPower\ViewPower.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2013-11-07 442880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-01-03 22:52:44 ----D---- C:\Program Files\trend micro
2014-01-03 22:52:42 ----D---- C:\rsit
2014-01-03 22:38:25 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-01-03 22:33:35 ----D---- C:\Windows\Migration
2013-12-30 17:13:14 ----D---- C:\IObit
2013-12-30 13:18:30 ----A---- C:\Windows\system32\drivers\aswstm.sys
2013-12-29 15:51:30 ----D---- C:\Users\Klášter\AppData\Roaming\newnext.me
2013-12-29 15:50:19 ----D---- C:\Program Files (x86)\Seznam.cz
2013-12-29 15:50:00 ----D---- C:\Users\Klášter\AppData\Roaming\Seznam.cz
2013-12-13 03:05:04 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2013-12-13 03:05:04 ----A---- C:\Windows\SYSWOW64\wmp.dll
2013-12-13 03:05:04 ----A---- C:\Windows\system32\wmploc.DLL
2013-12-13 03:05:02 ----A---- C:\Windows\system32\wmp.dll
2013-12-13 03:03:21 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2013-12-13 03:03:20 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2013-12-13 03:03:20 ----A---- C:\Windows\SYSWOW64\ieui.dll
2013-12-13 03:03:20 ----A---- C:\Windows\system32\jsproxy.dll
2013-12-13 03:03:20 ----A---- C:\Windows\system32\ieui.dll
2013-12-13 03:03:19 ----A---- C:\Windows\system32\ieUnatt.exe
2013-12-13 03:03:19 ----A---- C:\Windows\system32\iesetup.dll
2013-12-13 03:03:19 ----A---- C:\Windows\system32\iernonce.dll
2013-12-13 03:03:19 ----A---- C:\Windows\system32\ieetwproxystub.dll
2013-12-13 03:03:19 ----A---- C:\Windows\system32\ieetwcollector.exe
2013-12-13 03:03:19 ----A---- C:\Windows\system32\ie4uinit.exe
2013-12-13 03:03:17 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2013-12-13 03:03:17 ----A---- C:\Windows\system32\mshtml.dll
2013-12-13 03:03:17 ----A---- C:\Windows\system32\jscript9diag.dll
2013-12-13 03:03:16 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2013-12-13 03:03:16 ----A---- C:\Windows\system32\ieapfltr.dll
2013-12-13 03:03:15 ----A---- C:\Windows\SYSWOW64\wininet.dll
2013-12-13 03:03:15 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2013-12-13 03:03:15 ----A---- C:\Windows\system32\wininet.dll
2013-12-13 03:03:15 ----A---- C:\Windows\system32\iertutil.dll
2013-12-13 03:03:14 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2013-12-13 03:03:14 ----A---- C:\Windows\system32\urlmon.dll
2013-12-13 03:03:13 ----A---- C:\Windows\system32\ieframe.dll
2013-12-13 03:03:12 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2013-12-13 03:03:11 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2013-12-13 03:03:10 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2013-12-13 03:03:10 ----A---- C:\Windows\system32\jscript9.dll
2013-12-12 17:01:07 ----A---- C:\Windows\SYSWOW64\msieftp.dll
2013-12-12 17:01:07 ----A---- C:\Windows\system32\msieftp.dll
2013-12-12 17:01:06 ----A---- C:\Windows\system32\win32k.sys
2013-12-12 17:01:04 ----A---- C:\Windows\SYSWOW64\tzres.dll
2013-12-12 17:01:04 ----A---- C:\Windows\system32\tzres.dll
2013-12-12 17:00:55 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2013-12-12 17:00:55 ----A---- C:\Windows\system32\imagehlp.dll
2013-12-12 17:00:54 ----A---- C:\Windows\SYSWOW64\WMPhoto.dll
2013-12-12 17:00:54 ----A---- C:\Windows\system32\WMPhoto.dll
2013-12-12 17:00:53 ----A---- C:\Windows\system32\drivers\portcls.sys
2013-12-12 17:00:53 ----A---- C:\Windows\system32\drivers\drmk.sys
2013-12-12 17:00:52 ----A---- C:\Windows\system32\scrrun.dll
2013-12-12 17:00:52 ----A---- C:\Windows\system32\cscript.exe
2013-12-12 17:00:51 ----A---- C:\Windows\SYSWOW64\wscript.exe
2013-12-12 17:00:51 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2013-12-12 17:00:51 ----A---- C:\Windows\SYSWOW64\cscript.exe
2013-12-12 17:00:51 ----A---- C:\Windows\system32\wscript.exe
2013-12-11 06:09:13 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2013-12-04 03:07:17 ----A---- C:\Windows\system32\IEUDINIT.EXE
2013-12-04 03:03:42 ----A---- C:\Windows\SYSWOW64\elshyph.dll
2013-12-04 03:03:42 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\wextract.exe
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\url.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\msrating.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\msls31.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\jsIntl.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\inseng.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\icardie.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2013-12-04 03:03:35 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2013-12-04 03:03:35 ----A---- C:\Windows\system32\elshyph.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\occache.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\mshta.exe
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\jscript.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2013-12-04 03:03:34 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\wextract.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\webcheck.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\vbscript.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\url.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\pngfilt.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\occache.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msrating.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msls31.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\mshtmlmedia.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\mshtmler.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\mshtmled.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\MshtmlDac.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\mshta.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msfeedssync.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msfeedsbs.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\msfeeds.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\licmgr10.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\jsIntl.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\jscript.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\inseng.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\imgutil.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\iexpress.exe
2013-12-04 03:03:34 ----A---- C:\Windows\system32\iesysprep.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\iepeers.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\iedkcs32.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\ieapfltr.dat
2013-12-04 03:03:34 ----A---- C:\Windows\system32\IEAdvpack.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\icardie.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\dxtrans.dll
2013-12-04 03:03:34 ----A---- C:\Windows\system32\dxtmsft.dll
======List of files/folders modified in the last 1 month======
2014-01-03 23:27:20 ----D---- C:\Windows\Temp
2014-01-03 23:25:15 ----RD---- C:\Program Files (x86)
2014-01-03 23:24:36 ----D---- C:\Windows\system32\config
2014-01-03 23:23:33 ----A---- C:\Windows\SYSWOW64\log.txt
2014-01-03 23:22:04 ----D---- C:\Windows
2014-01-03 23:21:00 ----D---- C:\Windows\System32
2014-01-03 23:18:56 ----D---- C:\Windows\inf
2014-01-03 22:52:44 ----RD---- C:\Program Files
2014-01-03 22:43:19 ----SHD---- C:\Windows\Installer
2014-01-03 22:43:18 ----HD---- C:\Config.Msi
2014-01-03 22:43:14 ----D---- C:\Windows\Microsoft.NET
2014-01-03 22:41:14 ----RSD---- C:\Windows\assembly
2014-01-03 22:39:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-01-03 22:38:25 ----D---- C:\Windows\SysWOW64
2014-01-03 22:34:48 ----D---- C:\Windows\SYSWOW64\en-US
2014-01-03 22:34:48 ----D---- C:\Windows\system32\en-US
2014-01-03 22:33:35 ----SD---- C:\ProgramData\Microsoft
2014-01-03 22:28:28 ----D---- C:\Windows\system32\drivers
2014-01-03 22:28:15 ----D---- C:\Windows\system32\catroot
2014-01-03 22:28:09 ----D---- C:\Windows\system32\DriverStore
2014-01-03 22:26:42 ----SHD---- C:\System Volume Information
2014-01-03 22:20:37 ----D---- C:\Windows\SoftwareDistribution
2014-01-03 22:13:27 ----D---- C:\Windows\system32\Tasks
2014-01-03 16:11:30 ----D---- C:\Windows\Tasks
2014-01-02 08:40:14 ----D---- C:\Windows\Prefetch
2014-01-01 22:39:54 ----D---- C:\Windows\system32\catroot2
2014-01-01 22:35:45 ----D---- C:\Windows\debug
2013-12-30 13:17:50 ----A---- C:\Windows\system32\aswBoot.exe
2013-12-30 12:03:13 ----D---- C:\ProgramData\ProductData
2013-12-21 00:11:36 ----D---- C:\Program Files (x86)\Mozilla Firefox
2013-12-16 03:03:03 ----D---- C:\Windows\system32\MRT
2013-12-16 03:01:36 ----A---- C:\Windows\system32\MRT.exe
2013-12-14 05:50:02 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2013-12-13 04:01:18 ----D---- C:\Windows\rescache
2013-12-13 03:23:26 ----D---- C:\Windows\winsxs
2013-12-13 03:21:23 ----D---- C:\Program Files\Windows Media Player
2013-12-13 03:21:23 ----D---- C:\Program Files\Internet Explorer
2013-12-13 03:21:23 ----D---- C:\Program Files (x86)\Windows Media Player
2013-12-13 03:21:23 ----D---- C:\Program Files (x86)\Internet Explorer
2013-12-13 03:21:22 ----D---- C:\Windows\SYSWOW64\cs-CZ
2013-12-13 03:21:22 ----D---- C:\Windows\system32\cs-CZ
2013-12-13 03:04:40 ----D---- C:\ProgramData\Microsoft Help
2013-12-11 16:18:44 ----D---- C:\Users\Klášter\AppData\Roaming\Skype
2013-12-11 06:09:22 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2013-12-05 23:14:35 ----D---- C:\Windows\Panther
2013-12-05 23:14:35 ----D---- C:\Windows\Logs
2013-12-04 03:22:53 ----D---- C:\Windows\SYSWOW64\migration
2013-12-04 03:22:52 ----D---- C:\Windows\system32\migration
2013-12-04 03:22:52 ----D---- C:\Windows\PolicyDefinitions
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2013-10-24 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2013-12-30 207904]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2013-05-22 17720]
R1 aswRdr;aswRdr; \??\C:\Windows\system32\drivers\aswRdr2.sys [2013-10-24 92544]
R1 aswSnx;aswSnx; \??\C:\Windows\system32\drivers\aswSnx.sys [2013-12-30 1034464]
R1 aswSP;aswSP; \??\C:\Windows\system32\drivers\aswSP.sys [2013-12-30 422216]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2013-12-30 78648]
R3 aswStm;aswStm; \??\C:\Windows\system32\drivers\aswStm.sys [2013-12-30 79672]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2013-11-07 5363200]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2010-12-28 76912]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2011-03-29 2157680]
S3 FileMonitor;FileMonitor; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [2013-03-23 23048]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2011-08-17 19968]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2013-02-10 19456]
S3 RegFilter;RegFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [2013-11-19 34848]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-02-10 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2013-02-10 30208]
S3 UrlFilter;UrlFilter; \??\C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [2013-11-19 23016]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-21 32768]
S3 winusb;Služba WinUSB; C:\Windows\system32\DRIVERS\WinUSB.SYS [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-10 65640]
R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [2013-10-25 878368]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-12-30 50344]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
R2 IMFservice;IMF Service; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [2013-11-11 341824]
R2 LiveUpdateSvc;LiveUpdate; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2013-10-25 2151200]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-22 326168]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2011-03-29 27760]
R2 Viewpower;Viewpower; C:\PROGRA~2\VIEWPO~1\TOMCAT~1.EXE [2011-10-10 116224]
R3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2013-11-07 279000]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-23 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-09-05 171680]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11 257416]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-23 136176]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2013-11-26 111616]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-10-05 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Re: Kontrola logu
Zdravim
Odinstalujte Advanced SystemCare , Malware Fighter a nasledne i vse od IOBit - jsou to cinske smejdy a spise jen skodi nez jsou uzitkem. Hledaji nesmyslne a neexistujici problemy, databazi haveti ukradli jine renomovane spolecnosti
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Re: Kontrola logu
Ony zmíněné programy jež mám odstranit z kompu jsou škodlivé?
Můžu provést druhý a třetí krok dle vašich instrukcí a přitom ponechat ony produkty ("čínské šmejdy"
) od IOBit?
Můžu provést druhý a třetí krok dle vašich instrukcí a přitom ponechat ony produkty ("čínské šmejdy"
Re: Kontrola logu
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Re: Kontrola logu
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.9 (01.01.2014:1)
OS: Windows 7 Home Premium x64
Ran by Kl çter on so 04.01.2014 at 10:29:32,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?
Value Name Type Value Data
========================================================================================
NextLive REG_SZ C:\Windows\SysWOW64\rundll32.exe "C:\Users\Kl çter\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\search settings
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1698764807-163466282-1135287668-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\applications\ilividsetup.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilivid_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilivid_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividmediabar_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividmediabar_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividsetup_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\setupdatamngr_searchqu_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\setupdatamngr_searchqu_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetim_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetim_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\search results toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\ilividsrtb
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\Users\Kl çter\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Program Files (x86)\Common Files\spigot"
~~~ FireFox
Successfully deleted: [File] C:\Users\Kl çter\AppData\Roaming\mozilla\firefox\profiles\roivx0lz.default\user.js
Successfully deleted the following from C:\Users\Kl çter\AppData\Roaming\mozilla\firefox\profiles\roivx0lz.default\prefs.js
user_pref("extensions.toolbar.mindspark._65Members_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=undefined&n=77fcdd40&ptnrS=Y6xpi000YY");
user_pref("extensions.toolbar.mindspark._65Members_.initialized", true);
user_pref("extensions.toolbar.mindspark._65Members_.installation.contextKey", "");
user_pref("extensions.toolbar.mindspark._65Members_.installation.installDate", "2013060416");
user_pref("extensions.toolbar.mindspark._65Members_.installation.partnerId", "Y6xpi000YY");
user_pref("extensions.toolbar.mindspark._65Members_.installation.partnerSubId", "");
user_pref("extensions.toolbar.mindspark._65Members_.installation.success", false);
user_pref("extensions.toolbar.mindspark._65Members_.installation.toolbarId", "undefined");
user_pref("extensions.toolbar.mindspark._65Members_.options.defaultSearch", false);
user_pref("extensions.toolbar.mindspark._65Members_.options.homePageEnabled", false);
user_pref("extensions.toolbar.mindspark._65Members_.options.keywordEnabled", false);
user_pref("extensions.toolbar.mindspark._65Members_.options.tabEnabled", false);
user_pref("extensions.toolbar.mindspark._65Members_.weather.location", "10001");
user_pref("extensions.toolbar.mindspark.lastInstalled", "fromdoctopdf@mindspark.com");
user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.mode.debug", "false");
user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
user_pref("sweetim.toolbar.previous.browser.search.defaulturl", "");
user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
user_pref("sweetim.toolbar.previous.browser.startup.homepage", "kl");
user_pref("sweetim.toolbar.previous.keyword.URL", "chrome://browser-region/locale/region.properties");
user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://sear
user_pref("sweetim.toolbar.search.history.capacity", "10");
user_pref("sweetim.toolbar.searchguard.enable", "true");
user_pref("sweetim.toolbar.simapp_id", "{1C131539-1103-11E1-A384-8C89A528B400}");
user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?barid={1C131539-1103-11E1-A384-8C89A528B400}");
user_pref("sweetim.toolbar.version", "1.3.0.1");
Emptied folder: C:\Users\Kl çter\AppData\Roaming\mozilla\firefox\profiles\roivx0lz.default\minidumps [73 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 04.01.2014 at 10:36:19,39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.9 (01.01.2014:1)
OS: Windows 7 Home Premium x64
Ran by Kl çter on so 04.01.2014 at 10:29:32,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Suspicious HKCU\..\Run entries found. Trojan:JS/Medfos.B?
Value Name Type Value Data
========================================================================================
NextLive REG_SZ C:\Windows\SysWOW64\rundll32.exe "C:\Users\Kl çter\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\search settings
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1698764807-163466282-1135287668-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\applications\ilividsetup.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\au__rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilivid_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilivid_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividmediabar_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividmediabar_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\ilividsetup_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\setupdatamngr_searchqu_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\setupdatamngr_searchqu_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetim_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetim_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\sweetimsetup_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\search results toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\ilividsrtb
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_format-factory_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\Users\Kl çter\appdata\locallow\datamngr"
Successfully deleted: [Folder] "C:\Program Files (x86)\Common Files\spigot"
~~~ FireFox
Successfully deleted: [File] C:\Users\Kl çter\AppData\Roaming\mozilla\firefox\profiles\roivx0lz.default\user.js
Successfully deleted the following from C:\Users\Kl çter\AppData\Roaming\mozilla\firefox\profiles\roivx0lz.default\prefs.js
user_pref("extensions.toolbar.mindspark._65Members_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=undefined&n=77fcdd40&ptnrS=Y6xpi000YY");
user_pref("extensions.toolbar.mindspark._65Members_.initialized", true);
user_pref("extensions.toolbar.mindspark._65Members_.installation.contextKey", "");
user_pref("extensions.toolbar.mindspark._65Members_.installation.installDate", "2013060416");
user_pref("extensions.toolbar.mindspark._65Members_.installation.partnerId", "Y6xpi000YY");
user_pref("extensions.toolbar.mindspark._65Members_.installation.partnerSubId", "");
user_pref("extensions.toolbar.mindspark._65Members_.installation.success", false);
user_pref("extensions.toolbar.mindspark._65Members_.installation.toolbarId", "undefined");
user_pref("extensions.toolbar.mindspark._65Members_.options.defaultSearch", false);
user_pref("extensions.toolbar.mindspark._65Members_.options.homePageEnabled", false);
user_pref("extensions.toolbar.mindspark._65Members_.options.keywordEnabled", false);
user_pref("extensions.toolbar.mindspark._65Members_.options.tabEnabled", false);
user_pref("extensions.toolbar.mindspark._65Members_.weather.location", "10001");
user_pref("extensions.toolbar.mindspark.lastInstalled", "fromdoctopdf@mindspark.com");
user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.mode.debug", "false");
user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "");
user_pref("sweetim.toolbar.previous.browser.search.defaulturl", "");
user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "");
user_pref("sweetim.toolbar.previous.browser.startup.homepage", "kl");
user_pref("sweetim.toolbar.previous.keyword.URL", "chrome://browser-region/locale/region.properties");
user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://sear
user_pref("sweetim.toolbar.search.history.capacity", "10");
user_pref("sweetim.toolbar.searchguard.enable", "true");
user_pref("sweetim.toolbar.simapp_id", "{1C131539-1103-11E1-A384-8C89A528B400}");
user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?barid={1C131539-1103-11E1-A384-8C89A528B400}");
user_pref("sweetim.toolbar.version", "1.3.0.1");
Emptied folder: C:\Users\Kl çter\AppData\Roaming\mozilla\firefox\profiles\roivx0lz.default\minidumps [73 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 04.01.2014 at 10:36:19,39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Re: Kontrola logu
# AdwCleaner v3.016 - Report created 04/01/2014 at 10:39:01
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Klášter - KLÁŠTER-PC
# Running from : C:\Users\Klášter\Klášter\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
[#] Folder Deleted : C:\ProgramData\Browser Manager
Folder Deleted : C:\Program Files (x86)\FromDocToPDF_65
Folder Deleted : C:\Users\Klášter\AppData\Local\FromDocToPDF_65
Folder Deleted : C:\Users\Klášter\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\SweetIMToolbarData
Folder Deleted : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Folder Deleted : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Folder Deleted : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Folder Deleted : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{612AD33D-9824-4E87-8396-92374E91C4BB}
Key Deleted : [x64] HKLM\SOFTWARE\DataMngr
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Mozilla Firefox v26.0 (cs)
[ File : C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\prefs.js ]
Line Deleted : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.yahoo.com/*\" param=\"[...]
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [3526 octets] - [04/01/2014 10:38:10]
AdwCleaner[S0].txt - [3495 octets] - [04/01/2014 10:39:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3555 octets] ##########
# Updated 23/12/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Klášter - KLÁŠTER-PC
# Running from : C:\Users\Klášter\Klášter\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
[#] Folder Deleted : C:\ProgramData\Browser Manager
Folder Deleted : C:\Program Files (x86)\FromDocToPDF_65
Folder Deleted : C:\Users\Klášter\AppData\Local\FromDocToPDF_65
Folder Deleted : C:\Users\Klášter\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\SweetIMToolbarData
Folder Deleted : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Folder Deleted : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Folder Deleted : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Folder Deleted : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{612AD33D-9824-4E87-8396-92374E91C4BB}
Key Deleted : [x64] HKLM\SOFTWARE\DataMngr
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Mozilla Firefox v26.0 (cs)
[ File : C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\prefs.js ]
Line Deleted : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.yahoo.com/*\" param=\"[...]
-\\ Google Chrome v31.0.1650.63
[ File : C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted : urls_to_restore_on_startup
*************************
AdwCleaner[R0].txt - [3526 octets] - [04/01/2014 10:38:10]
AdwCleaner[S0].txt - [3495 octets] - [04/01/2014 10:39:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3555 octets] ##########
Re: Kontrola logu
Poprosim o log z FRSTLauncheru http://forum.viry.cz/viewtopic.php?f=13&t=133100
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Re: Kontrola logu
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014
Ran by Klášter (administrator) on KLÁŠTER-PC on 05-01-2014 21:42:04
Running from C:\Users\Klášter\Klášter\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(IObit) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Acresso) C:\Program Files (x86)\ViewPower\TomcatWrapper.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Acresso) C:\Program Files (x86)\ViewPower\ViewPower.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3024896 2011-04-06] (VIA)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IObit Malware Fighter] - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1573184 2013-12-13] (IObit)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-30] (AVAST Software)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Advanced SystemCare 7] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2285344 2013-12-09] (IObit)
AppInit_DLLs: [ ] ()
AppInit_DLLs-x32: [ ] ()
Startup: C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ViewPower.lnk
ShortcutTarget: ViewPower.lnk -> C:\Program Files (x86)\ViewPower\ViewPower.exe (Acresso)
Startup: C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKCU - DefaultScope {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {5BCBE05D-5A31-4C80-BC31-84B3F159104D} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.1.0.196
FireFox:
========
FF ProfilePath: C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Ads Removal - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\adsremoval@adsremoval.net
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\ascsurfingprotection@iobit.com
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchKeyword: yahoo.com
CHR DefaultSearchProvider: Yahoo!
CHR DefaultSearchURL: http://search.yahoo.com/search?fr=chr-g ... earchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Kl\u00E1\u0161ter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL No File
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll No File
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Ads Removal) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0
CHR Extension: (avast! Online Security) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2011.70_0
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx
==================== Services (Whitelisted) =================
R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [881440 2013-12-09] (IObit)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-30] (AVAST Software)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [341824 2013-11-11] (IObit)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-03-29] (VIA Technologies, Inc.)
R2 Viewpower; C:\Program Files (x86)\ViewPower\TomcatWrapper.exe [116224 2011-10-10] (Acresso)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2013-12-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2013-12-30] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2013-12-30] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2013-12-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-30] ()
S3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2013-11-19] (IObit.com)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] ()
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-11-19] (IObit.com)
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-05 21:41 - 2014-01-05 21:41 - 00000000 ____D C:\FRST
2014-01-05 21:40 - 2014-01-05 21:40 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 21:37 - 2014-01-05 21:40 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-04 17:13 - 2014-01-04 17:14 - 00000000 ____D C:\Users\Klášter\Downloads\2014-cz-handy
2014-01-04 17:08 - 2014-01-05 21:13 - 00000411 _____ C:\Windows\setupact.log
2014-01-04 17:08 - 2014-01-04 17:08 - 00000000 _____ C:\Windows\setuperr.log
2014-01-04 10:38 - 2014-01-04 10:39 - 00000000 ____D C:\AdwCleaner
2014-01-04 10:36 - 2014-01-04 10:36 - 00007756 _____ C:\Users\Klášter\Desktop\JRT.txt
2014-01-04 10:29 - 2014-01-04 10:29 - 00000000 ____D C:\Windows\ERUNT
2014-01-04 08:52 - 2014-01-04 08:52 - 00001237 _____ C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-01-04 08:52 - 2014-01-04 08:52 - 00001213 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-01-03 22:52 - 2014-01-03 23:27 - 00000000 ____D C:\rsit
2014-01-03 22:52 - 2014-01-03 23:27 - 00000000 ____D C:\Program Files\trend micro
2014-01-03 22:38 - 2014-01-03 22:38 - 01551706 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-03 22:20 - 2014-01-05 21:16 - 00195777 _____ C:\Windows\WindowsUpdate.log
2014-01-03 22:13 - 2014-01-03 22:13 - 00003128 _____ C:\Windows\System32\Tasks\{0ED41DF9-7246-4ADD-A6B6-E24C67D21425}
2013-12-30 17:13 - 2013-12-30 17:13 - 00000000 ____D C:\IObit
2013-12-30 13:19 - 2013-12-30 13:19 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-30 13:18 - 2013-12-30 13:19 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-29 15:53 - 2013-12-29 15:53 - 00000000 ____D C:\Users\Klášter\AppData\Local\Prompt Downloader
2013-12-29 15:51 - 2014-01-04 08:09 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\newnext.me
2013-12-29 15:51 - 2014-01-03 17:14 - 00008452 _____ C:\Users\Klášter\daemonprocess.txt
2013-12-29 15:51 - 2014-01-03 16:20 - 00000000 ____D C:\Users\Klášter\AppData\Local\genienext
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\cache
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\.android
2013-12-29 15:50 - 2014-01-03 22:14 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Seznam.cz
2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2013-12-26 15:27 - 2013-12-26 15:28 - 03534848 _____ C:\Users\Klášter\Downloads\setkani2.ppt
2013-12-26 15:23 - 2013-12-26 15:23 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync(1).exe
2013-12-26 15:22 - 2013-12-26 15:22 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync.exe
2013-12-25 18:34 - 2013-12-25 18:59 - 736495470 _____ C:\Users\Klášter\Downloads\Che-Guevara---Revoluce-2008-drama.avi
2013-12-23 23:25 - 2013-12-23 23:25 - 00021732 _____ C:\Users\Klášter\Downloads\PonticoPreghiera.zip
2013-12-23 23:25 - 2013-12-23 23:25 - 00014723 _____ C:\Users\Klášter\Downloads\Antirrhetikos.zip
2013-12-16 12:05 - 2013-12-16 12:05 - 00257049 _____ C:\Users\Klášter\Downloads\prilohy_28870.zip
2013-12-13 03:05 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-13 03:05 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-13 03:05 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-13 03:05 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-13 03:03 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-13 03:03 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-13 03:03 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-13 03:03 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-13 03:03 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-13 03:03 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-13 03:03 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-13 03:03 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-13 03:03 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-13 03:03 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-13 03:03 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-13 03:03 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-13 03:03 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-13 03:03 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-13 03:03 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-13 03:03 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-13 03:03 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-13 03:03 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-13 03:03 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-13 03:03 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-13 03:03 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-13 03:03 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-13 03:03 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-13 03:03 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-13 03:03 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-13 03:03 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-13 03:03 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-13 03:03 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-13 03:03 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-13 03:03 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-13 03:03 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 17:01 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-12 17:01 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-12 17:01 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 17:01 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 17:01 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 17:00 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 17:00 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 17:00 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 17:00 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-12 17:00 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 17:00 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 17:00 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-12 17:00 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 17:00 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 17:00 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 17:00 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-12 17:00 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 17:00 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 17:00 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 06:09 - 2013-12-11 06:09 - 09272200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
==================== One Month Modified Files and Folders =======
2014-01-05 21:41 - 2014-01-05 21:41 - 00000000 ____D C:\FRST
2014-01-05 21:40 - 2014-01-05 21:40 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 21:40 - 2014-01-05 21:37 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-05 21:21 - 2009-07-14 05:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-05 21:21 - 2009-07-14 05:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-05 21:18 - 2013-01-24 15:00 - 00003986 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A13D2A84-1BAE-4D1F-8EC1-0401F946E445}
2014-01-05 21:16 - 2014-01-03 22:20 - 00195777 _____ C:\Windows\WindowsUpdate.log
2014-01-05 21:13 - 2014-01-04 17:08 - 00000411 _____ C:\Windows\setupact.log
2014-01-05 21:13 - 2013-11-19 10:58 - 00000286 _____ C:\Windows\Tasks\Driver Booster Update.job
2014-01-05 21:13 - 2012-03-23 22:02 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-05 21:13 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-05 19:18 - 2013-03-19 21:19 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-05 19:18 - 2012-03-23 22:02 - 00000954 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-04 17:53 - 2011-04-12 09:34 - 00668882 _____ C:\Windows\system32\perfh005.dat
2014-01-04 17:53 - 2011-04-12 09:34 - 00141542 _____ C:\Windows\system32\perfc005.dat
2014-01-04 17:53 - 2009-07-14 06:13 - 01584626 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-04 17:14 - 2014-01-04 17:13 - 00000000 ____D C:\Users\Klášter\Downloads\2014-cz-handy
2014-01-04 17:08 - 2014-01-04 17:08 - 00000000 _____ C:\Windows\setuperr.log
2014-01-04 17:06 - 2011-10-27 20:30 - 00000000 ____D C:\Users\Klášter\Documents\Honzo A
2014-01-04 10:57 - 2011-10-21 19:43 - 00000000 ____D C:\Users\Klášter\Documents\Michal
2014-01-04 10:39 - 2014-01-04 10:38 - 00000000 ____D C:\AdwCleaner
2014-01-04 10:36 - 2014-01-04 10:36 - 00007756 _____ C:\Users\Klášter\Desktop\JRT.txt
2014-01-04 10:29 - 2014-01-04 10:29 - 00000000 ____D C:\Windows\ERUNT
2014-01-04 08:57 - 2013-11-10 22:56 - 00002205 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2014-01-04 08:56 - 2011-10-05 18:10 - 00000000 ____D C:\Users\Klášter
2014-01-04 08:52 - 2014-01-04 08:52 - 00001237 _____ C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-01-04 08:52 - 2014-01-04 08:52 - 00001213 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-01-04 08:52 - 2013-11-10 22:57 - 00003098 _____ C:\Windows\System32\Tasks\ASC7_PerformanceMonitor
2014-01-04 08:52 - 2013-11-10 22:56 - 00002854 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Klášter
2014-01-04 08:52 - 2012-11-15 21:32 - 00000000 ____D C:\Program Files (x86)\IObit
2014-01-04 08:09 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\newnext.me
2014-01-03 23:27 - 2014-01-03 22:52 - 00000000 ____D C:\rsit
2014-01-03 23:27 - 2014-01-03 22:52 - 00000000 ____D C:\Program Files\trend micro
2014-01-03 22:38 - 2014-01-03 22:38 - 01551706 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-03 22:14 - 2013-12-29 15:50 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Seznam.cz
2014-01-03 22:13 - 2014-01-03 22:13 - 00003128 _____ C:\Windows\System32\Tasks\{0ED41DF9-7246-4ADD-A6B6-E24C67D21425}
2014-01-03 22:09 - 2013-04-25 21:48 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2014-01-03 17:14 - 2013-12-29 15:51 - 00008452 _____ C:\Users\Klášter\daemonprocess.txt
2014-01-03 16:20 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\genienext
2013-12-30 17:13 - 2013-12-30 17:13 - 00000000 ____D C:\IObit
2013-12-30 13:19 - 2013-12-30 13:19 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-30 13:19 - 2013-12-30 13:18 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 01034464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 00422216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-30 13:17 - 2013-04-25 21:47 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-30 13:17 - 2013-03-07 08:14 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-30 13:17 - 2011-10-06 10:47 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-30 12:03 - 2013-11-10 22:56 - 00000000 ____D C:\ProgramData\ProductData
2013-12-30 12:03 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-29 15:53 - 2013-12-29 15:53 - 00000000 ____D C:\Users\Klášter\AppData\Local\Prompt Downloader
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\cache
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\.android
2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2013-12-28 17:16 - 2011-11-14 16:37 - 00000000 ____D C:\Users\Klášter\Documents\David
2013-12-26 15:28 - 2013-12-26 15:27 - 03534848 _____ C:\Users\Klášter\Downloads\setkani2.ppt
2013-12-26 15:23 - 2013-12-26 15:23 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync(1).exe
2013-12-26 15:22 - 2013-12-26 15:22 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync.exe
2013-12-25 18:59 - 2013-12-25 18:34 - 736495470 _____ C:\Users\Klášter\Downloads\Che-Guevara---Revoluce-2008-drama.avi
2013-12-23 23:25 - 2013-12-23 23:25 - 00021732 _____ C:\Users\Klášter\Downloads\PonticoPreghiera.zip
2013-12-23 23:25 - 2013-12-23 23:25 - 00014723 _____ C:\Users\Klášter\Downloads\Antirrhetikos.zip
2013-12-21 00:11 - 2013-11-13 10:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-16 12:05 - 2013-12-16 12:05 - 00257049 _____ C:\Users\Klášter\Downloads\prilohy_28870.zip
2013-12-16 03:03 - 2013-08-15 02:01 - 00000000 ____D C:\Windows\system32\MRT
2013-12-16 03:01 - 2011-10-05 18:46 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-14 05:50 - 2013-10-15 07:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-12-13 04:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-13 03:23 - 2009-07-14 05:45 - 00343256 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-13 03:04 - 2011-10-10 12:36 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 16:18 - 2011-10-15 08:52 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Skype
2013-12-11 06:09 - 2013-12-11 06:09 - 09272200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-12-11 06:09 - 2013-03-19 21:19 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 06:09 - 2013-03-19 21:19 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 06:09 - 2011-10-05 18:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 05:55 - 2012-03-23 22:02 - 00003950 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-11 05:55 - 2012-03-23 22:02 - 00003698 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-06 21:29 - 2011-10-06 08:15 - 00000000 ____D C:\Users\Klášter\AppData\Local\Nero
Some content of TEMP:
====================
C:\Users\Klášter\AppData\Local\Temp\Quarantine.exe
C:\Users\Klášter\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-20 06:17
==================== End Of Log ============================
Ran by Klášter (administrator) on KLÁŠTER-PC on 05-01-2014 21:42:04
Running from C:\Users\Klášter\Klášter\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(IObit) C:\Program Files (x86)\IObit\Driver Booster\AutoUpdate.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\Monitor.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Acresso) C:\Program Files (x86)\ViewPower\TomcatWrapper.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag 2\SmartDefrag.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Acresso) C:\Program Files (x86)\ViewPower\ViewPower.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3024896 2011-04-06] (VIA)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IObit Malware Fighter] - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1573184 2013-12-13] (IObit)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-30] (AVAST Software)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Advanced SystemCare 7] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2285344 2013-12-09] (IObit)
AppInit_DLLs: [ ] ()
AppInit_DLLs-x32: [ ] ()
Startup: C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ViewPower.lnk
ShortcutTarget: ViewPower.lnk -> C:\Program Files (x86)\ViewPower\ViewPower.exe (Acresso)
Startup: C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKCU - DefaultScope {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {5BCBE05D-5A31-4C80-BC31-84B3F159104D} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.1.0.196
FireFox:
========
FF ProfilePath: C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Ads Removal - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\adsremoval@adsremoval.net
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\ascsurfingprotection@iobit.com
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchKeyword: yahoo.com
CHR DefaultSearchProvider: Yahoo!
CHR DefaultSearchURL: http://search.yahoo.com/search?fr=chr-g ... earchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Kl\u00E1\u0161ter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL No File
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll No File
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Ads Removal) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0
CHR Extension: (avast! Online Security) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2011.70_0
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx
==================== Services (Whitelisted) =================
R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [881440 2013-12-09] (IObit)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-30] (AVAST Software)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [341824 2013-11-11] (IObit)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-03-29] (VIA Technologies, Inc.)
R2 Viewpower; C:\Program Files (x86)\ViewPower\TomcatWrapper.exe [116224 2011-10-10] (Acresso)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2013-12-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2013-12-30] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2013-12-30] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2013-12-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-30] ()
S3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2013-11-19] (IObit.com)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] ()
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-11-19] (IObit.com)
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-05 21:41 - 2014-01-05 21:41 - 00000000 ____D C:\FRST
2014-01-05 21:40 - 2014-01-05 21:40 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 21:37 - 2014-01-05 21:40 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-04 17:13 - 2014-01-04 17:14 - 00000000 ____D C:\Users\Klášter\Downloads\2014-cz-handy
2014-01-04 17:08 - 2014-01-05 21:13 - 00000411 _____ C:\Windows\setupact.log
2014-01-04 17:08 - 2014-01-04 17:08 - 00000000 _____ C:\Windows\setuperr.log
2014-01-04 10:38 - 2014-01-04 10:39 - 00000000 ____D C:\AdwCleaner
2014-01-04 10:36 - 2014-01-04 10:36 - 00007756 _____ C:\Users\Klášter\Desktop\JRT.txt
2014-01-04 10:29 - 2014-01-04 10:29 - 00000000 ____D C:\Windows\ERUNT
2014-01-04 08:52 - 2014-01-04 08:52 - 00001237 _____ C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-01-04 08:52 - 2014-01-04 08:52 - 00001213 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-01-03 22:52 - 2014-01-03 23:27 - 00000000 ____D C:\rsit
2014-01-03 22:52 - 2014-01-03 23:27 - 00000000 ____D C:\Program Files\trend micro
2014-01-03 22:38 - 2014-01-03 22:38 - 01551706 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-03 22:20 - 2014-01-05 21:16 - 00195777 _____ C:\Windows\WindowsUpdate.log
2014-01-03 22:13 - 2014-01-03 22:13 - 00003128 _____ C:\Windows\System32\Tasks\{0ED41DF9-7246-4ADD-A6B6-E24C67D21425}
2013-12-30 17:13 - 2013-12-30 17:13 - 00000000 ____D C:\IObit
2013-12-30 13:19 - 2013-12-30 13:19 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-30 13:18 - 2013-12-30 13:19 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-29 15:53 - 2013-12-29 15:53 - 00000000 ____D C:\Users\Klášter\AppData\Local\Prompt Downloader
2013-12-29 15:51 - 2014-01-04 08:09 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\newnext.me
2013-12-29 15:51 - 2014-01-03 17:14 - 00008452 _____ C:\Users\Klášter\daemonprocess.txt
2013-12-29 15:51 - 2014-01-03 16:20 - 00000000 ____D C:\Users\Klášter\AppData\Local\genienext
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\cache
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\.android
2013-12-29 15:50 - 2014-01-03 22:14 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Seznam.cz
2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2013-12-26 15:27 - 2013-12-26 15:28 - 03534848 _____ C:\Users\Klášter\Downloads\setkani2.ppt
2013-12-26 15:23 - 2013-12-26 15:23 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync(1).exe
2013-12-26 15:22 - 2013-12-26 15:22 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync.exe
2013-12-25 18:34 - 2013-12-25 18:59 - 736495470 _____ C:\Users\Klášter\Downloads\Che-Guevara---Revoluce-2008-drama.avi
2013-12-23 23:25 - 2013-12-23 23:25 - 00021732 _____ C:\Users\Klášter\Downloads\PonticoPreghiera.zip
2013-12-23 23:25 - 2013-12-23 23:25 - 00014723 _____ C:\Users\Klášter\Downloads\Antirrhetikos.zip
2013-12-16 12:05 - 2013-12-16 12:05 - 00257049 _____ C:\Users\Klášter\Downloads\prilohy_28870.zip
2013-12-13 03:05 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-13 03:05 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-13 03:05 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-13 03:05 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-13 03:03 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-13 03:03 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-13 03:03 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-13 03:03 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-13 03:03 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-13 03:03 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-13 03:03 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-13 03:03 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-13 03:03 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-13 03:03 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-13 03:03 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-13 03:03 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-13 03:03 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-13 03:03 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-13 03:03 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-13 03:03 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-13 03:03 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-13 03:03 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-13 03:03 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-13 03:03 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-13 03:03 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-13 03:03 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-13 03:03 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-13 03:03 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-13 03:03 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-13 03:03 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-13 03:03 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-13 03:03 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-13 03:03 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-13 03:03 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-13 03:03 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 17:01 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-12 17:01 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-12 17:01 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 17:01 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 17:01 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 17:00 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 17:00 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 17:00 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 17:00 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-12 17:00 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 17:00 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 17:00 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-12 17:00 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 17:00 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 17:00 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 17:00 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-12 17:00 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 17:00 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 17:00 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 06:09 - 2013-12-11 06:09 - 09272200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
==================== One Month Modified Files and Folders =======
2014-01-05 21:41 - 2014-01-05 21:41 - 00000000 ____D C:\FRST
2014-01-05 21:40 - 2014-01-05 21:40 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 21:40 - 2014-01-05 21:37 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-05 21:21 - 2009-07-14 05:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-05 21:21 - 2009-07-14 05:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-05 21:18 - 2013-01-24 15:00 - 00003986 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A13D2A84-1BAE-4D1F-8EC1-0401F946E445}
2014-01-05 21:16 - 2014-01-03 22:20 - 00195777 _____ C:\Windows\WindowsUpdate.log
2014-01-05 21:13 - 2014-01-04 17:08 - 00000411 _____ C:\Windows\setupact.log
2014-01-05 21:13 - 2013-11-19 10:58 - 00000286 _____ C:\Windows\Tasks\Driver Booster Update.job
2014-01-05 21:13 - 2012-03-23 22:02 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-05 21:13 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-05 19:18 - 2013-03-19 21:19 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-05 19:18 - 2012-03-23 22:02 - 00000954 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-04 17:53 - 2011-04-12 09:34 - 00668882 _____ C:\Windows\system32\perfh005.dat
2014-01-04 17:53 - 2011-04-12 09:34 - 00141542 _____ C:\Windows\system32\perfc005.dat
2014-01-04 17:53 - 2009-07-14 06:13 - 01584626 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-04 17:14 - 2014-01-04 17:13 - 00000000 ____D C:\Users\Klášter\Downloads\2014-cz-handy
2014-01-04 17:08 - 2014-01-04 17:08 - 00000000 _____ C:\Windows\setuperr.log
2014-01-04 17:06 - 2011-10-27 20:30 - 00000000 ____D C:\Users\Klášter\Documents\Honzo A
2014-01-04 10:57 - 2011-10-21 19:43 - 00000000 ____D C:\Users\Klášter\Documents\Michal
2014-01-04 10:39 - 2014-01-04 10:38 - 00000000 ____D C:\AdwCleaner
2014-01-04 10:36 - 2014-01-04 10:36 - 00007756 _____ C:\Users\Klášter\Desktop\JRT.txt
2014-01-04 10:29 - 2014-01-04 10:29 - 00000000 ____D C:\Windows\ERUNT
2014-01-04 08:57 - 2013-11-10 22:56 - 00002205 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
2014-01-04 08:56 - 2011-10-05 18:10 - 00000000 ____D C:\Users\Klášter
2014-01-04 08:52 - 2014-01-04 08:52 - 00001237 _____ C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-01-04 08:52 - 2014-01-04 08:52 - 00001213 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-01-04 08:52 - 2013-11-10 22:57 - 00003098 _____ C:\Windows\System32\Tasks\ASC7_PerformanceMonitor
2014-01-04 08:52 - 2013-11-10 22:56 - 00002854 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Klášter
2014-01-04 08:52 - 2012-11-15 21:32 - 00000000 ____D C:\Program Files (x86)\IObit
2014-01-04 08:09 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\newnext.me
2014-01-03 23:27 - 2014-01-03 22:52 - 00000000 ____D C:\rsit
2014-01-03 23:27 - 2014-01-03 22:52 - 00000000 ____D C:\Program Files\trend micro
2014-01-03 22:38 - 2014-01-03 22:38 - 01551706 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-03 22:14 - 2013-12-29 15:50 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Seznam.cz
2014-01-03 22:13 - 2014-01-03 22:13 - 00003128 _____ C:\Windows\System32\Tasks\{0ED41DF9-7246-4ADD-A6B6-E24C67D21425}
2014-01-03 22:09 - 2013-04-25 21:48 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2014-01-03 17:14 - 2013-12-29 15:51 - 00008452 _____ C:\Users\Klášter\daemonprocess.txt
2014-01-03 16:20 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\genienext
2013-12-30 17:13 - 2013-12-30 17:13 - 00000000 ____D C:\IObit
2013-12-30 13:19 - 2013-12-30 13:19 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-30 13:19 - 2013-12-30 13:18 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 01034464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 00422216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-30 13:17 - 2013-04-25 21:47 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-30 13:17 - 2013-03-07 08:14 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-30 13:17 - 2011-10-06 10:47 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-30 12:03 - 2013-11-10 22:56 - 00000000 ____D C:\ProgramData\ProductData
2013-12-30 12:03 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-29 15:53 - 2013-12-29 15:53 - 00000000 ____D C:\Users\Klášter\AppData\Local\Prompt Downloader
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\cache
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\.android
2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2013-12-28 17:16 - 2011-11-14 16:37 - 00000000 ____D C:\Users\Klášter\Documents\David
2013-12-26 15:28 - 2013-12-26 15:27 - 03534848 _____ C:\Users\Klášter\Downloads\setkani2.ppt
2013-12-26 15:23 - 2013-12-26 15:23 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync(1).exe
2013-12-26 15:22 - 2013-12-26 15:22 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync.exe
2013-12-25 18:59 - 2013-12-25 18:34 - 736495470 _____ C:\Users\Klášter\Downloads\Che-Guevara---Revoluce-2008-drama.avi
2013-12-23 23:25 - 2013-12-23 23:25 - 00021732 _____ C:\Users\Klášter\Downloads\PonticoPreghiera.zip
2013-12-23 23:25 - 2013-12-23 23:25 - 00014723 _____ C:\Users\Klášter\Downloads\Antirrhetikos.zip
2013-12-21 00:11 - 2013-11-13 10:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-16 12:05 - 2013-12-16 12:05 - 00257049 _____ C:\Users\Klášter\Downloads\prilohy_28870.zip
2013-12-16 03:03 - 2013-08-15 02:01 - 00000000 ____D C:\Windows\system32\MRT
2013-12-16 03:01 - 2011-10-05 18:46 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-14 05:50 - 2013-10-15 07:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-12-13 04:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-13 03:23 - 2009-07-14 05:45 - 00343256 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-13 03:04 - 2011-10-10 12:36 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 16:18 - 2011-10-15 08:52 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Skype
2013-12-11 06:09 - 2013-12-11 06:09 - 09272200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-12-11 06:09 - 2013-03-19 21:19 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 06:09 - 2013-03-19 21:19 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 06:09 - 2011-10-05 18:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 05:55 - 2012-03-23 22:02 - 00003950 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-11 05:55 - 2012-03-23 22:02 - 00003698 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-06 21:29 - 2011-10-06 08:15 - 00000000 ____D C:\Users\Klášter\AppData\Local\Nero
Some content of TEMP:
====================
C:\Users\Klášter\AppData\Local\Temp\Quarantine.exe
C:\Users\Klášter\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-20 06:17
==================== End Of Log ============================
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Re: Kontrola logu
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Re: Kontrola logu
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-01-2014
Ran by Klášter (administrator) on KLÁŠTER-PC on 05-01-2014 22:08:29
Running from C:\Users\Klášter\Klášter\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Acresso) C:\Program Files (x86)\ViewPower\TomcatWrapper.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Acresso) C:\Program Files (x86)\ViewPower\ViewPower.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3024896 2011-04-06] (VIA)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-30] (AVAST Software)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: [ ] ()
AppInit_DLLs-x32: [ ] ()
Startup: C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ViewPower.lnk
ShortcutTarget: ViewPower.lnk -> C:\Program Files (x86)\ViewPower\ViewPower.exe (Acresso)
Startup: C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKCU - DefaultScope {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {5BCBE05D-5A31-4C80-BC31-84B3F159104D} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.1.0.196
FireFox:
========
FF ProfilePath: C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Ads Removal - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\adsremoval@adsremoval.net
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchKeyword: yahoo.com
CHR DefaultSearchProvider: Yahoo!
CHR DefaultSearchURL: http://search.yahoo.com/search?fr=chr-g ... earchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Kl\u00E1\u0161ter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL No File
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll No File
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Ads Removal) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0
CHR Extension: (avast! Online Security) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2011.70_0
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-30] (AVAST Software)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-03-29] (VIA Technologies, Inc.)
R2 Viewpower; C:\Program Files (x86)\ViewPower\TomcatWrapper.exe [116224 2011-10-10] (Acresso)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2013-12-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2013-12-30] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2013-12-30] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2013-12-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-30] ()
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-05 22:08 - 2014-01-05 22:08 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 21:59 - 2014-01-05 21:59 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2014-01-05 21:41 - 2014-01-05 21:41 - 00000000 ____D C:\FRST
2014-01-05 21:37 - 2014-01-05 22:08 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-04 17:13 - 2014-01-04 17:14 - 00000000 ____D C:\Users\Klášter\Downloads\2014-cz-handy
2014-01-04 10:38 - 2014-01-04 10:39 - 00000000 ____D C:\AdwCleaner
2014-01-04 10:36 - 2014-01-04 10:36 - 00007756 _____ C:\Users\Klášter\Desktop\JRT.txt
2014-01-04 10:29 - 2014-01-04 10:29 - 00000000 ____D C:\Windows\ERUNT
2014-01-03 22:52 - 2014-01-03 23:27 - 00000000 ____D C:\rsit
2014-01-03 22:52 - 2014-01-03 23:27 - 00000000 ____D C:\Program Files\trend micro
2014-01-03 22:38 - 2014-01-03 22:38 - 01551706 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-03 22:20 - 2014-01-05 21:16 - 00195777 ____N C:\Windows\WindowsUpdate.log
2014-01-03 22:13 - 2014-01-03 22:13 - 00003128 _____ C:\Windows\System32\Tasks\{0ED41DF9-7246-4ADD-A6B6-E24C67D21425}
2013-12-30 17:13 - 2013-12-30 17:13 - 00000000 ____D C:\IObit
2013-12-30 13:19 - 2013-12-30 13:19 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-30 13:18 - 2013-12-30 13:19 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-29 15:53 - 2013-12-29 15:53 - 00000000 ____D C:\Users\Klášter\AppData\Local\Prompt Downloader
2013-12-29 15:51 - 2014-01-04 08:09 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\newnext.me
2013-12-29 15:51 - 2014-01-03 17:14 - 00008452 _____ C:\Users\Klášter\daemonprocess.txt
2013-12-29 15:51 - 2014-01-03 16:20 - 00000000 ____D C:\Users\Klášter\AppData\Local\genienext
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\cache
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\.android
2013-12-29 15:50 - 2014-01-03 22:14 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Seznam.cz
2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2013-12-26 15:27 - 2013-12-26 15:28 - 03534848 _____ C:\Users\Klášter\Downloads\setkani2.ppt
2013-12-26 15:23 - 2013-12-26 15:23 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync(1).exe
2013-12-26 15:22 - 2013-12-26 15:22 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync.exe
2013-12-25 18:34 - 2013-12-25 18:59 - 736495470 _____ C:\Users\Klášter\Downloads\Che-Guevara---Revoluce-2008-drama.avi
2013-12-23 23:25 - 2013-12-23 23:25 - 00021732 _____ C:\Users\Klášter\Downloads\PonticoPreghiera.zip
2013-12-23 23:25 - 2013-12-23 23:25 - 00014723 _____ C:\Users\Klášter\Downloads\Antirrhetikos.zip
2013-12-16 12:05 - 2013-12-16 12:05 - 00257049 _____ C:\Users\Klášter\Downloads\prilohy_28870.zip
2013-12-13 03:05 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-13 03:05 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-13 03:05 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-13 03:05 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-13 03:03 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-13 03:03 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-13 03:03 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-13 03:03 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-13 03:03 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-13 03:03 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-13 03:03 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-13 03:03 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-13 03:03 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-13 03:03 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-13 03:03 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-13 03:03 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-13 03:03 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-13 03:03 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-13 03:03 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-13 03:03 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-13 03:03 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-13 03:03 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-13 03:03 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-13 03:03 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-13 03:03 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-13 03:03 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-13 03:03 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-13 03:03 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-13 03:03 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-13 03:03 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-13 03:03 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-13 03:03 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-13 03:03 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-13 03:03 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-13 03:03 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 17:01 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-12 17:01 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-12 17:01 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 17:01 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 17:01 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 17:00 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 17:00 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 17:00 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 17:00 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-12 17:00 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 17:00 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 17:00 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-12 17:00 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 17:00 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 17:00 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 17:00 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-12 17:00 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 17:00 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 17:00 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 06:09 - 2013-12-11 06:09 - 09272200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
==================== One Month Modified Files and Folders =======
2014-01-05 22:08 - 2014-01-05 22:08 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 22:08 - 2014-01-05 21:37 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-05 22:06 - 2011-10-21 19:43 - 00000000 ____D C:\Users\Klášter\Documents\Michal
2014-01-05 22:05 - 2012-11-15 21:32 - 00000000 ____D C:\Program Files (x86)\IObit
2014-01-05 22:00 - 2012-03-23 22:02 - 00000954 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-05 21:59 - 2014-01-05 21:59 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2014-01-05 21:41 - 2014-01-05 21:41 - 00000000 ____D C:\FRST
2014-01-05 21:21 - 2009-07-14 05:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-05 21:21 - 2009-07-14 05:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-05 21:18 - 2013-01-24 15:00 - 00003986 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A13D2A84-1BAE-4D1F-8EC1-0401F946E445}
2014-01-05 21:16 - 2014-01-03 22:20 - 00195777 ____N C:\Windows\WindowsUpdate.log
2014-01-05 21:13 - 2012-03-23 22:02 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-05 21:13 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-05 19:18 - 2013-03-19 21:19 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-04 17:53 - 2011-04-12 09:34 - 00668882 _____ C:\Windows\system32\perfh005.dat
2014-01-04 17:53 - 2011-04-12 09:34 - 00141542 _____ C:\Windows\system32\perfc005.dat
2014-01-04 17:53 - 2009-07-14 06:13 - 01584626 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-04 17:14 - 2014-01-04 17:13 - 00000000 ____D C:\Users\Klášter\Downloads\2014-cz-handy
2014-01-04 17:06 - 2011-10-27 20:30 - 00000000 ____D C:\Users\Klášter\Documents\Honzo A
2014-01-04 10:39 - 2014-01-04 10:38 - 00000000 ____D C:\AdwCleaner
2014-01-04 10:36 - 2014-01-04 10:36 - 00007756 _____ C:\Users\Klášter\Desktop\JRT.txt
2014-01-04 10:29 - 2014-01-04 10:29 - 00000000 ____D C:\Windows\ERUNT
2014-01-04 08:56 - 2011-10-05 18:10 - 00000000 ____D C:\Users\Klášter
2014-01-04 08:09 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\newnext.me
2014-01-03 23:27 - 2014-01-03 22:52 - 00000000 ____D C:\rsit
2014-01-03 23:27 - 2014-01-03 22:52 - 00000000 ____D C:\Program Files\trend micro
2014-01-03 22:38 - 2014-01-03 22:38 - 01551706 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-03 22:14 - 2013-12-29 15:50 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Seznam.cz
2014-01-03 22:13 - 2014-01-03 22:13 - 00003128 _____ C:\Windows\System32\Tasks\{0ED41DF9-7246-4ADD-A6B6-E24C67D21425}
2014-01-03 22:09 - 2013-04-25 21:48 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2014-01-03 17:14 - 2013-12-29 15:51 - 00008452 _____ C:\Users\Klášter\daemonprocess.txt
2014-01-03 16:20 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\genienext
2013-12-30 17:13 - 2013-12-30 17:13 - 00000000 ____D C:\IObit
2013-12-30 13:19 - 2013-12-30 13:19 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-30 13:19 - 2013-12-30 13:18 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 01034464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 00422216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-30 13:17 - 2013-04-25 21:47 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-30 13:17 - 2013-03-07 08:14 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-30 13:17 - 2011-10-06 10:47 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-30 12:03 - 2013-11-10 22:56 - 00000000 ____D C:\ProgramData\ProductData
2013-12-30 12:03 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-29 15:53 - 2013-12-29 15:53 - 00000000 ____D C:\Users\Klášter\AppData\Local\Prompt Downloader
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\cache
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\.android
2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2013-12-28 17:16 - 2011-11-14 16:37 - 00000000 ____D C:\Users\Klášter\Documents\David
2013-12-26 15:28 - 2013-12-26 15:27 - 03534848 _____ C:\Users\Klášter\Downloads\setkani2.ppt
2013-12-26 15:23 - 2013-12-26 15:23 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync(1).exe
2013-12-26 15:22 - 2013-12-26 15:22 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync.exe
2013-12-25 18:59 - 2013-12-25 18:34 - 736495470 _____ C:\Users\Klášter\Downloads\Che-Guevara---Revoluce-2008-drama.avi
2013-12-23 23:25 - 2013-12-23 23:25 - 00021732 _____ C:\Users\Klášter\Downloads\PonticoPreghiera.zip
2013-12-23 23:25 - 2013-12-23 23:25 - 00014723 _____ C:\Users\Klášter\Downloads\Antirrhetikos.zip
2013-12-21 00:11 - 2013-11-13 10:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-16 12:05 - 2013-12-16 12:05 - 00257049 _____ C:\Users\Klášter\Downloads\prilohy_28870.zip
2013-12-16 03:03 - 2013-08-15 02:01 - 00000000 ____D C:\Windows\system32\MRT
2013-12-16 03:01 - 2011-10-05 18:46 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-14 05:50 - 2013-10-15 07:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-12-13 04:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-13 03:23 - 2009-07-14 05:45 - 00343256 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-13 03:04 - 2011-10-10 12:36 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 16:18 - 2011-10-15 08:52 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Skype
2013-12-11 06:09 - 2013-12-11 06:09 - 09272200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-12-11 06:09 - 2013-03-19 21:19 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 06:09 - 2013-03-19 21:19 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 06:09 - 2011-10-05 18:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 05:55 - 2012-03-23 22:02 - 00003950 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-11 05:55 - 2012-03-23 22:02 - 00003698 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-06 21:29 - 2011-10-06 08:15 - 00000000 ____D C:\Users\Klášter\AppData\Local\Nero
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-20 06:17
==================== End Of Log ============================
Ran by Klášter (administrator) on KLÁŠTER-PC on 05-01-2014 22:08:29
Running from C:\Users\Klášter\Klášter\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Acresso) C:\Program Files (x86)\ViewPower\TomcatWrapper.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Acresso) C:\Program Files (x86)\ViewPower\ViewPower.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\ViewPower\jre\bin\javaw.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [HDAudDeck] - C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3024896 2011-04-06] (VIA)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2013-12-30] (AVAST Software)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: [ ] ()
AppInit_DLLs-x32: [ ] ()
Startup: C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ViewPower.lnk
ShortcutTarget: ViewPower.lnk -> C:\Program Files (x86)\ViewPower\ViewPower.exe (Acresso)
Startup: C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cz/
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKCU - DefaultScope {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKCU - {5BCBE05D-5A31-4C80-BC31-84B3F159104D} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.1.0.196
FireFox:
========
FF ProfilePath: C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Ads Removal - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\adsremoval@adsremoval.net
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchKeyword: yahoo.com
CHR DefaultSearchProvider: Yahoo!
CHR DefaultSearchURL: http://search.yahoo.com/search?fr=chr-g ... earchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Kl\u00E1\u0161ter\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL No File
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll No File
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll No File
CHR Extension: (YouTube) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Ads Removal) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0
CHR Extension: (avast! Online Security) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2011.70_0
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0
CHR Extension: (Gmail) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-30] (AVAST Software)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-03-29] (VIA Technologies, Inc.)
R2 Viewpower; C:\Program Files (x86)\ViewPower\TomcatWrapper.exe [116224 2011-10-10] (Acresso)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2013-12-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-10-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-10-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2013-12-30] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2013-12-30] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2013-12-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-30] ()
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-05 22:08 - 2014-01-05 22:08 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 21:59 - 2014-01-05 21:59 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2014-01-05 21:41 - 2014-01-05 21:41 - 00000000 ____D C:\FRST
2014-01-05 21:37 - 2014-01-05 22:08 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-04 17:13 - 2014-01-04 17:14 - 00000000 ____D C:\Users\Klášter\Downloads\2014-cz-handy
2014-01-04 10:38 - 2014-01-04 10:39 - 00000000 ____D C:\AdwCleaner
2014-01-04 10:36 - 2014-01-04 10:36 - 00007756 _____ C:\Users\Klášter\Desktop\JRT.txt
2014-01-04 10:29 - 2014-01-04 10:29 - 00000000 ____D C:\Windows\ERUNT
2014-01-03 22:52 - 2014-01-03 23:27 - 00000000 ____D C:\rsit
2014-01-03 22:52 - 2014-01-03 23:27 - 00000000 ____D C:\Program Files\trend micro
2014-01-03 22:38 - 2014-01-03 22:38 - 01551706 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-03 22:20 - 2014-01-05 21:16 - 00195777 ____N C:\Windows\WindowsUpdate.log
2014-01-03 22:13 - 2014-01-03 22:13 - 00003128 _____ C:\Windows\System32\Tasks\{0ED41DF9-7246-4ADD-A6B6-E24C67D21425}
2013-12-30 17:13 - 2013-12-30 17:13 - 00000000 ____D C:\IObit
2013-12-30 13:19 - 2013-12-30 13:19 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-30 13:18 - 2013-12-30 13:19 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-29 15:53 - 2013-12-29 15:53 - 00000000 ____D C:\Users\Klášter\AppData\Local\Prompt Downloader
2013-12-29 15:51 - 2014-01-04 08:09 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\newnext.me
2013-12-29 15:51 - 2014-01-03 17:14 - 00008452 _____ C:\Users\Klášter\daemonprocess.txt
2013-12-29 15:51 - 2014-01-03 16:20 - 00000000 ____D C:\Users\Klášter\AppData\Local\genienext
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\cache
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\.android
2013-12-29 15:50 - 2014-01-03 22:14 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Seznam.cz
2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2013-12-26 15:27 - 2013-12-26 15:28 - 03534848 _____ C:\Users\Klášter\Downloads\setkani2.ppt
2013-12-26 15:23 - 2013-12-26 15:23 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync(1).exe
2013-12-26 15:22 - 2013-12-26 15:22 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync.exe
2013-12-25 18:34 - 2013-12-25 18:59 - 736495470 _____ C:\Users\Klášter\Downloads\Che-Guevara---Revoluce-2008-drama.avi
2013-12-23 23:25 - 2013-12-23 23:25 - 00021732 _____ C:\Users\Klášter\Downloads\PonticoPreghiera.zip
2013-12-23 23:25 - 2013-12-23 23:25 - 00014723 _____ C:\Users\Klášter\Downloads\Antirrhetikos.zip
2013-12-16 12:05 - 2013-12-16 12:05 - 00257049 _____ C:\Users\Klášter\Downloads\prilohy_28870.zip
2013-12-13 03:05 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-13 03:05 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-13 03:05 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-13 03:05 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-13 03:03 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-13 03:03 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-13 03:03 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-13 03:03 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-13 03:03 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-13 03:03 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-13 03:03 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-13 03:03 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-13 03:03 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-13 03:03 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-13 03:03 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-13 03:03 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-13 03:03 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-13 03:03 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-13 03:03 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-13 03:03 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-13 03:03 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-13 03:03 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-13 03:03 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-13 03:03 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-13 03:03 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-13 03:03 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-13 03:03 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-13 03:03 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-13 03:03 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-13 03:03 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-13 03:03 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-13 03:03 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-13 03:03 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-13 03:03 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-13 03:03 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 17:01 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-12 17:01 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-12 17:01 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 17:01 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 17:01 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 17:00 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 17:00 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 17:00 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 17:00 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-12 17:00 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 17:00 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 17:00 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-12 17:00 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 17:00 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 17:00 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 17:00 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-12 17:00 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 17:00 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 17:00 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 06:09 - 2013-12-11 06:09 - 09272200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
==================== One Month Modified Files and Folders =======
2014-01-05 22:08 - 2014-01-05 22:08 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 22:08 - 2014-01-05 21:37 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-05 22:06 - 2011-10-21 19:43 - 00000000 ____D C:\Users\Klášter\Documents\Michal
2014-01-05 22:05 - 2012-11-15 21:32 - 00000000 ____D C:\Program Files (x86)\IObit
2014-01-05 22:00 - 2012-03-23 22:02 - 00000954 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-05 21:59 - 2014-01-05 21:59 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2014-01-05 21:41 - 2014-01-05 21:41 - 00000000 ____D C:\FRST
2014-01-05 21:21 - 2009-07-14 05:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-05 21:21 - 2009-07-14 05:45 - 00022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-05 21:18 - 2013-01-24 15:00 - 00003986 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A13D2A84-1BAE-4D1F-8EC1-0401F946E445}
2014-01-05 21:16 - 2014-01-03 22:20 - 00195777 ____N C:\Windows\WindowsUpdate.log
2014-01-05 21:13 - 2012-03-23 22:02 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-05 21:13 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-05 19:18 - 2013-03-19 21:19 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-04 17:53 - 2011-04-12 09:34 - 00668882 _____ C:\Windows\system32\perfh005.dat
2014-01-04 17:53 - 2011-04-12 09:34 - 00141542 _____ C:\Windows\system32\perfc005.dat
2014-01-04 17:53 - 2009-07-14 06:13 - 01584626 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-04 17:14 - 2014-01-04 17:13 - 00000000 ____D C:\Users\Klášter\Downloads\2014-cz-handy
2014-01-04 17:06 - 2011-10-27 20:30 - 00000000 ____D C:\Users\Klášter\Documents\Honzo A
2014-01-04 10:39 - 2014-01-04 10:38 - 00000000 ____D C:\AdwCleaner
2014-01-04 10:36 - 2014-01-04 10:36 - 00007756 _____ C:\Users\Klášter\Desktop\JRT.txt
2014-01-04 10:29 - 2014-01-04 10:29 - 00000000 ____D C:\Windows\ERUNT
2014-01-04 08:56 - 2011-10-05 18:10 - 00000000 ____D C:\Users\Klášter
2014-01-04 08:09 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\newnext.me
2014-01-03 23:27 - 2014-01-03 22:52 - 00000000 ____D C:\rsit
2014-01-03 23:27 - 2014-01-03 22:52 - 00000000 ____D C:\Program Files\trend micro
2014-01-03 22:38 - 2014-01-03 22:38 - 01551706 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-03 22:14 - 2013-12-29 15:50 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Seznam.cz
2014-01-03 22:13 - 2014-01-03 22:13 - 00003128 _____ C:\Windows\System32\Tasks\{0ED41DF9-7246-4ADD-A6B6-E24C67D21425}
2014-01-03 22:09 - 2013-04-25 21:48 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2014-01-03 17:14 - 2013-12-29 15:51 - 00008452 _____ C:\Users\Klášter\daemonprocess.txt
2014-01-03 16:20 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\genienext
2013-12-30 17:13 - 2013-12-30 17:13 - 00000000 ____D C:\IObit
2013-12-30 13:19 - 2013-12-30 13:19 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-30 13:19 - 2013-12-30 13:18 - 00079672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 01034464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 00422216 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2013-12-30 13:17 - 2013-04-25 21:48 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-30 13:17 - 2013-04-25 21:47 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-30 13:17 - 2013-03-07 08:14 - 00207904 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-30 13:17 - 2011-10-06 10:47 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-30 12:03 - 2013-11-10 22:56 - 00000000 ____D C:\ProgramData\ProductData
2013-12-30 12:03 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-29 15:53 - 2013-12-29 15:53 - 00000000 ____D C:\Users\Klášter\AppData\Local\Prompt Downloader
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\AppData\Local\cache
2013-12-29 15:51 - 2013-12-29 15:51 - 00000000 ____D C:\Users\Klášter\.android
2013-12-29 15:50 - 2013-12-29 15:50 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2013-12-28 17:16 - 2011-11-14 16:37 - 00000000 ____D C:\Users\Klášter\Documents\David
2013-12-26 15:28 - 2013-12-26 15:27 - 03534848 _____ C:\Users\Klášter\Downloads\setkani2.ppt
2013-12-26 15:23 - 2013-12-26 15:23 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync(1).exe
2013-12-26 15:22 - 2013-12-26 15:22 - 00819136 _____ (Google Inc.) C:\Users\Klášter\Downloads\googledrivesync.exe
2013-12-25 18:59 - 2013-12-25 18:34 - 736495470 _____ C:\Users\Klášter\Downloads\Che-Guevara---Revoluce-2008-drama.avi
2013-12-23 23:25 - 2013-12-23 23:25 - 00021732 _____ C:\Users\Klášter\Downloads\PonticoPreghiera.zip
2013-12-23 23:25 - 2013-12-23 23:25 - 00014723 _____ C:\Users\Klášter\Downloads\Antirrhetikos.zip
2013-12-21 00:11 - 2013-11-13 10:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-16 12:05 - 2013-12-16 12:05 - 00257049 _____ C:\Users\Klášter\Downloads\prilohy_28870.zip
2013-12-16 03:03 - 2013-08-15 02:01 - 00000000 ____D C:\Windows\system32\MRT
2013-12-16 03:01 - 2011-10-05 18:46 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-14 05:50 - 2013-10-15 07:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-12-13 04:01 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-13 03:23 - 2009-07-14 05:45 - 00343256 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-13 03:04 - 2011-10-10 12:36 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 16:18 - 2011-10-15 08:52 - 00000000 ____D C:\Users\Klášter\AppData\Roaming\Skype
2013-12-11 06:09 - 2013-12-11 06:09 - 09272200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2013-12-11 06:09 - 2013-03-19 21:19 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 06:09 - 2013-03-19 21:19 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-11 06:09 - 2011-10-05 18:33 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 05:55 - 2012-03-23 22:02 - 00003950 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-11 05:55 - 2012-03-23 22:02 - 00003698 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-06 21:29 - 2011-10-06 08:15 - 00000000 ____D C:\Users\Klášter\AppData\Local\Nero
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-20 06:17
==================== End Of Log ============================
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Re: Kontrola logu
Odinstaloval jsem produkty od IOBit.
.......................
.......................
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Re: Kontrola logu
Je v tuto chvíli možné ukončit vaše "léčení", nebo je třeba ještě provést nějaké kroky aby byl tento proces bezpečně zakončen??
Re: Kontrola logu
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IObit Malware Fighter] - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1573184 2013-12-13] (IObit) HKLM-x32\...\Run: [seznam-listicka-distribuce] - "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdat HKCU\...\Run: [Advanced SystemCare 7] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2285344 2013-12-09] (IObit) AppInit_DLLs: [ ] () AppInit_DLLs-x32: [ ] () SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKCU - DefaultScope {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms} SearchScopes: HKCU - {5BCBE05D-5A31-4C80-BC31-84B3F159104D} URL = http://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194 SearchScopes: HKCU - {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms} BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit) BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit) FF Extension: Ads Removal - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\adsremoval@adsremoval.net FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\ascsurfingprotection@iobit.com CHR DefaultSearchKeyword: yahoo.com CHR DefaultSearchProvider: Yahoo! CHR DefaultSearchURL: http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms} CHR DefaultNewTabURL: CHR Extension: (Ads Removal) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0 CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0 CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [881440 2013-12-09] (IObit) R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [341824 2013-11-11] (IObit) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit) S3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit) S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2013-11-19] (IObit.com) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] () S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-11-19] (IObit.com) S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x] 2014-01-05 21:40 - 2014-01-05 21:40 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat 2014-01-05 21:37 - 2014-01-05 21:40 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE 2014-01-04 08:52 - 2014-01-04 08:52 - 00001237 _____ C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk 2014-01-04 08:52 - 2014-01-04 08:52 - 00001213 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk 2014-01-04 08:52 - 2013-11-10 22:57 - 00003098 _____ C:\Windows\System32\Tasks\ASC7_PerformanceMonitor 2014-01-04 08:52 - 2013-11-10 22:56 - 00002854 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Klášter 2014-01-04 08:52 - 2012-11-15 21:32 - 00000000 ____D C:\Program Files (x86)\IObit 2014-01-04 08:57 - 2013-11-10 22:56 - 00002205 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk C:\Users\Klášter\AppData\Local\Temp\Quarantine.exe C:\Users\Klášter\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Hosts: CMD: shutdown /r /f /t 2 End- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
-
Michal Řezáč
- Návštěvník

- Příspěvky: 12
- Registrován: 03 Led 2014 23:07
Re: Kontrola logu
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 05-01-2014
Ran by Klášter at 2014-01-07 08:40:02 Run:1
Running from C:\Users\Klášter\Klášter\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IObit Malware Fighter] - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1573184 2013-12-13] (IObit)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdat
HKCU\...\Run: [Advanced SystemCare 7] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2285344 2013-12-09] (IObit)
AppInit_DLLs: [ ] ()
AppInit_DLLs-x32: [ ] ()
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKCU - DefaultScope {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms}
SearchScopes: HKCU - {5BCBE05D-5A31-4C80-BC31-84B3F159104D} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
FF Extension: Ads Removal - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\adsremoval@adsremoval.net
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\ascsurfingprotection@iobit.com
CHR DefaultSearchKeyword: yahoo.com
CHR DefaultSearchProvider: Yahoo!
CHR DefaultSearchURL: http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms}
CHR DefaultNewTabURL:
CHR Extension: (Ads Removal) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx
R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [881440 2013-12-09] (IObit)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [341824 2013-11-11] (IObit)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
S3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2013-11-19] (IObit.com)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] ()
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-11-19] (IObit.com)
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
2014-01-05 21:40 - 2014-01-05 21:40 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 21:37 - 2014-01-05 21:40 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-04 08:52 - 2014-01-04 08:52 - 00001237 _____ C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-01-04 08:52 - 2014-01-04 08:52 - 00001213 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-01-04 08:52 - 2013-11-10 22:57 - 00003098 _____ C:\Windows\System32\Tasks\ASC7_PerformanceMonitor
2014-01-04 08:52 - 2013-11-10 22:56 - 00002854 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Klášter
2014-01-04 08:52 - 2012-11-15 21:32 - 00000000 ____D C:\Program Files (x86)\IObit
2014-01-04 08:57 - 2013-11-10 22:56 - 00002205 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
C:\Users\Klášter\AppData\Local\Temp\Quarantine.exe
C:\Users\Klášter\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\IObit Malware Fighter => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 7 => Value not found.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5BCBE05D-5A31-4C80-BC31-84B3F159104D} => Key deleted successfully.
HKCR\CLSID\{5BCBE05D-5A31-4C80-BC31-84B3F159104D} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{665B0B23-55A0-45E5-B273-5C978B11DA74} => Key deleted successfully.
HKCR\CLSID\{665B0B23-55A0-45E5-B273-5C978B11DA74} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814} => Key not found.
HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} => Key not found.
HKCR\Wow6432Node\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} => Key not found.
C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\adsremoval@adsremoval.net => Moved successfully.
C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\ascsurfingprotection@iobit.com not found.
CHR DefaultSearchKeyword: yahoo.com ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchProvider: Yahoo! ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchURL: http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms} ==> The Chrome "Settings" can be used to fix the entry.
C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod => Moved successfully.
C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd => Moved successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd => Key not found.
"C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx" => File/Directory not found.
AdvancedSystemCareService7 => Service not found.
IMFservice => Service not found.
LiveUpdateSvc => Service deleted successfully.
FileMonitor => Service not found.
RegFilter => Service not found.
SmartDefragDriver => Service not found.
UrlFilter => Service not found.
pccsmcfd => Service deleted successfully.
C:\Users\Klášter\Desktop\LM.bat => Moved successfully.
C:\Users\Klášter\AppData\Local\MSGBOX.EXE => Moved successfully.
"C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk" => File/Directory not found.
"C:\Users\Public\Desktop\IObit Uninstaller.lnk" => File/Directory not found.
"C:\Windows\System32\Tasks\ASC7_PerformanceMonitor" => File/Directory not found.
"C:\Windows\System32\Tasks\ASC7_SkipUac_Klášter" => File/Directory not found.
C:\Program Files (x86)\IObit => Moved successfully.
"C:\Users\Public\Desktop\Advanced SystemCare 7.lnk" => File/Directory not found.
"C:\Users\Klášter\AppData\Local\Temp\Quarantine.exe" => File/Directory not found.
"C:\Users\Klášter\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe" => File/Directory not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====
Ran by Klášter at 2014-01-07 08:40:02 Run:1
Running from C:\Users\Klášter\Klášter\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IObit Malware Fighter] - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [1573184 2013-12-13] (IObit)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdat
HKCU\...\Run: [Advanced SystemCare 7] - C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe [2285344 2013-12-09] (IObit)
AppInit_DLLs: [ ] ()
AppInit_DLLs-x32: [ ] ()
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKCU - DefaultScope {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms}
SearchScopes: HKCU - {5BCBE05D-5A31-4C80-BC31-84B3F159104D} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {665B0B23-55A0-45E5-B273-5C978B11DA74} URL = http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms}
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll (IObit)
BHO-x32: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll (IObit)
FF Extension: Ads Removal - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\adsremoval@adsremoval.net
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\ascsurfingprotection@iobit.com
CHR DefaultSearchKeyword: yahoo.com
CHR DefaultSearchProvider: Yahoo!
CHR DefaultSearchURL: http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms}
CHR DefaultNewTabURL:
CHR Extension: (Ads Removal) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod\1.0.0_0
CHR Extension: (Advanced SystemCare Surfing Protection) - C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx
R2 AdvancedSystemCareService7; C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCService.exe [881440 2013-12-09] (IObit)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [341824 2013-11-11] (IObit)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
S3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [23048 2013-03-23] (IObit)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2013-11-19] (IObit.com)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [17720 2013-05-22] ()
S3 UrlFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [23016 2013-11-19] (IObit.com)
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
2014-01-05 21:40 - 2014-01-05 21:40 - 00015327 _____ C:\Users\Klášter\Desktop\LM.bat
2014-01-05 21:37 - 2014-01-05 21:40 - 00029696 _____ C:\Users\Klášter\AppData\Local\MSGBOX.EXE
2014-01-04 08:52 - 2014-01-04 08:52 - 00001237 _____ C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2014-01-04 08:52 - 2014-01-04 08:52 - 00001213 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2014-01-04 08:52 - 2013-11-10 22:57 - 00003098 _____ C:\Windows\System32\Tasks\ASC7_PerformanceMonitor
2014-01-04 08:52 - 2013-11-10 22:56 - 00002854 _____ C:\Windows\System32\Tasks\ASC7_SkipUac_Klášter
2014-01-04 08:52 - 2012-11-15 21:32 - 00000000 ____D C:\Program Files (x86)\IObit
2014-01-04 08:57 - 2013-11-10 22:56 - 00002205 _____ C:\Users\Public\Desktop\Advanced SystemCare 7.lnk
C:\Users\Klášter\AppData\Local\Temp\Quarantine.exe
C:\Users\Klášter\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Hosts:
CMD: shutdown /r /f /t 2
End
*****************
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\IObit Malware Fighter => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 7 => Value not found.
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5BCBE05D-5A31-4C80-BC31-84B3F159104D} => Key deleted successfully.
HKCR\CLSID\{5BCBE05D-5A31-4C80-BC31-84B3F159104D} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{665B0B23-55A0-45E5-B273-5C978B11DA74} => Key deleted successfully.
HKCR\CLSID\{665B0B23-55A0-45E5-B273-5C978B11DA74} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814} => Key not found.
HKCR\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} => Key not found.
HKCR\Wow6432Node\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} => Key not found.
C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\adsremoval@adsremoval.net => Moved successfully.
C:\Users\Klášter\AppData\Roaming\Mozilla\Firefox\Profiles\roivx0lz.default\Extensions\ascsurfingprotection@iobit.com not found.
CHR DefaultSearchKeyword: yahoo.com ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchProvider: Yahoo! ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSearchURL: http://search.yahoo.com/search?fr=chr-g ... =800236&p={searchTerms} ==> The Chrome "Settings" can be used to fix the entry.
C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkcefkcdkepgkpbgncjchhbjgoanleod => Moved successfully.
C:\Users\Klášter\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd => Moved successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd => Key not found.
"C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASC_GhromePlugin.crx" => File/Directory not found.
AdvancedSystemCareService7 => Service not found.
IMFservice => Service not found.
LiveUpdateSvc => Service deleted successfully.
FileMonitor => Service not found.
RegFilter => Service not found.
SmartDefragDriver => Service not found.
UrlFilter => Service not found.
pccsmcfd => Service deleted successfully.
C:\Users\Klášter\Desktop\LM.bat => Moved successfully.
C:\Users\Klášter\AppData\Local\MSGBOX.EXE => Moved successfully.
"C:\Users\Klášter\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk" => File/Directory not found.
"C:\Users\Public\Desktop\IObit Uninstaller.lnk" => File/Directory not found.
"C:\Windows\System32\Tasks\ASC7_PerformanceMonitor" => File/Directory not found.
"C:\Windows\System32\Tasks\ASC7_SkipUac_Klášter" => File/Directory not found.
C:\Program Files (x86)\IObit => Moved successfully.
"C:\Users\Public\Desktop\Advanced SystemCare 7.lnk" => File/Directory not found.
"C:\Users\Klášter\AppData\Local\Temp\Quarantine.exe" => File/Directory not found.
"C:\Users\Klášter\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe" => File/Directory not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
========= shutdown /r /f /t 2 =========
========= End of CMD: =========
==== End of Fixlog ====


Přispějete na provoz fóra?