Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Potřebuji kontrolu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Drakonus
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 07 led 2014 23:54

Potřebuji kontrolu

#1 Příspěvek od Drakonus »

Můžete se mi prosím na to podívat? :-)




Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-01-2014
Ran by Patrik (administrator) on PATRIK-PC on 08-01-2014 00:11:31
Running from C:\Users\Patrik\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
() C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
() C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe
(Akamai Technologies, Inc.) C:\Users\Patrik\AppData\Local\Akamai\netsession_win.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
(Akamai Technologies, Inc.) C:\Users\Patrik\AppData\Local\Akamai\netsession_win.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsAPHider\AsAPHider.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Patrik\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5617432 2013-08-19] (ESET)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] ()
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [msbvpiwSrv] - "C:\Windows\system32\msbvpiw.vbe" msajiy mscvnxp
HKLM-x32\...\Run: [Printsrv] - c:\Windows\System32\Printing_Admin_Scripts\en-US\driverupd.vbs
HKCU\...\Run: [OscarX7Mouse5Mode] - C:\Program Files (x86)\OscarX7Editor5Mode\OscarX7Editor5Mode\OscarEditor.exe [3521024 2012-03-20] ()
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKCU\...\Run: [Akamai NetSession Interface] - C:\Users\Patrik\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class - {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} - C:\Program Files (x86)\Perfect World Entertainment\Arc\plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37

FireFox:
========
FF ProfilePath: C:\Users\Patrik\AppData\Roaming\Mozilla\Firefox\Profiles\47d0n0lc.default-1383045575497
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin - C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Patrik\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Battlefield Heroes) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh\5.0.203.0_0
CHR Extension: (Google Search) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (GFACE Experience Plugin) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdlfmdbdibkbfdpjocdaolcheehmpol\0.39.0_0
CHR Extension: (Raptor Safari) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjlpfeclhbaeppnmdmlgnhiglkopphin\1.0.1_0
CHR Extension: (AdBlock Premium) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj\2.6.4.3_0
CHR Extension: (Tank Riders) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdmmodjlfegeieihcdcgcalkgmhgmiae\1.0.3_0
CHR Extension: (AdBlock) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (Tux Joker Dark Theme) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgenhbcaefgdnnkppjllhmfjgjnacnng\1_0
CHR Extension: (Google Wallet) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1
CHR Extension: (Battlefield Play4Free) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh\1.0.96.0_0
CHR Extension: (Gmail) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR Extension: (Cracking Sands Racing) - C:\Users\Patrik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnafpgbiiobelphegdbieldnmojicndb\1.0.1_0

==================== Services (Whitelisted) =================

S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88424 2013-10-10] (Perfect World Entertainment Inc)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [918144 2010-11-03] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [915584 2010-12-02] ()
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [586880 2010-10-21] ()
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337240 2013-08-19] (ESET)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-28] ()
S2 SetupARService; C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [24576 2013-10-25] (Realtek Semiconductor.)

==================== Drivers (Whitelisted) ====================

R0 AiChargerPlus; C:\Windows\System32\DRIVERS\AiChargerPlus.sys [14464 2010-11-08] (ASUSTek Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2010-08-24] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-10-25] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-08-20] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [168256 2013-08-20] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [220232 2013-08-20] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44120 2013-08-20] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-08-20] (ESET)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2013-10-25] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [239296 2013-08-26] (ESET)
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-08 00:11 - 2014-01-08 00:12 - 00015381 _____ C:\Users\Patrik\Desktop\FRST.txt
2014-01-08 00:11 - 2014-01-08 00:11 - 00000000 ____D C:\FRST
2014-01-08 00:08 - 2014-01-08 00:09 - 01931762 _____ (Farbar) C:\Users\Patrik\Desktop\FRST64.exe
2014-01-08 00:07 - 2014-01-08 00:08 - 00112640 _____ (forum.viry.cz) C:\Users\Patrik\Desktop\FRSTLauncher.exe
2014-01-08 00:03 - 2014-01-08 00:03 - 00000534 _____ C:\Windows\PFRO.log
2014-01-07 23:44 - 2014-01-07 23:44 - 00030785 _____ C:\ComboFix.txt
2014-01-07 23:08 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-07 23:08 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-07 23:08 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-07 23:08 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-07 23:08 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-07 23:08 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-07 23:08 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-07 23:08 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-07 23:07 - 2014-01-07 23:45 - 00000000 ____D C:\Qoobox
2014-01-07 23:07 - 2014-01-07 23:40 - 00000000 ____D C:\Windows\erdnt
2014-01-07 15:33 - 2014-01-08 00:03 - 00000672 _____ C:\Windows\setupact.log
2014-01-07 15:33 - 2014-01-07 15:33 - 00000000 _____ C:\Windows\setuperr.log
2014-01-07 00:09 - 2014-01-07 00:09 - 00007648 _____ C:\Users\Patrik\AppData\Local\Resmon.ResmonCfg
2014-01-07 00:07 - 2014-01-07 00:08 - 05160001 ____R (Swearware) C:\Users\Patrik\Downloads\ComboFix.exe
2014-01-06 22:00 - 2014-01-06 22:00 - 00943044 _____ C:\Windows\SysWOW64\scrypt130511GeForce GTX 560glg2tc1984w256l4.bin
2014-01-06 18:52 - 2014-01-06 18:52 - 00000000 ____D C:\Windows\bitstreams
2014-01-06 18:52 - 2013-05-31 16:32 - 01704448 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Windows\libeay32.dll
2014-01-06 18:52 - 2013-05-31 16:32 - 00612352 _____ (The cURL library, http://curl.haxx.se/) C:\Windows\libcurl.dll
2014-01-06 18:52 - 2013-05-31 16:32 - 00364544 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Windows\ssleay32.dll
2014-01-06 18:52 - 2013-05-31 16:32 - 00279955 _____ C:\Windows\libidn-11.dll
2014-01-06 18:52 - 2013-05-31 16:32 - 00206309 _____ C:\Windows\NEWS.txt
2014-01-06 18:52 - 2013-05-31 16:32 - 00183382 _____ C:\Windows\librtmp.dll
2014-01-06 18:52 - 2013-05-31 16:32 - 00171008 _____ (The libssh2 library, http://www.libssh2.org/) C:\Windows\libssh2.dll
2014-01-06 18:52 - 2013-05-31 16:32 - 00110094 _____ (libusb.org) C:\Windows\libusb-1.0.dll
2014-01-06 18:52 - 2013-05-31 16:32 - 00084992 _____ C:\Windows\zlib1.dll
2014-01-06 18:52 - 2013-05-31 16:32 - 00064577 _____ C:\Windows\miner.php
2014-01-06 18:52 - 2013-05-31 16:32 - 00049279 _____ C:\Windows\API-README.txt
2014-01-06 18:52 - 2013-05-31 16:32 - 00044727 _____ C:\Windows\diablo130302.cl
2014-01-06 18:52 - 2013-05-31 16:32 - 00043810 _____ C:\Windows\poclbm130302.cl
2014-01-06 18:52 - 2013-05-31 16:32 - 00035821 _____ C:\Windows\COPYING.txt
2014-01-06 18:52 - 2013-05-31 16:32 - 00030802 _____ C:\Windows\diakgcn121016.cl
2014-01-06 18:52 - 2013-05-31 16:32 - 00024624 _____ C:\Windows\GPU-README.txt
2014-01-06 18:52 - 2013-05-31 16:32 - 00023825 _____ C:\Windows\scrypt130511.cl
2014-01-06 18:52 - 2013-05-31 16:32 - 00015886 _____ C:\Windows\windows-build.txt
2014-01-06 18:52 - 2013-05-31 16:32 - 00013062 _____ C:\Windows\phatk121016.cl
2014-01-06 18:52 - 2013-05-31 16:32 - 00011728 _____ C:\Windows\FPGA-README.txt
2014-01-06 18:52 - 2013-05-31 16:32 - 00011166 _____ C:\Windows\linux-usb-cgminer.txt
2014-01-06 18:52 - 2013-05-31 16:32 - 00009998 _____ C:\Windows\SCRYPT-README.txt
2014-01-06 18:52 - 2013-05-31 16:32 - 00007530 _____ C:\Windows\api-example.c
2014-01-06 18:52 - 2013-05-31 16:32 - 00004108 _____ C:\Windows\ASIC-README.txt
2014-01-06 18:52 - 2013-05-31 16:32 - 00003431 _____ C:\Windows\API.class
2014-01-06 18:52 - 2013-05-31 16:32 - 00003306 _____ C:\Windows\API.java
2014-01-06 18:52 - 2013-05-31 16:32 - 00002174 _____ C:\Windows\api-example.php
2014-01-06 18:52 - 2013-05-31 16:32 - 00000763 _____ C:\Windows\example.conf
2014-01-06 18:52 - 2013-05-31 16:32 - 00000438 _____ C:\Windows\AUTHORS.txt
2014-01-06 18:40 - 2014-01-08 00:04 - 00000028 _____ C:\Users\Patrik\AppData\Roaming\msajiy.dat
2014-01-06 18:40 - 2014-01-07 23:05 - 00001705 _____ C:\Users\Patrik\AppData\Roaming\mscvnxp.dat
2014-01-06 18:39 - 2013-12-10 22:25 - 00005453 ____S C:\Windows\SysWOW64\msajiy.vbe
2014-01-06 18:39 - 2013-12-10 22:25 - 00001645 ____S C:\Windows\SysWOW64\mscvnxp.vbe
2014-01-06 18:39 - 2013-08-11 15:40 - 00043520 ____S (NirSoft) C:\Windows\SysWOW64\nircmdc.exe
2014-01-05 22:32 - 2014-01-05 22:44 - 732530174 ____R C:\Users\Patrik\Downloads\Jackass Presents Bad Grandpa.avi
2014-01-05 22:32 - 2014-01-05 22:32 - 00097776 ____R C:\Users\Patrik\Downloads\Bad Grandpa Titulky.srt
2014-01-03 23:51 - 2014-01-03 23:51 - 00000000 ____D C:\Users\Patrik\Downloads\Pár Pařmenů
2014-01-01 22:51 - 2014-01-01 22:54 - 00000000 ____D C:\Users\Patrik\Downloads\Hobit - Šmakova dračí poušť
2014-01-01 14:19 - 2014-01-01 14:19 - 00000000 ____D C:\Users\Patrik\AppData\Local\HemiSoft
2013-12-29 20:09 - 2013-12-29 20:09 - 00000000 ____D C:\Riot Games
2013-12-29 19:30 - 2013-12-29 21:43 - 2131294208 ____R C:\Users\Patrik\Downloads\2 zbraně.avi
2013-12-29 17:26 - 2013-12-29 17:26 - 00000000 ____H C:\Users\Patrik\Documents\Default.rdp
2013-12-26 18:16 - 2013-12-26 18:27 - 00000000 ____D C:\Users\Public\wow
2013-12-25 14:32 - 2013-12-25 14:32 - 00000000 ____D C:\Users\Patrik\aTubeCatcher
2013-12-25 13:38 - 2013-12-25 14:24 - 1782052864 ____R C:\Users\Patrik\Downloads\Millerovi na tripu.avi
2013-12-24 19:08 - 2013-12-24 19:08 - 00000222 _____ C:\Users\Patrik\Desktop\Call of Duty Black Ops II - Multiplayer.url
2013-12-22 01:34 - 2013-12-22 02:19 - 1849278464 ____R C:\Users\Patrik\Downloads\Kick-Ass 2.avi
2013-12-21 20:04 - 2013-12-21 20:04 - 00000000 ____D C:\Users\Patrik\Documents\Ghost Games
2013-12-21 12:43 - 2014-01-01 15:03 - 00000000 ____D C:\Users\Patrik\Documents\Soubory aplikace Outlook
2013-12-20 16:14 - 2014-01-06 18:47 - 00000000 ____D C:\Users\Patrik\AppData\Roaming\.minecraft
2013-12-18 20:26 - 2013-12-18 20:43 - 725263224 ____R C:\Users\Patrik\Downloads\asterix-a-obelix-mise-kleopatra-cz.avi
2013-12-15 02:00 - 2013-12-15 02:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-15 01:56 - 2013-12-15 01:56 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-12-15 01:56 - 2013-12-15 01:56 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-12-14 23:51 - 2013-12-15 00:06 - 00000000 ____D C:\Users\Patrik\Downloads\Elysium
2013-12-14 23:17 - 2013-12-14 23:49 - 00000000 ____D C:\Users\Patrik\Desktop\OVB
2013-12-14 23:12 - 2013-12-14 23:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2013-12-14 23:08 - 2013-12-22 10:13 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2013-12-14 23:07 - 2013-12-14 23:07 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-12-14 23:07 - 2013-12-14 23:07 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2013-12-14 23:06 - 2013-12-14 23:07 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-12-14 23:06 - 2013-12-14 23:06 - 00000000 ____D C:\Windows\PCHEALTH
2013-12-14 23:04 - 2013-12-15 02:04 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-14 23:04 - 2013-12-14 23:06 - 00000000 ____D C:\Program Files\Microsoft Office
2013-12-14 23:04 - 2013-12-14 23:04 - 00000000 ____D C:\Users\Patrik\AppData\Local\Microsoft Help
2013-12-14 23:04 - 2013-12-14 23:04 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-12-14 23:04 - 2013-12-14 23:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-12-14 23:04 - 2013-12-14 23:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2013-12-14 22:27 - 2013-12-14 22:27 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-12-13 18:54 - 2013-12-13 18:56 - 00000000 ____D C:\Program Files (x86)\Neverwinter_en
2013-12-13 18:51 - 2013-12-13 18:51 - 00000000 ____D C:\Program Files (x86)\Perfect World Entertainment
2013-12-12 13:42 - 2013-05-10 06:56 - 14631424 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2013-12-12 13:42 - 2013-05-10 06:56 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2013-12-12 13:42 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2013-12-12 13:42 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2013-12-12 13:41 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 13:41 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 13:41 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 13:41 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-12-12 13:41 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 13:41 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 13:41 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 13:41 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 13:41 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 13:41 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-12-12 13:41 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 13:41 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 13:41 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 13:41 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 13:41 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 13:41 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-12-12 13:41 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-12-12 13:41 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 13:41 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-12-12 13:41 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2013-12-12 13:41 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-12-12 13:41 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 13:41 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 13:41 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-12-12 13:41 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-12-12 13:41 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 13:41 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-12 13:41 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 13:41 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2013-12-12 13:41 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-12-12 13:41 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-12-12 11:58 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2013-12-12 11:58 - 2013-11-23 18:47 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2013-12-12 11:58 - 2013-11-12 03:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-12 11:58 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2013-12-12 11:58 - 2013-10-30 03:32 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2013-12-12 11:58 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msieftp.dll
2013-12-12 11:58 - 2013-10-30 02:24 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-12 11:58 - 2013-10-19 03:18 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-12 11:58 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imagehlp.dll
2013-12-12 11:58 - 2013-10-12 03:32 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-12 11:58 - 2013-10-12 03:31 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-12 11:58 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshom.ocx
2013-12-12 11:58 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrrun.dll
2013-12-12 11:58 - 2013-10-12 02:33 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-12 11:58 - 2013-10-12 02:33 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-12 11:58 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscript.exe
2013-12-12 11:58 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cscript.exe
2013-12-12 11:58 - 2013-10-04 03:16 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-12 11:58 - 2013-10-04 02:36 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys

==================== One Month Modified Files and Folders =======

2014-01-08 00:12 - 2014-01-08 00:11 - 00015381 _____ C:\Users\Patrik\Desktop\FRST.txt
2014-01-08 00:11 - 2014-01-08 00:11 - 00000000 ____D C:\FRST
2014-01-08 00:11 - 2009-07-14 05:45 - 00014224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-08 00:11 - 2009-07-14 05:45 - 00014224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-08 00:09 - 2014-01-08 00:08 - 01931762 _____ (Farbar) C:\Users\Patrik\Desktop\FRST64.exe
2014-01-08 00:08 - 2014-01-08 00:07 - 00112640 _____ (forum.viry.cz) C:\Users\Patrik\Desktop\FRSTLauncher.exe
2014-01-08 00:06 - 2013-10-03 10:54 - 01273988 _____ C:\Windows\WindowsUpdate.log
2014-01-08 00:04 - 2014-01-06 18:40 - 00000028 _____ C:\Users\Patrik\AppData\Roaming\msajiy.dat
2014-01-08 00:03 - 2014-01-08 00:03 - 00000534 _____ C:\Windows\PFRO.log
2014-01-08 00:03 - 2014-01-07 15:33 - 00000672 _____ C:\Windows\setupact.log
2014-01-08 00:03 - 2013-12-01 20:44 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1ceeecdc2c3882a.job
2014-01-08 00:03 - 2013-10-03 14:07 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-08 00:03 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-07 23:54 - 2013-10-03 14:56 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-07 23:50 - 2013-10-29 12:38 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1ced49b73ed0b78.job
2014-01-07 23:50 - 2013-10-29 12:34 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2014-01-07 23:45 - 2014-01-07 23:07 - 00000000 ____D C:\Qoobox
2014-01-07 23:45 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default
2014-01-07 23:44 - 2014-01-07 23:44 - 00030785 _____ C:\ComboFix.txt
2014-01-07 23:40 - 2014-01-07 23:07 - 00000000 ____D C:\Windows\erdnt
2014-01-07 23:25 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-07 23:05 - 2014-01-06 18:40 - 00001705 _____ C:\Users\Patrik\AppData\Roaming\mscvnxp.dat
2014-01-07 19:56 - 2013-10-04 16:17 - 00000000 ____D C:\Users\Patrik\AppData\Roaming\Skype
2014-01-07 15:57 - 2013-10-29 14:00 - 00000000 ____D C:\Users\Patrik\AppData\Local\PMB Files
2014-01-07 15:57 - 2013-10-29 14:00 - 00000000 ____D C:\ProgramData\PMB Files
2014-01-07 15:33 - 2014-01-07 15:33 - 00000000 _____ C:\Windows\setuperr.log
2014-01-07 00:09 - 2014-01-07 00:09 - 00007648 _____ C:\Users\Patrik\AppData\Local\Resmon.ResmonCfg
2014-01-07 00:08 - 2014-01-07 00:07 - 05160001 ____R (Swearware) C:\Users\Patrik\Downloads\ComboFix.exe
2014-01-07 00:01 - 2013-10-25 14:57 - 00000000 ____D C:\Users\Patrik\AppData\Roaming\DAEMON Tools Lite
2014-01-07 00:01 - 2013-10-19 20:48 - 00000000 ____D C:\Users\Patrik\AppData\Roaming\TS3Client
2014-01-07 00:01 - 2013-10-04 14:07 - 00000000 ____D C:\Program Files (x86)\Steam
2014-01-07 00:01 - 2013-10-03 16:27 - 00000000 ____D C:\Users\Patrik\AppData\Roaming\uTorrent
2014-01-06 22:00 - 2014-01-06 22:00 - 00943044 _____ C:\Windows\SysWOW64\scrypt130511GeForce GTX 560glg2tc1984w256l4.bin
2014-01-06 18:52 - 2014-01-06 18:52 - 00000000 ____D C:\Windows\bitstreams
2014-01-06 18:52 - 2009-07-14 16:18 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2014-01-06 18:47 - 2013-12-20 16:14 - 00000000 ____D C:\Users\Patrik\AppData\Roaming\.minecraft
2014-01-06 05:43 - 2013-10-03 19:38 - 00000000 ____D C:\Users\Patrik\AppData\Roaming\vlc
2014-01-05 22:44 - 2014-01-05 22:32 - 732530174 ____R C:\Users\Patrik\Downloads\Jackass Presents Bad Grandpa.avi
2014-01-05 22:32 - 2014-01-05 22:32 - 00097776 ____R C:\Users\Patrik\Downloads\Bad Grandpa Titulky.srt
2014-01-05 19:57 - 2013-08-11 14:04 - 00000000 ____D C:\Program Files (x86)\WOT
2014-01-03 23:51 - 2014-01-03 23:51 - 00000000 ____D C:\Users\Patrik\Downloads\Pár Pařmenů
2014-01-02 19:03 - 2013-10-19 09:12 - 00000000 ____D C:\Users\Patrik\Desktop\Hry
2014-01-02 11:05 - 2013-10-05 08:59 - 00282104 _____ C:\Windows\SysWOW64\PnkBstrB.xtr
2014-01-02 11:05 - 2013-10-04 14:52 - 00282104 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2014-01-02 11:05 - 2013-10-04 14:52 - 00234768 _____ C:\Windows\SysWOW64\PnkBstrB.ex0
2014-01-02 03:09 - 2013-10-03 14:05 - 01567972 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2014-01-02 03:09 - 2009-07-14 16:18 - 00672122 _____ C:\Windows\system32\perfh005.dat
2014-01-02 03:09 - 2009-07-14 16:18 - 00142810 _____ C:\Windows\system32\perfc005.dat
2014-01-02 03:09 - 2009-07-14 06:13 - 01567972 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-01 22:54 - 2014-01-01 22:51 - 00000000 ____D C:\Users\Patrik\Downloads\Hobit - Šmakova dračí poušť
2014-01-01 15:03 - 2013-12-21 12:43 - 00000000 ____D C:\Users\Patrik\Documents\Soubory aplikace Outlook
2014-01-01 14:19 - 2014-01-01 14:19 - 00000000 ____D C:\Users\Patrik\AppData\Local\HemiSoft
2013-12-30 12:49 - 2013-10-25 11:55 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-30 12:49 - 2013-10-25 11:55 - 00000000 ____D C:\Program Files\CCleaner
2013-12-29 21:43 - 2013-12-29 19:30 - 2131294208 ____R C:\Users\Patrik\Downloads\2 zbraně.avi
2013-12-29 20:09 - 2013-12-29 20:09 - 00000000 ____D C:\Riot Games
2013-12-29 20:09 - 2013-10-29 14:01 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
2013-12-29 17:26 - 2013-12-29 17:26 - 00000000 ____H C:\Users\Patrik\Documents\Default.rdp
2013-12-27 14:04 - 2013-11-11 19:33 - 00000000 ____D C:\Program Files (x86)\Panda
2013-12-26 18:27 - 2013-12-26 18:16 - 00000000 ____D C:\Users\Public\wow
2013-12-26 13:24 - 2013-10-07 16:57 - 00000000 ____D C:\Users\Patrik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2013-12-25 14:32 - 2013-12-25 14:32 - 00000000 ____D C:\Users\Patrik\aTubeCatcher
2013-12-25 14:32 - 2013-10-03 13:17 - 00000000 ____D C:\Users\Patrik
2013-12-25 14:24 - 2013-12-25 13:38 - 1782052864 ____R C:\Users\Patrik\Downloads\Millerovi na tripu.avi
2013-12-24 20:31 - 2013-10-05 11:18 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-12-24 20:31 - 2013-10-04 16:17 - 00000000 ____D C:\ProgramData\Skype
2013-12-24 19:08 - 2013-12-24 19:08 - 00000222 _____ C:\Users\Patrik\Desktop\Call of Duty Black Ops II - Multiplayer.url
2013-12-23 19:57 - 2013-12-03 13:31 - 00000000 ____D C:\ProgramData\Hi-Rez Studios
2013-12-23 19:57 - 2013-12-03 13:31 - 00000000 ____D C:\Program Files (x86)\Hi-Rez Studios
2013-12-23 19:57 - 2013-10-03 13:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-12-23 19:55 - 2013-10-23 15:56 - 00000669 _____ C:\Users\Patrik\Documents\Uninstall STAR WARS The Old Republic.log
2013-12-23 19:55 - 2013-10-07 13:56 - 00000000 ____D C:\Program Files (x86)\OutlastOutlast
2013-12-23 18:00 - 2013-11-13 12:57 - 00000000 ____D C:\Program Files (x86)\World of warcraft
2013-12-22 10:13 - 2013-12-14 23:08 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2013-12-22 10:13 - 2013-11-07 15:38 - 00000000 ____D C:\Users\Patrik\AppData\Local\Akamai
2013-12-22 10:13 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2013-12-22 02:19 - 2013-12-22 01:34 - 1849278464 ____R C:\Users\Patrik\Downloads\Kick-Ass 2.avi
2013-12-21 20:04 - 2013-12-21 20:04 - 00000000 ____D C:\Users\Patrik\Documents\Ghost Games
2013-12-18 20:43 - 2013-12-18 20:26 - 725263224 ____R C:\Users\Patrik\Downloads\asterix-a-obelix-mise-kleopatra-cz.avi
2013-12-17 16:15 - 2013-10-06 13:36 - 00000000 ____D C:\Users\Patrik\Documents\My Games
2013-12-17 13:35 - 2013-12-04 17:54 - 00000003 _____ C:\Windows\system32\HRUPPROG.TXT
2013-12-16 10:08 - 2013-10-05 10:27 - 00000000 ____D C:\Windows\system32\MRT
2013-12-16 10:06 - 2013-10-05 10:27 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-16 01:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-12-15 02:19 - 2009-07-14 05:45 - 00441744 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-15 02:04 - 2013-12-14 23:04 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-15 02:04 - 2009-07-14 03:34 - 00000541 _____ C:\Windows\win.ini
2013-12-15 02:00 - 2013-12-15 02:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-15 01:56 - 2013-12-15 01:56 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2013-12-15 01:56 - 2013-12-15 01:56 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2013-12-15 00:06 - 2013-12-14 23:51 - 00000000 ____D C:\Users\Patrik\Downloads\Elysium
2013-12-14 23:49 - 2013-12-14 23:17 - 00000000 ____D C:\Users\Patrik\Desktop\OVB
2013-12-14 23:16 - 2013-10-04 12:15 - 00111520 _____ C:\Users\Patrik\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-14 23:12 - 2013-12-14 23:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2013-12-14 23:12 - 2009-07-14 16:37 - 00000000 ____D C:\Windows\ShellNew
2013-12-14 23:11 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2013-12-14 23:07 - 2013-12-14 23:07 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2013-12-14 23:07 - 2013-12-14 23:07 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2013-12-14 23:07 - 2013-12-14 23:06 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2013-12-14 23:06 - 2013-12-14 23:06 - 00000000 ____D C:\Windows\PCHEALTH
2013-12-14 23:06 - 2013-12-14 23:04 - 00000000 ____D C:\Program Files\Microsoft Office
2013-12-14 23:05 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\System
2013-12-14 23:04 - 2013-12-14 23:04 - 00000000 ____D C:\Users\Patrik\AppData\Local\Microsoft Help
2013-12-14 23:04 - 2013-12-14 23:04 - 00000000 ____D C:\Program Files\Microsoft Analysis Services
2013-12-14 23:04 - 2013-12-14 23:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2013-12-14 23:04 - 2013-12-14 23:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2013-12-14 22:27 - 2013-12-14 22:27 - 00000000 ____D C:\Program Files (x86)\MSECache
2013-12-14 09:01 - 2009-07-14 06:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2013-12-13 18:56 - 2013-12-13 18:54 - 00000000 ____D C:\Program Files (x86)\Neverwinter_en
2013-12-13 18:51 - 2013-12-13 18:51 - 00000000 ____D C:\Program Files (x86)\Perfect World Entertainment
2013-12-11 10:54 - 2013-10-03 14:56 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-11 10:54 - 2013-10-03 14:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-11 10:54 - 2013-10-03 14:56 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 22:25 - 2014-01-06 18:39 - 00005453 ____S C:\Windows\SysWOW64\msajiy.vbe
2013-12-10 22:25 - 2014-01-06 18:39 - 00001645 ____S C:\Windows\SysWOW64\mscvnxp.vbe

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


testsigning: ==> Check for possible unsigned rootkit driver <===== ATTENTION!


nointegritychecks: ==> Integrity Checks is disabled <===== ATTENTION!


LastRegBack: 2013-12-30 03:15




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:931.51 GB) (Free:632.8 GB) NTFS ==>[Drive with boot components (obtained from BCD)]

Available physical RAM: 5985.16 MB
Total physical RAM: 8154.44 MB
Percentage of memory in use: 26%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 239E239E)
Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1ceeecdc2c3882a.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1ced49b73ed0b78.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\ProgramData:gs5sys
AlternateDataStreams: C:\Users\All Users:gs5sys
AlternateDataStreams: C:\Users\Patrik:gs5sys
AlternateDataStreams: C:\ProgramData\Application Data:gs5sys
AlternateDataStreams: C:\ProgramData\Data aplikací:gs5sys
AlternateDataStreams: C:\ProgramData\Templates:gs5sys
AlternateDataStreams: C:\ProgramData\Šablony:gs5sys
AlternateDataStreams: C:\Users\Patrik\Data aplikací:gs5sys
AlternateDataStreams: C:\Users\Patrik\Local Settings:gs5sys
AlternateDataStreams: C:\Users\Patrik\Soubory cookie:gs5sys
AlternateDataStreams: C:\Users\Patrik\Šablony:gs5sys
AlternateDataStreams: C:\Users\Patrik\Desktop\desktop.ini:gs5sys
AlternateDataStreams: C:\Users\Patrik\AppData\Local:gs5sys
AlternateDataStreams: C:\Users\Patrik\AppData\Roaming:gs5sys
AlternateDataStreams: C:\Users\Patrik\AppData\Local\Data aplikací:gs5sys
AlternateDataStreams: C:\Users\Patrik\AppData\Local\History:gs5sys
AlternateDataStreams: C:\Users\Patrik\Documents\desktop.ini:gs5sys
AlternateDataStreams: C:\Users\Public\Documents\desktop.ini:gs5sys

==================== Security Center ==================

AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Patrik\Desktop" je 1391 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
DoNotAllowExceptions REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Potřebuji kontrolu

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Jen se zeptam pouzivate legalni operacni system, nejvyssi licence Ultimate zrovna neni bezna. :?:

:arrow: Ten ComboFix Vam tam poradil kdo??

:arrow: Licencni podminky ComboFixu hovori jasne "Nikdy by nemel byt pouzit v prostredi bez dozoru zkusene osoby"
Obrázek

:arrow: Nebezpeci CFka
  • Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
  • Maze stopy po haveti, takze v logu z RSIT neni nic videt
  • Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
  • CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
  • CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Drakonus
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 07 led 2014 23:54

Re: Potřebuji kontrolu

#3 Příspěvek od Drakonus »

Heh no legalni system nemam:-/
A ten Combofix sem si nasel.Mel sem podezreni nejake haveti co NOD nenasel.

Pc mel nejakou slabost na vykon. Pri spusti se zacinal vic zahrivat a cpu pracovalo na 30% a vic
RAMky meli frekvenci myslim 1066 misto 1333 a cpu bylo nataktovano na 4ghz. Uz sem si nevedel rady kdyz sem to dal do normalu. Tak sem pouzil combo ale myslim ze pc je v normalu nemel sem cas to otestovat. Kdyz tak dodam potrebny log.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Potřebuji kontrolu

#4 Příspěvek od vyosek »

:arrow: Najit jste si ho nasel, ale uz nectete co po Vas CF chce a na co varuje

:arrow: Taktez nectete pravidla fora
Pomáhat NELZE:
2) Pokud stroj uživatele obsahuje nelegální hostitelský čí ochranný software
(operační systém, antivir, firewall, atd.)
Je mi tedy lito, ale dale nemohu s radami pokracovat :closed:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět