zasekaný netobook prosím o kontrolu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
trken
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 12 Dub 2014 09:37

zasekaný netobook prosím o kontrolu

#1 Příspěvek od trken »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-04-2014
Ran by Marek (administrator) on MAREK-HP on 12-04-2014 11:15:27
Running from C:\Users\Marek\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(AMD) C:\windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Hewlett-Packard Company) C:\windows\system32\Hpservice.exe
(Validity Sensors, Inc.) C:\windows\system32\vcsFPService.exe
(AMD) C:\windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hewlett-Packard Company) c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
() C:\windows\system32\dmwu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
() C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe
() C:\windows\SysWOW64\PnkBstrA.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(ArcSoft, Inc.) C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
() C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Windows\SysWOW64\jmdp\stij.exe
() C:\Windows\System32\ljkb\stij.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Portrait Displays, Inc) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe
(Intel Corporation) C:\windows\system32\igfxext.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Users\Marek\Downloads\FRST64(1).exe
(forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\windows\SysWOW64\PING.EXE


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HPPowerAssistant] - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2919992 2011-01-27] (Hewlett-Packard Company)
HKLM\...\Run: [MfeEpePcMonitor] - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [200704 2013-02-01] ()
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-05-29] (IDT, Inc.)
HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-08-19] (Qualcomm Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-12-18] (Synaptics Incorporated)
HKLM-x32\...\Run: [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [12274688 2011-02-07] (Hewlett-Packard)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] - c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [HP HD Webcam [Fixed]_Monitor] - C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [267128 2010-11-26] ()
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [DTRun] - c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [517456 2010-11-24] (ArcSoft Inc.)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [Sweetpacks Communicator] - C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [333728 2012-06-20] (Hewlett-Packard Company)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [HPQuickWebProxy] - C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [169528 2013-08-14] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [184736 2012-09-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-08-11] (PDF Complete Inc)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\windows\System32\SPReview\SPReview.exe [301568 2013-03-21] (Microsoft Corporation)
HKU\.DEFAULT\...\Policies\system: [LogonHoursAction] 2
HKU\.DEFAULT\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-19\...\RunOnce: [] - [X]
HKU\S-1-5-20\...\RunOnce: [] - [X]
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [PCSpeedUp] - C:\Program Files (x86)\Zrychleni Pocitace\PCSpeedUp.lnk [2421 2011-10-07] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1632680 2013-03-15] (Valve Corporation)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [RoboForm] - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [96056 2012-07-01] (Siber Systems)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [DAEMON Tools Lite] - C:\Users\Marek\Desktop\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Marek\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: D - D:\LaunchU3.exe -a
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: G - G:\Autorun.exe
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {4945ed31-e8f7-11e0-91ff-d0df9a83b284} - D:\LaunchU3.exe -a
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {675cb4f5-110d-11e2-8c8c-d0df9a83b284} - D:\autorun.exe
Lsa: [Notification Packages] EpePcNp64 DPPassFilter scecli

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5211
URLSearchHook: HKLM-x32 - (No Name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
URLSearchHook: HKCU - (No Name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... earchTerms}
SearchScopes: HKCU - {081195C4-99E7-43AE-827C-4C0E73F36079} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTe ... 3&tsp=5211
SearchScopes: HKCU - {1C2920AB-9D92-458F-BEB6-605293C9B344} URL = http://websearch.ask.com/redirect?clien ... 23779F55B5
SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKCU - {328E4130-2CF7-4428-B221-2FFC6F23E707} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {46681A16-F188-4F4E-B5E0-B1B6CEAA2949} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKCU - {58288FB1-5AB9-4ACE-B2ED-8C5C00655A58} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
SearchScopes: HKCU - {64C1301A-8756-4AB3-A952-CF5F712FCA3B} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKCU - {BCD40402-51BD-4984-A396-EB39C29F9735} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKCU - {C2E7B0A1-F210-4BF8-9DAE-671BE418AE12} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKCU - {E2F0CC30-E546-4367-A763-B651B2849BD5} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://mysearch.sweetpacks.com?src=6&q= ... id=&&st=23
SearchScopes: HKCU - {F2968A10-6F79-4FEB-BF75-BE8CDFF6DEFA} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
BHO-x32: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO-x32: buenosearch Helper Object - {F1C81E40-2485-4DB6-8C9D-04BD596B281E} - C:\Program Files (x86)\buenosearch LTD\buenosearch\1.8.28.7\bh\buenosearch.dll (Montiera Technologies LTD)
Toolbar: HKLM - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - No Name - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
Toolbar: HKLM-x32 - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} - No File
Toolbar: HKLM-x32 - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - buenosearch Toolbar - {828DC97A-2277-4E10-92A9-4907FA0922A9} - C:\Program Files (x86)\buenosearch LTD\buenosearch\1.8.28.7\buenosearchTlbr.dll (Montiera Technologies LTD)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - avast! EasyPass Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.3.1

FireFox:
========
FF ProfilePath: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default
FF user.js: detected! => C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\user.js
FF NewTab: hxxp://www.sweetpacks-search.com/?barid=&src=97&&st=23
FF DefaultSearchEngine: Sweetpacks Search
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Sweetpacks Search
FF Homepage: hxxp://www.sweetpacks-search.com/?barid=&src=10&&st=23
FF Keyword.URL: hxxp://mysearch.sweetpacks.com?src=6&barid=&&st=23&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\buenosearch.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\MyStart Search.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\MyStart.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\sweetim.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\Sweetpacks Search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: FreeHD-Sport TV V9.0 - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\aba3db73-c9bd-47b3-99c1-ebaf0b0b87ad@c4364137-5195-4339-81dd-ebf2e8579728.com [2014-04-08]
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\cs@dictionaries.addons.mozilla.org [2013-01-12]
FF Extension: DoNotTrackMe: Online Privacy Protection - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\donottrackplus@abine.com [2014-03-13]
FF Extension: BuenoSearch - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\ffxtlbr@buenosearch.com [2014-04-08]
FF Extension: Temp Installer - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{77868449-f49d-d6ec-3145-e651161b1ff8} [2013-06-14]
FF Extension: Seznam lištička - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-06-14]
FF Extension: Adblock Plus - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-07-29]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-30]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-11-27]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta706.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta706\ff
FF Extension: Video Player - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta706\ff [2014-01-10]

Chrome:
=======
CHR HomePage: hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5211
CHR DefaultSearchKeyword: sweetpacks-search.com
CHR DefaultSearchProvider: Sweetpacks
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U6) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.60.24) - C:\windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (Google Drive) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-11-09]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2013-06-14]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-06-14]
CHR Extension: (YouTube) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-09]
CHR Extension: (FreeHD-Sport TV V9.0) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\clkckblnmlbemmgefidhlmjcfboijafe [2014-04-08]
CHR Extension: (Google Search) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-09]
CHR Extension: (Video Player) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\kebgadnalhlpkjgjldclfinbfldjhpba [2014-01-10]
CHR Extension: (Skype Click to Call) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-07-20]
CHR Extension: (Google Wallet) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-30]
CHR Extension: (SweetPacks Chrome Extension) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2013-09-27]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-06-14]
CHR Extension: (Gmail) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-09]
CHR HKLM-x32\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\Marek\AppData\Local\Temp\crx13D0.tmp [2012-11-09]
CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2012-11-09]
CHR HKLM-x32\...\Chrome\Extension: [kebgadnalhlpkjgjldclfinbfldjhpba] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta706\ch\VideoPlayerV3beta706.crx [2014-01-07]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03]
CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\SysWOW64\jmdp\SweetNT.crx [2014-04-06]

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-19] (Qualcomm Atheros Commnucations)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [486224 2011-11-10] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [464480 2011-02-04] (Hewlett-Packard Company)
R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [133688 2011-01-28] (Hewlett-Packard Company)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-06-20] (Hewlett-Packard Company)
R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [2276144 2014-04-07] ()
R2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1323008 2013-02-01] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-11] (PDF Complete Inc)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75136 2012-10-11] ()
R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc.)
S2 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [62184 2011-03-07] (Xobni Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-19] (Atheros)

==================== Drivers (Whitelisted) ====================

R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-27] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-27] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-27] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-03-14] ()
R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2012-08-19] (Qualcomm Atheros)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [63336 2011-02-07] (Hewlett-Packard Company)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2012-10-08] (DT Soft Ltd)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-03-14] ()
R0 MfeEpeOpal; C:\Windows\System32\Drivers\MfeEpeOpal.sys [101288 2013-02-01] (McAfee, Inc.)
R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [158888 2013-02-01] (McAfee, Inc.)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [2611704 2011-01-12] (Sunplus Technology)
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Classic\safedrv.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-12 11:15 - 2014-04-12 11:15 - 00034906 _____ () C:\Users\Marek\Desktop\FRST.txt
2014-04-12 11:15 - 2014-04-12 11:15 - 00015327 _____ () C:\Users\Marek\Desktop\LM.bat
2014-04-12 11:14 - 2014-04-12 11:15 - 00029696 _____ () C:\Users\Marek\AppData\Local\MSGBOX.EXE
2014-04-12 11:13 - 2014-04-12 11:13 - 00000097 _____ () C:\Users\Marek\Downloads\FRST.txt
2014-04-12 11:09 - 2014-04-12 11:09 - 00112640 _____ (forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
2014-04-12 11:08 - 2014-04-12 11:09 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64(1).exe
2014-04-12 11:02 - 2014-04-12 11:02 - 00000000 _____ () C:\windows\SysWOW64\sho649D.tmp
2014-04-12 11:01 - 2014-04-12 11:01 - 00000000 ____D () C:\windows\SysWOW64\jmdp
2014-04-12 11:01 - 2014-04-12 11:01 - 00000000 ____D () C:\windows\system32\ljkb
2014-04-12 10:55 - 2014-04-12 11:13 - 00045306 _____ () C:\Users\Marek\Downloads\Addition.txt
2014-04-12 10:53 - 2014-04-12 11:15 - 00000000 ____D () C:\FRST
2014-04-12 10:50 - 2014-04-12 10:51 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64.exe
2014-04-09 12:50 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-09 12:50 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-09 12:50 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-04-09 12:50 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-04-09 12:50 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2014-04-09 12:49 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2014-04-09 12:49 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2014-04-09 12:49 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2014-04-09 12:49 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2014-04-09 12:49 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2014-04-09 12:48 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2014-04-09 12:48 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2014-04-09 12:48 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2014-04-09 12:48 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2014-04-09 12:48 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2014-04-09 12:48 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2014-04-08 23:03 - 2014-04-08 23:03 - 00000000 _____ () C:\windows\SysWOW64\sho7E43.tmp
2014-04-08 21:37 - 2014-04-08 21:37 - 00003158 _____ () C:\windows\System32\Tasks\{7A144C18-F2E8-4018-83D9-818D6C8A98E8}
2014-04-08 21:36 - 2014-04-08 21:36 - 00003388 _____ () C:\windows\System32\Tasks\EPUpdater
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Users\Marek\AppData\Roaming\buenosearch LTD
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Program Files (x86)\buenosearch LTD
2014-04-08 21:35 - 2014-04-12 11:04 - 00003132 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job
2014-04-08 21:35 - 2014-04-12 11:04 - 00002544 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job
2014-04-08 21:35 - 2014-04-12 11:04 - 00001622 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job
2014-04-08 21:35 - 2014-04-12 11:04 - 00001538 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job
2014-04-08 21:35 - 2014-04-08 21:35 - 00006162 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3
2014-04-08 21:35 - 2014-04-08 21:35 - 00005574 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4
2014-04-08 21:35 - 2014-04-08 21:35 - 00004652 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5
2014-04-08 21:35 - 2014-04-08 21:35 - 00004568 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1
2014-04-08 21:34 - 2014-04-08 21:35 - 00000000 ____D () C:\Program Files (x86)\FreeHD-Sport TV V9.0
2014-04-08 21:24 - 2014-04-08 21:25 - 00565320 _____ () C:\Users\Marek\Downloads\NeoliveApp_setup(18_3f)_ff.exe
2014-04-07 22:44 - 2014-04-07 22:44 - 00000000 _____ () C:\windows\SysWOW64\sho9EAF.tmp
2014-04-03 21:48 - 2014-04-03 21:48 - 00219550 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society(1).pptx
2014-04-03 21:47 - 2014-03-31 13:07 - 00022449 _____ () C:\Users\Marek\Downloads\food and meal prezentace.odp
2014-04-03 21:46 - 2014-04-03 21:46 - 00065992 _____ () C:\Users\Marek\Downloads\Traveling.pptx
2014-04-03 10:47 - 2014-04-03 10:47 - 00219533 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society.pptx
2014-04-02 23:13 - 2014-04-02 23:13 - 00000000 _____ () C:\windows\SysWOW64\sho78A8.tmp
2014-04-02 10:48 - 2014-04-10 17:09 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForMarek
2014-04-02 10:48 - 2014-04-10 17:09 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForMarek.job
2014-04-01 23:10 - 2014-04-01 23:10 - 00000000 _____ () C:\windows\SysWOW64\sho667D.tmp
2014-03-31 13:32 - 2014-03-31 13:34 - 00699763 _____ () C:\Users\Marek\Downloads\NATURE, ENVIROMENT, ECOLOGY.pptx
2014-03-30 21:04 - 2014-03-30 21:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 01:06 - 2014-03-27 01:06 - 00000000 _____ () C:\windows\SysWOW64\sho872C.tmp
2014-03-26 00:08 - 2014-03-26 00:08 - 00000000 _____ () C:\windows\SysWOW64\sho6BA0.tmp
2014-03-25 20:19 - 2014-03-25 20:19 - 00066695 _____ () C:\Users\Marek\Downloads\School and education, your studies.pptx
2014-03-24 23:59 - 2014-03-24 23:59 - 00000000 _____ () C:\windows\SysWOW64\shoD96E.tmp
2014-03-24 13:18 - 2014-03-24 13:18 - 00751791 _____ () C:\Users\Marek\Downloads\Prezentace Opava.pptx
2014-03-24 00:32 - 2014-03-24 00:32 - 00000000 _____ () C:\windows\SysWOW64\shoAD5A.tmp
2014-03-21 00:20 - 2014-03-21 00:20 - 00000000 _____ () C:\windows\SysWOW64\sho6808.tmp
2014-03-18 23:10 - 2014-03-18 23:10 - 00000000 _____ () C:\windows\SysWOW64\shoB471.tmp
2014-03-15 02:47 - 2014-03-15 02:47 - 00000000 _____ () C:\windows\SysWOW64\sho61B2.tmp
2014-03-13 08:42 - 2014-04-09 07:12 - 00004582 _____ () C:\windows\PFRO.log

==================== One Month Modified Files and Folders =======

2014-04-12 11:15 - 2014-04-12 11:15 - 00034906 _____ () C:\Users\Marek\Desktop\FRST.txt
2014-04-12 11:15 - 2014-04-12 11:15 - 00015327 _____ () C:\Users\Marek\Desktop\LM.bat
2014-04-12 11:15 - 2014-04-12 11:14 - 00029696 _____ () C:\Users\Marek\AppData\Local\MSGBOX.EXE
2014-04-12 11:15 - 2014-04-12 10:53 - 00000000 ____D () C:\FRST
2014-04-12 11:13 - 2014-04-12 11:13 - 00000097 _____ () C:\Users\Marek\Downloads\FRST.txt
2014-04-12 11:13 - 2014-04-12 10:55 - 00045306 _____ () C:\Users\Marek\Downloads\Addition.txt
2014-04-12 11:12 - 2009-07-14 06:45 - 00020944 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-12 11:12 - 2009-07-14 06:45 - 00020944 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-12 11:11 - 2012-06-27 07:26 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-12 11:09 - 2014-04-12 11:09 - 00112640 _____ (forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
2014-04-12 11:09 - 2014-04-12 11:08 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64(1).exe
2014-04-12 11:09 - 2011-08-23 12:48 - 02060409 _____ () C:\windows\WindowsUpdate.log
2014-04-12 11:06 - 2011-11-16 16:50 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-04-12 11:06 - 2011-05-12 02:05 - 00000000 ____D () C:\ProgramData\PDFC
2014-04-12 11:04 - 2014-04-08 21:35 - 00003132 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job
2014-04-12 11:04 - 2014-04-08 21:35 - 00002544 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job
2014-04-12 11:04 - 2014-04-08 21:35 - 00001622 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job
2014-04-12 11:04 - 2014-04-08 21:35 - 00001538 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job
2014-04-12 11:04 - 2013-06-14 09:43 - 00000356 _____ () C:\windows\Tasks\AmiUpdXp.job
2014-04-12 11:04 - 2012-11-09 12:47 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-12 11:03 - 2014-03-11 10:35 - 00002750 _____ () C:\windows\setupact.log
2014-04-12 11:03 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-12 11:02 - 2014-04-12 11:02 - 00000000 _____ () C:\windows\SysWOW64\sho649D.tmp
2014-04-12 11:01 - 2014-04-12 11:01 - 00000000 ____D () C:\windows\SysWOW64\jmdp
2014-04-12 11:01 - 2014-04-12 11:01 - 00000000 ____D () C:\windows\system32\ljkb
2014-04-12 11:00 - 2012-08-21 18:09 - 00000000 ____D () C:\Users\Marek\AppData\Local\PMB Files
2014-04-12 10:51 - 2014-04-12 10:50 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64.exe
2014-04-12 10:47 - 2012-11-09 12:47 - 00000950 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-12 10:31 - 2013-04-13 15:46 - 00000000 ____D () C:\Users\Marek\AppData\Roaming\Skype
2014-04-12 09:40 - 2013-06-02 11:38 - 00000000 ____D () C:\windows\SysWOW64\WNLT
2014-04-12 09:40 - 2013-06-02 11:38 - 00000000 ____D () C:\windows\SysWOW64\ARFC
2014-04-12 00:24 - 2012-08-21 18:09 - 00000000 ____D () C:\ProgramData\PMB Files
2014-04-11 20:35 - 2011-09-28 12:26 - 00000000 ____D () C:\Users\Marek\AppData\Local\CrashDumps
2014-04-11 09:52 - 2012-11-09 12:50 - 00002143 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-11 09:35 - 2012-07-01 17:51 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-04-10 17:09 - 2014-04-02 10:48 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForMarek
2014-04-10 17:09 - 2014-04-02 10:48 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForMarek.job
2014-04-10 12:12 - 2012-08-29 11:41 - 00000000 ____D () C:\Users\Marek\AppData\Local\Adobe
2014-04-10 12:12 - 2012-06-27 07:26 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-04-10 12:12 - 2012-06-27 07:25 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-04-10 12:12 - 2011-09-29 11:00 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-10 12:08 - 2011-09-27 21:20 - 00000000 ____D () C:\windows\rescache
2014-04-10 08:50 - 2012-06-04 16:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-10 08:48 - 2013-07-22 07:14 - 00000000 ____D () C:\windows\system32\MRT
2014-04-10 08:43 - 2013-03-27 09:56 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-09 12:39 - 2013-12-25 11:44 - 00000052 _____ () C:\windows\SysWOW64\DOErrors.log
2014-04-09 12:38 - 2011-11-30 15:37 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-04-09 07:12 - 2014-03-13 08:42 - 00004582 _____ () C:\windows\PFRO.log
2014-04-08 23:03 - 2014-04-08 23:03 - 00000000 _____ () C:\windows\SysWOW64\sho7E43.tmp
2014-04-08 21:37 - 2014-04-08 21:37 - 00003158 _____ () C:\windows\System32\Tasks\{7A144C18-F2E8-4018-83D9-818D6C8A98E8}
2014-04-08 21:36 - 2014-04-08 21:36 - 00003388 _____ () C:\windows\System32\Tasks\EPUpdater
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Users\Marek\AppData\Roaming\buenosearch LTD
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Program Files (x86)\buenosearch LTD
2014-04-08 21:35 - 2014-04-08 21:35 - 00006162 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3
2014-04-08 21:35 - 2014-04-08 21:35 - 00005574 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4
2014-04-08 21:35 - 2014-04-08 21:35 - 00004652 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5
2014-04-08 21:35 - 2014-04-08 21:35 - 00004568 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1
2014-04-08 21:35 - 2014-04-08 21:34 - 00000000 ____D () C:\Program Files (x86)\FreeHD-Sport TV V9.0
2014-04-08 21:25 - 2014-04-08 21:24 - 00565320 _____ () C:\Users\Marek\Downloads\NeoliveApp_setup(18_3f)_ff.exe
2014-04-08 16:40 - 2012-09-12 08:16 - 00000000 ____D () C:\Users\Marek\Desktop\škola
2014-04-08 09:08 - 2011-05-12 02:04 - 00671360 _____ () C:\windows\system32\perfh005.dat
2014-04-08 09:08 - 2011-05-12 02:04 - 00142682 _____ () C:\windows\system32\perfc005.dat
2014-04-08 09:08 - 2009-07-14 07:13 - 01586106 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-07 22:44 - 2014-04-07 22:44 - 00000000 _____ () C:\windows\SysWOW64\sho9EAF.tmp
2014-04-07 16:57 - 2013-06-02 11:38 - 02276144 _____ () C:\windows\system32\dmwu.exe
2014-04-07 16:55 - 2013-06-02 11:38 - 00033792 _____ (IncrediMail, Ltd.) C:\windows\system32\ImHttpComm.dll
2014-04-07 10:05 - 2011-09-27 12:35 - 00000000 ____D () C:\Users\Marek\Documents\Bluetooth Folder
2014-04-03 21:48 - 2014-04-03 21:48 - 00219550 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society(1).pptx
2014-04-03 21:46 - 2014-04-03 21:46 - 00065992 _____ () C:\Users\Marek\Downloads\Traveling.pptx
2014-04-03 10:47 - 2014-04-03 10:47 - 00219533 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society.pptx
2014-04-03 07:42 - 2012-11-09 12:47 - 00003946 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-03 07:42 - 2012-11-09 12:47 - 00003694 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-02 23:13 - 2014-04-02 23:13 - 00000000 _____ () C:\windows\SysWOW64\sho78A8.tmp
2014-04-02 11:09 - 2011-09-27 12:25 - 00000000 ____D () C:\Users\Marek
2014-04-01 23:10 - 2014-04-01 23:10 - 00000000 _____ () C:\windows\SysWOW64\sho667D.tmp
2014-03-31 20:01 - 2012-08-13 20:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-31 13:34 - 2014-03-31 13:32 - 00699763 _____ () C:\Users\Marek\Downloads\NATURE, ENVIROMENT, ECOLOGY.pptx
2014-03-31 13:07 - 2014-04-03 21:47 - 00022449 _____ () C:\Users\Marek\Downloads\food and meal prezentace.odp
2014-03-31 03:16 - 2014-04-09 12:50 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 12:50 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 12:50 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 12:50 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-30 21:04 - 2014-03-30 21:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 08:20 - 2009-07-14 07:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2014-03-27 01:06 - 2014-03-27 01:06 - 00000000 _____ () C:\windows\SysWOW64\sho872C.tmp
2014-03-26 00:08 - 2014-03-26 00:08 - 00000000 _____ () C:\windows\SysWOW64\sho6BA0.tmp
2014-03-25 20:19 - 2014-03-25 20:19 - 00066695 _____ () C:\Users\Marek\Downloads\School and education, your studies.pptx
2014-03-24 23:59 - 2014-03-24 23:59 - 00000000 _____ () C:\windows\SysWOW64\shoD96E.tmp
2014-03-24 13:18 - 2014-03-24 13:18 - 00751791 _____ () C:\Users\Marek\Downloads\Prezentace Opava.pptx
2014-03-24 00:32 - 2014-03-24 00:32 - 00000000 _____ () C:\windows\SysWOW64\shoAD5A.tmp
2014-03-21 00:20 - 2014-03-21 00:20 - 00000000 _____ () C:\windows\SysWOW64\sho6808.tmp
2014-03-20 23:41 - 2011-09-27 12:25 - 00003218 _____ () C:\windows\System32\Tasks\HPCeeScheduleForMAREK-HP$
2014-03-20 23:41 - 2011-09-27 12:25 - 00000342 _____ () C:\windows\Tasks\HPCeeScheduleForMAREK-HP$.job
2014-03-18 23:10 - 2014-03-18 23:10 - 00000000 _____ () C:\windows\SysWOW64\shoB471.tmp
2014-03-16 11:18 - 2013-04-13 15:46 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-15 02:47 - 2014-03-15 02:47 - 00000000 _____ () C:\windows\SysWOW64\sho61B2.tmp
2014-03-13 08:45 - 2013-12-23 14:20 - 00444536 _____ () C:\windows\system32\FNTCACHE.DAT

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
Přílohy
Addition.rar
(9.18 KiB) Staženo 25 x

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: zasekaný netobook prosím o kontrolu

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

trken
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 12 Dub 2014 09:37

Re: zasekaný netobook prosím o kontrolu

#3 Příspěvek od trken »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Professional x64
Ran by Marek on so 12.04.2014 at 11:46:59,19
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values




~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\esrv.babylonesrvc
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\esrv.babylonesrvc.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escort.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escortapp.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escorteng.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escortlbr.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\esrv.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\babsolution
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\babylontoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\im
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\iminstaller
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\powerpack
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\wnlt
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\utorrentbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-480172161-1048873251-2458544992-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\wnlt
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\b
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\babylon.dskbnd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylnapp.appcore
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylnapp.appcore.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylntlbr.bbylntlbrhlpr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\escort.escrtbtn.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\dmwu_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\dmwu_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\wnlt
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{99c91fc5-db5b-4aa0-bb70-5d89c5a4df96}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ea8fa6be-29be-4af2-9352-841f83215eb0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\babylon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\babylontoolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\bundlesweetimsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\bundlesweetimsetup_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\mybabylontb_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\mybabylontb_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\sweetim_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\sweetim_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\sweetimsetup_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\sweetimsetup_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\sweetpacksupdatemanager_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\sweetpacksupdatemanager_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APN_ATU3__RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\APN_ATU3__RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskSLib_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskSLib_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\robotaskbaricon_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\robotaskbaricon_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\TaskScheduler_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_steam_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\SoftonicDownloader_for_steam_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{1C2920AB-9D92-458F-BEB6-605293C9B344}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{58288FB1-5AB9-4ACE-B2ED-8C5C00655A58}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"



~~~ Files

Successfully deleted: [File] "C:\Users\Marek\appdata\locallow\SkwConfig.bin"
Failed to delete: [File] "C:\windows\system32\dmwu.exe"
Failed to delete: [File] "C:\windows\system32\ImHttpComm.dll"
Successfully deleted: [File] C:\windows\syswow64\sho1256.tmp
Successfully deleted: [File] C:\windows\syswow64\sho1628.tmp
Successfully deleted: [File] C:\windows\syswow64\sho1A.tmp
Successfully deleted: [File] C:\windows\syswow64\sho1CB6.tmp
Successfully deleted: [File] C:\windows\syswow64\sho1D9F.tmp
Successfully deleted: [File] C:\windows\syswow64\sho1FEB.tmp
Successfully deleted: [File] C:\windows\syswow64\sho26FA.tmp
Successfully deleted: [File] C:\windows\syswow64\sho2970.tmp
Successfully deleted: [File] C:\windows\syswow64\sho2D63.tmp
Successfully deleted: [File] C:\windows\syswow64\sho2F0D.tmp
Successfully deleted: [File] C:\windows\syswow64\sho3687.tmp
Successfully deleted: [File] C:\windows\syswow64\sho3707.tmp
Successfully deleted: [File] C:\windows\syswow64\sho3915.tmp
Successfully deleted: [File] C:\windows\syswow64\sho3CA3.tmp
Successfully deleted: [File] C:\windows\syswow64\sho3D6A.tmp
Successfully deleted: [File] C:\windows\syswow64\sho3E08.tmp
Successfully deleted: [File] C:\windows\syswow64\sho4642.tmp
Successfully deleted: [File] C:\windows\syswow64\sho475D.tmp
Successfully deleted: [File] C:\windows\syswow64\sho4A37.tmp
Successfully deleted: [File] C:\windows\syswow64\sho4B5D.tmp
Successfully deleted: [File] C:\windows\syswow64\sho4B6C.tmp
Successfully deleted: [File] C:\windows\syswow64\sho4F03.tmp
Successfully deleted: [File] C:\windows\syswow64\sho57F0.tmp
Successfully deleted: [File] C:\windows\syswow64\sho5B49.tmp
Successfully deleted: [File] C:\windows\syswow64\sho5E71.tmp
Successfully deleted: [File] C:\windows\syswow64\sho6029.tmp
Successfully deleted: [File] C:\windows\syswow64\sho61B2.tmp
Successfully deleted: [File] C:\windows\syswow64\sho649D.tmp
Successfully deleted: [File] C:\windows\syswow64\sho667D.tmp
Successfully deleted: [File] C:\windows\syswow64\sho6808.tmp
Successfully deleted: [File] C:\windows\syswow64\sho684.tmp
Successfully deleted: [File] C:\windows\syswow64\sho689A.tmp
Successfully deleted: [File] C:\windows\syswow64\sho6BA0.tmp
Successfully deleted: [File] C:\windows\syswow64\sho6D14.tmp
Successfully deleted: [File] C:\windows\syswow64\sho6E3E.tmp
Successfully deleted: [File] C:\windows\syswow64\sho7212.tmp
Successfully deleted: [File] C:\windows\syswow64\sho73B9.tmp
Successfully deleted: [File] C:\windows\syswow64\sho78A8.tmp
Successfully deleted: [File] C:\windows\syswow64\sho7C03.tmp
Successfully deleted: [File] C:\windows\syswow64\sho7E43.tmp
Successfully deleted: [File] C:\windows\syswow64\sho7EBF.tmp
Successfully deleted: [File] C:\windows\syswow64\sho842D.tmp
Successfully deleted: [File] C:\windows\syswow64\sho8539.tmp
Successfully deleted: [File] C:\windows\syswow64\sho86D.tmp
Successfully deleted: [File] C:\windows\syswow64\sho872C.tmp
Successfully deleted: [File] C:\windows\syswow64\sho8A63.tmp
Successfully deleted: [File] C:\windows\syswow64\sho8EE8.tmp
Successfully deleted: [File] C:\windows\syswow64\sho8FC5.tmp
Successfully deleted: [File] C:\windows\syswow64\sho97EC.tmp
Successfully deleted: [File] C:\windows\syswow64\sho9B40.tmp
Successfully deleted: [File] C:\windows\syswow64\sho9BA.tmp
Successfully deleted: [File] C:\windows\syswow64\sho9C7F.tmp
Successfully deleted: [File] C:\windows\syswow64\sho9CD.tmp
Successfully deleted: [File] C:\windows\syswow64\sho9EAF.tmp
Successfully deleted: [File] C:\windows\syswow64\sho9FF5.tmp
Successfully deleted: [File] C:\windows\syswow64\shoA042.tmp
Successfully deleted: [File] C:\windows\syswow64\shoA258.tmp
Successfully deleted: [File] C:\windows\syswow64\shoA4CD.tmp
Successfully deleted: [File] C:\windows\syswow64\shoA805.tmp
Successfully deleted: [File] C:\windows\syswow64\shoAA5D.tmp
Successfully deleted: [File] C:\windows\syswow64\shoAAA2.tmp
Successfully deleted: [File] C:\windows\syswow64\shoAD5A.tmp
Successfully deleted: [File] C:\windows\syswow64\shoB06D.tmp
Successfully deleted: [File] C:\windows\syswow64\shoB127.tmp
Successfully deleted: [File] C:\windows\syswow64\shoB442.tmp
Successfully deleted: [File] C:\windows\syswow64\shoB471.tmp
Successfully deleted: [File] C:\windows\syswow64\shoBAF5.tmp
Successfully deleted: [File] C:\windows\syswow64\shoBDE7.tmp
Successfully deleted: [File] C:\windows\syswow64\shoBF87.tmp
Successfully deleted: [File] C:\windows\syswow64\shoC494.tmp
Successfully deleted: [File] C:\windows\syswow64\shoC50D.tmp
Successfully deleted: [File] C:\windows\syswow64\shoC5E4.tmp
Successfully deleted: [File] C:\windows\syswow64\shoC717.tmp
Successfully deleted: [File] C:\windows\syswow64\shoC73E.tmp
Successfully deleted: [File] C:\windows\syswow64\shoC80E.tmp
Successfully deleted: [File] C:\windows\syswow64\shoCB4A.tmp
Successfully deleted: [File] C:\windows\syswow64\shoCE17.tmp
Successfully deleted: [File] C:\windows\syswow64\shoD154.tmp
Successfully deleted: [File] C:\windows\syswow64\shoD4ED.tmp
Successfully deleted: [File] C:\windows\syswow64\shoD579.tmp
Successfully deleted: [File] C:\windows\syswow64\shoD96E.tmp
Successfully deleted: [File] C:\windows\syswow64\shoDD43.tmp
Successfully deleted: [File] C:\windows\syswow64\shoE311.tmp
Successfully deleted: [File] C:\windows\syswow64\shoE465.tmp
Successfully deleted: [File] C:\windows\syswow64\shoE7A3.tmp
Successfully deleted: [File] C:\windows\syswow64\shoEC9D.tmp
Successfully deleted: [File] C:\windows\syswow64\shoECD7.tmp
Successfully deleted: [File] C:\windows\syswow64\shoF4C1.tmp
Successfully deleted: [File] C:\windows\syswow64\shoF8DA.tmp
Successfully deleted: [File] C:\windows\syswow64\shoFD8F.tmp
Successfully deleted: [File] C:\windows\syswow64\shoFE1D.tmp



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\sweetim"
Successfully deleted: [Folder] "C:\ProgramData\trymedia"
Successfully deleted: [Folder] "C:\Users\Marek\AppData\Roaming\babsolution"
Successfully deleted: [Folder] "C:\Users\Marek\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\Marek\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\Marek\AppData\Roaming\similarsites"
Successfully deleted: [Folder] "C:\Users\Marek\appdata\locallow\babylontoolbar"
Successfully deleted: [Folder] "C:\Users\Marek\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\Marek\appdata\locallow\utorrentbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\conduit"
Successfully deleted: [Folder] "C:\Program Files (x86)\similarsites"
Successfully deleted: [Folder] "C:\Program Files (x86)\sweetim"
Successfully deleted: [Folder] "C:\Program Files (x86)\utorrentbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\videoplayerv3"
Successfully deleted: [Folder] "C:\windows\syswow64\arfc"
Failed to delete: [Folder] "C:\windows\syswow64\jmdp"
Successfully deleted: [Folder] "C:\windows\syswow64\wnlt"
Failed to delete: [Folder] "C:\windows\system32\ljkb"
Successfully deleted: [Folder] "C:\Users\Marek\documents\pcspeedup"



~~~ FireFox

Successfully deleted: [File] C:\user.js
Successfully deleted: [File] C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\user.js
Successfully deleted: [File] C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\invalidprefs.js
Successfully deleted: [File] C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\searchplugins\askcom.xml
Successfully deleted: [File] C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\searchplugins\babylon.xml
Successfully deleted: [File] C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\searchplugins\conduit.xml
Successfully deleted: [File] C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\searchplugins\mystart search.xml
Successfully deleted: [File] C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\searchplugins\sweetim.xml
Successfully deleted: [Folder] C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\conduitcommon
Successfully deleted: [Folder] C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\sweetpackstoolbardata
Successfully deleted the following from C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\prefs.js

user_pref("CT2786678..clientLogIsEnabled", false);
user_pref("CT2786678..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent");
user_pref("CT2786678..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation");
user_pref("CT2786678.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
user_pref("CT2786678.BrowserCompStateIsOpen_130067977588633691", true);
user_pref("CT2786678.BrowserCompStateIsOpen_1359634298000", true);
user_pref("CT2786678.CTID", "CT2786678");
user_pref("CT2786678.CurrentServerDate", "27-6-2013");
user_pref("CT2786678.DSInstall", true);
user_pref("CT2786678.DialogsAlignMode", "LTR");
user_pref("CT2786678.DialogsGetterLastCheckTime", "Wed Jun 26 2013 13:39:29 GMT+0200");
user_pref("CT2786678.DownloadReferralCookieData", "");
user_pref("CT2786678.EMailNotifierPollDate", "Thu Jun 27 2013 00:09:02 GMT+0200");
user_pref("CT2786678.FeedLastCount5690698542593514850", 501);
user_pref("CT2786678.FeedPollDate2429156812186649977", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156813040823546", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156813130095866", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156813224203613", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156813230837251", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156813454291735", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156813729834876", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156813860870021", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156814264681793", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156814863075366", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedPollDate2429156815257761081", "Wed Jun 26 2013 23:59:01 GMT+0200");
user_pref("CT2786678.FeedTTL2429156813040823546", 15);
user_pref("CT2786678.FeedTTL2429156813130095866", 10);
user_pref("CT2786678.FeedTTL2429156813454291735", 5);
user_pref("CT2786678.FeedTTL2429156813729834876", 5);
user_pref("CT2786678.FeedTTL2429156814264681793", 5);
user_pref("CT2786678.FirstServerDate", "26-6-2013");
user_pref("CT2786678.FirstTime", true);
user_pref("CT2786678.FirstTimeFF3", true);
user_pref("CT2786678.FirstTimeHiddenVer", true);
user_pref("CT2786678.FixPageNotFoundErrors", true);
user_pref("CT2786678.GroupingServerCheckInterval", 1440);
user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
user_pref("CT2786678.HPInstall", true);
user_pref("CT2786678.HasUserGlobalKeys", true);
user_pref("CT2786678.HomePageProtectorEnabled", true);
user_pref("CT2786678.HomepageBeforeUnload", "hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13");
user_pref("CT2786678.Initialize", true);
user_pref("CT2786678.InitializeCommonPrefs", true);
user_pref("CT2786678.InstallationAndCookieDataSentCount", 3);
user_pref("CT2786678.InstallationType", "Unknown");
user_pref("CT2786678.InstalledDate", "Wed Jun 26 2013 13:39:40 GMT+0200");
user_pref("CT2786678.IsAlertDBUpdated", true);
user_pref("CT2786678.IsGrouping", false);
user_pref("CT2786678.IsInitSetupIni", true);
user_pref("CT2786678.IsMulticommunity", false);
user_pref("CT2786678.IsOpenThankYouPage", true);
user_pref("CT2786678.IsOpenUninstallPage", true);
user_pref("CT2786678.IsProtectorsInit", true);
user_pref("CT2786678.LanguagePackLastCheckTime", "Wed Jun 26 2013 13:39:33 GMT+0200");
user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440);
user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx");
user_pref("CT2786678.LastLogin_3.18.0.7", "Wed Jun 26 2013 23:43:24 GMT+0200");
user_pref("CT2786678.LatestVersion", "3.18.0.7");
user_pref("CT2786678.Locale", "en");
user_pref("CT2786678.MCDetectTooltipHeight", "83");
user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
user_pref("CT2786678.MCDetectTooltipWidth", "295");
user_pref("CT2786678.MyStuffEnabledAtInstallation", true);
user_pref("CT2786678.OriginalFirstVersion", "3.18.0.7");
user_pref("CT2786678.SavedHomepage", "hxxp://mixidj.delta-search.com/?affID=121125&babsrc=HP_ss&mntrId=5071D0DF9A83B284");
user_pref("CT2786678.SearchCaption", "uTorrentBar Customized Web Search");
user_pref("CT2786678.SearchEngineBeforeUnload", "uTorrentBar Customized Web Search");
user_pref("CT2786678.SearchFromAddressBarIsInit", true);
user_pref("CT2786678.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=2&CUI=SB_CUI&UM=UM_ID&q=");
user_pref("CT2786678.SearchInNewTabEnabled", true);
user_pref("CT2786678.SearchInNewTabIntervalMM", 1440);
user_pref("CT2786678.SearchInNewTabLastCheckTime", "Wed Jun 26 2013 13:39:41 GMT+0200");
user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID&UM=UM_ID");
user_pref("CT2786678.SearchProtectorEnabled", true);
user_pref("CT2786678.SearchProtectorToolbarDisabled", false);
user_pref("CT2786678.SendProtectorDataViaLogin", true);
user_pref("CT2786678.ServiceMapLastCheckTime", "Wed Jun 26 2013 13:39:31 GMT+0200");
user_pref("CT2786678.SettingsLastCheckTime", "Wed Jun 26 2013 22:41:07 GMT+0200");
user_pref("CT2786678.SettingsLastUpdate", "1372234283");
user_pref("CT2786678.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13");
user_pref("CT2786678.ThirdPartyComponentsInterval", 504);
user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Wed Jun 26 2013 13:39:25 GMT+0200");
user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1331805997");
user_pref("CT2786678.ToolbarShrinkedFromSetup", false);
user_pref("CT2786678.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2786678");
user_pref("CT2786678.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,client.conduit-storage.com,OurToolbar.com,CommunityToolbars.com,ForumToolbar.com
user_pref("CT2786678.UserID", "UN73724406041418284");
user_pref("CT2786678.ValidationData_Toolbar", 1);
user_pref("CT2786678.WeatherNetwork", "");
user_pref("CT2786678.WeatherPollDate", "Wed Jun 26 2013 23:59:02 GMT+0200");
user_pref("CT2786678.WeatherUnit", "C");
user_pref("CT2786678.alertChannelId", "1178763");
user_pref("CT2786678.backendstorage./9b+7e+x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e,x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e-x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e.:2z527", "2423");
user_pref("CT2786678.backendstorage./9b+7e.x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e/x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e06cg5el8:", "6E6D6A7071706F6F7074");
user_pref("CT2786678.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473707677767575767A242F4B49474F42357D5D5C3D");
user_pref("CT2786678.backendstorage./9b+7e0x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e1x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e2x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e3x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e4x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e5x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e6x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e7x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e8x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e9x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e:x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e;x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e<x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e=x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e>x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e?x305", "2423");
user_pref("CT2786678.backendstorage./9b+7e@x305", "2423");
user_pref("CT2786678.backendstorage./9b+7eax305", "2423");
user_pref("CT2786678.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B265146492965504656496571734D337D56545138505C");
user_pref("CT2786678.backendstorage./9b+7ebx305", "2423");
user_pref("CT2786678.backendstorage./9b+7ecx305", "2423");
user_pref("CT2786678.backendstorage./9b+7edx305", "2423");
user_pref("CT2786678.backendstorage./9b+7etx305", "2423");
user_pref("CT2786678.backendstorage./9b-0?3g>d", "6E3E686D6F7172767A7844454A20794D7B4F254E524E202A23235726572C2D28275F2F60");
user_pref("CT2786678.backendstorage./9b-0?3g@6:5;", "");
user_pref("CT2786678.backendstorage./9b-0?3gfa7ef", "2B2E2C3D");
user_pref("CT2786678.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E4249357D37382F3A494D5D513F283338435D6554695B65546D57695D5D686365533C70766C6675
user_pref("CT2786678.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6E6A68707374757677");
user_pref("CT2786678.backendstorage./9b3=>@44i48?", "372C2D32697576334236334148477B213F3E484F4E4D4648502B564B4E2E5959595F4C564F3764535750");
user_pref("CT2786678.backendstorage./9b5ba==9cjag", "676D3D3C3D6D6F717A7348757349764A77787C7C7E");
user_pref("CT2786678.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6A7071706F6F706F787375");
user_pref("CT2786678.backendstorage./9b9643g3/9e", "6A");
user_pref("CT2786678.backendstorage./9b;45>:bi9i7ie", "2B2E2C3D");
user_pref("CT2786678.backendstorage./9b<:222h64<", "393F352F3E");
user_pref("CT2786678.backendstorage./9b<:222h64<l8daj", "6D70706F76746F7975722A797A727A75757D7D");
user_pref("CT2786678.backendstorage./9b=+03eh8h8j?:", "4443");
user_pref("CT2786678.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B2651464929655046566470727951555E5E52");
user_pref("CT2786678.backendstorage./9b?b0d:8aj62<h", "6D");
user_pref("CT2786678.backendstorage./9ba@0<0bi6a7gn:6@l?", "6C");
user_pref("CT2786678.backendstorage.mam_gk_appsdata", "7B2261707073223A5B7B226964223A225072696365476F6E67222C2275726C223A22687474703A2F2F7072696365676F6E672E636F6E647569746170
user_pref("CT2786678.backendstorage.mam_gk_appsdefaultenabled", "6E756C6C");
user_pref("CT2786678.backendstorage.mam_gk_appstate_couponbuddy", "6F6666");
user_pref("CT2786678.backendstorage.mam_gk_appstate_easytobook", "6F6666");
user_pref("CT2786678.backendstorage.mam_gk_appstate_easytobook_targeted", "6F6666");
user_pref("CT2786678.backendstorage.mam_gk_appstate_pricegong", "6F6666");
user_pref("CT2786678.backendstorage.mam_gk_appstatereporttime", "31333732323833303130303335");
user_pref("CT2786678.backendstorage.mam_gk_configuration", "7B22636F6E66696775726174696F6E223A5B7B226964223A2245617379746F626F6F6B5F7461726765746564222C22637269746572696173223
user_pref("CT2786678.backendstorage.mam_gk_currentversion", "312E382E302E34");
user_pref("CT2786678.backendstorage.mam_gk_eventscache", "7B2230313033373033622D346430322D346637352D383061332D613966373731336437646365223A7B22746F706963223A2273656E64557361676
user_pref("CT2786678.backendstorage.mam_gk_first_time", "31");
user_pref("CT2786678.backendstorage.mam_gk_gadgetopen", "30");
user_pref("CT2786678.backendstorage.mam_gk_lastlogintime", "31333732323833303130373336");
user_pref("CT2786678.backendstorage.mam_gk_localization", "7B22676164676574436F6E74656E74506F6C696379223A7B2254657874223A22436F6E74656E7420506F6C696379227D2C226761646765744465
user_pref("CT2786678.backendstorage.mam_gk_settings1.8.0.4", "7B22537461747573223A22737563636565646564222C2244617461223A7B22696E74657276616C223A3234302C227374616D70223A2235345
user_pref("CT2786678.backendstorage.mam_gk_showclosebutton", "74727565");
user_pref("CT2786678.backendstorage.mam_gk_showwelcomegadget", "66616C7365");
user_pref("CT2786678.backendstorage.mam_gk_user_approval_interacted", "31");
user_pref("CT2786678.backendstorage.mam_gk_userid", "38623739396531312D626632312D343135362D616564382D346531633166343130613662");
user_pref("CT2786678.backendstorage.pg_enable", "74727565");
user_pref("CT2786678.globalFirstTimeInfoLastCheckTime", "Wed Jun 26 2013 13:39:31 GMT+0200");
user_pref("CT2786678.homepageProtectorEnableByLogin", true);
user_pref("CT2786678.initDone", true);
user_pref("CT2786678.isAppTrackingManagerOn", false);
user_pref("CT2786678.myStuffEnabled", true);
user_pref("CT2786678.myStuffPublihserMinWidth", 400);
user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID");
user_pref("CT2786678.myStuffServiceIntervalMM", 1440);
user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT");
user_pref("CT2786678.navigateToUrlOnSearch", false);
user_pref("CT2786678.revertSettingsEnabled", true);
user_pref("CT2786678.searchProtectorDialogDelayInSec", 10);
user_pref("CT2786678.searchProtectorEnableByLogin", true);
user_pref("CT2786678.testingCtid", "");
user_pref("CT2786678.toolbarAppMetaDataLastCheckTime", "Wed Jun 26 2013 13:39:31 GMT+0200");
user_pref("CT2786678.toolbarContextMenuLastCheckTime", "Wed Jun 26 2013 13:39:33 GMT+0200");
user_pref("CT2786678.usagesFlag", 2);
user_pref("CommunityToolbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13,hxxp://search.conduit.com/?ctid=CT2786678&SearchSource=13,hxxp://
user_pref("CommunityToolbar.ConduitSearchList", " ,uTorrentBar Customized Web Search,uTorrentBar Customized Web Search,uTorrentBar Customized Web Search");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=EB_LOCALE&ctid=CT2786678", "b5I8zzzMgsg0XG/fawLlFw==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=en&ctid=CT2786678", "b5I8zzzMgsg0XG/fawLlFw==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=EB_LOCALE&ctid=CT2786678", "9uXRY86McHhmOreOHsv6MA==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=en&ctid=CT2786678", "9uXRY86McHhmOreOHsv6MA==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=EB_LOCALE&ctid=CT2786678", "I1tfz7EBg4DmNytL9x55lQ==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=en&ctid=CT2786678", "I1tfz7EBg4DmNytL9x55lQ==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=EB_LOCALE&ctid=CT2786678", "ZI41WLbm1fFgx4gn0bs99Q==");
user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=en&ctid=CT2786678", "ZI41WLbm1fFgx4gn0bs99Q==");
user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\Marek\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\dgiit9b9.default\\conduitCommon\\modules\\3.18.0.7");
user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.18.0.7");
user_pref("CommunityToolbar.ToolbarsList", "CT2786678");
user_pref("CommunityToolbar.ToolbarsList2", "CT2786678");
user_pref("CommunityToolbar.ToolbarsList4", "CT2786678");
user_pref("CommunityToolbar.globalUserId", "e75d21d3-a909-47dd-8095-98210d1ada99");
user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2786678");
user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Wed Jun 26 2013 13:39:33 GMT+0200");
user_pref("CommunityToolbar.notifications.alertEnabled", true);
user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Wed Jun 26 2013 13:39:37 GMT+0200");
user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
user_pref("CommunityToolbar.notifications.locale", "en");
user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Wed Jun 26 2013 13:39:29 GMT+0200");
user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
user_pref("CommunityToolbar.notifications.showTrayIcon", false);
user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
user_pref("CommunityToolbar.notifications.userId", "d20417b2-7e05-4411-8a55-cb30ab9145ad");
user_pref("CommunityToolbar.originalHomepage", "hxxp://mixidj.delta-search.com/?affID=121125&babsrc=HP_ss&mntrId=5071D0DF9A83B284");
user_pref("CommunityToolbar.originalSearchEngine", "Mixi.DJ Search");
user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
user_pref("browser.newtab.url", "hxxp://mystart.incredibar.com/?a=&i=26&loc=skw");
user_pref("browser.search.defaultenginename", "MyStart Search");
user_pref("browser.search.defaultthis.engineName", "uTorrentBar Customized Web Search");
user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&SearchSource=3&q={searchTerms}");
user_pref("browser.search.selectedEngine", "MyStart Search");
user_pref("browser.startup.homepage", "hxxp://mystart.incredibar.com/?a=&i=26&loc=skw");
user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109980");
user_pref("extensions.BabylonToolbar_i.hardId", "5071a0a6000000000000f2df9a8342f4");
user_pref("extensions.BabylonToolbar_i.id", "5071a0a6000000000000f2df9a8342f4");
user_pref("extensions.BabylonToolbar_i.instlDay", "15403");
user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1716:53:16");
user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
user_pref("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728com51386.51386.cookie.testingGaq.value", "%22hxxp%3A//extclickmedia-maynemyltf.netdna-ss
user_pref("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728com51386.51386.name", "FreeHD-Sport TV V9.0");
user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5211");
user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5211");
user_pref("extensions.crossrider.bic", "14542d72c885399648caafb181e472c4");
user_pref("keyword.URL", "hxxp://mystart.incredibar.com/?a=&i=26&loc=skw&search=");
user_pref("sweetim.toolbar.RevertDialog.enable", "false");
user_pref("sweetim.toolbar.UserSelectedSaveSettings", "true");
user_pref("sweetim.toolbar.Visibility.VisibilityGuardLastUnHide", "0");
user_pref("sweetim.toolbar.Visibility.enable", "true");
user_pref("sweetim.toolbar.Visibility.intervaldays", "7");
user_pref("sweetim.toolbar.cda.DisableOveride.enable", "true");
user_pref("sweetim.toolbar.cda.HideOveride.enable", "true");
user_pref("sweetim.toolbar.cda.RemoveOveride.enable", "true");
user_pref("sweetim.toolbar.dialogs.0.enable", "true");
user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-handler.js");
user_pref("sweetim.toolbar.dialogs.0.height", "335");
user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog");
user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;");
user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote ... crg=$cargo;");
user_pref("sweetim.toolbar.dialogs.0.width", "761");
user_pref("sweetim.toolbar.dialogs.1.enable", "true");
user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-handler.js");
user_pref("sweetim.toolbar.dialogs.1.height", "300");
user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog");
user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog");
user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html");
user_pref("sweetim.toolbar.dialogs.1.width", "500");
user_pref("sweetim.toolbar.dialogs.2.enable", "true");
user_pref("sweetim.toolbar.dialogs.2.handler", "chrome://sim_toolbar_package/content/cdadialog-handler.js");
user_pref("sweetim.toolbar.dialogs.2.height", "150");
user_pref("sweetim.toolbar.dialogs.2.id", "id_dialog_hide_disable_remove");
user_pref("sweetim.toolbar.dialogs.2.title", "Option Dialog");
user_pref("sweetim.toolbar.dialogs.2.url", "hxxp://www.sweetim.com/simffbar/simcdadialog.asp");
user_pref("sweetim.toolbar.dialogs.2.width", "530");
user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.google.com/.*|.*.google.co.in/.*|.*.google.com.br/.*|.*.google.es/.*|.*.youtube
user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
user_pref("sweetim.toolbar.keywordUrlGuard.enable", "false");
user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
user_pref("sweetim.toolbar.mode.debug", "false");
user_pref("sweetim.toolbar.newtab.created", "false");
user_pref("sweetim.toolbar.newtab.enable", "false");
user_pref("sweetim.toolbar.previous.keyword.URL", "");
user_pref("sweetim.toolbar.rc.url", "hxxp://www.sweetim.com/simffbar/rc.html?toolba ... crg=$cargo;");
user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true");
user_pref("sweetim.toolbar.scripts.0.callback", "simVerification");
user_pref("sweetim.toolbar.scripts.0.domain-blacklist", "");
user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*");
user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb");
user_pref("sweetim.toolbar.scripts.0.enable", "false");
user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb");
user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js");
user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "true");
user_pref("sweetim.toolbar.scripts.1.callback", "simVerification");
user_pref("sweetim.toolbar.scripts.1.domain-blacklist", "");
user_pref("sweetim.toolbar.scripts.1.domain-whitelist", "hxxps://(www.|apps.)?facebook\\.com.*");
user_pref("sweetim.toolbar.scripts.1.elementid", "id_script_sim_fb");
user_pref("sweetim.toolbar.scripts.1.enable", "false");
user_pref("sweetim.toolbar.scripts.1.id", "id_script_fb_hxxpS");
user_pref("sweetim.toolbar.scripts.1.url", "hxxps://sc.sweetim.com/apps/in/fb/infb.js");
user_pref("sweetim.toolbar.scripts.2.addcontextdiv", "false");
user_pref("sweetim.toolbar.scripts.2.callback", "");
user_pref("sweetim.toolbar.scripts.2.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..*|.*.yahoo..*|.*.youtube.com.*|.*ask.com.*|.*.sweetim.com.*");
user_pref("sweetim.toolbar.scripts.2.domain-whitelist", "");
user_pref("sweetim.toolbar.scripts.2.elementid", "id_predict_include_script");
user_pref("sweetim.toolbar.scripts.2.enable", "false");
user_pref("sweetim.toolbar.scripts.2.id", "id_script_prad");
user_pref("sweetim.toolbar.scripts.2.url", "hxxp://cdn1.certified-apps.com/scripts/shared/enable.js?si=3104&tid=chff1");
user_pref("sweetim.toolbar.search.history.capacity", "10");
user_pref("sweetim.toolbar.searchguard.enable", "false");
user_pref("sweetim.toolbar.searchguard.initialized_by_rc", "true");
user_pref("sweetim.toolbar.simapp_id", "{C30E7A22-E870-11E1-BD18-D0DF9A83B284}");
user_pref("sweetim.toolbar.version", "1.9.0.0");
Emptied folder: C:\Users\Marek\AppData\Roaming\mozilla\firefox\profiles\dgiit9b9.default\minidumps [239 files]



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 12.04.2014 at 11:57:03,67
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~





# AdwCleaner v3.023 - Report created 12/04/2014 at 11:59:44
# Updated 01/04/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Marek - MAREK-HP
# Running from : C:\Users\Marek\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : IBUpdaterService

***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\~BabylonToolbar
Folder Deleted : C:\windows\SysWOW64\jmdp
Folder Deleted : C:\windows\System32\ljkb
Folder Deleted : C:\Users\Marek\AppData\Local\Conduit
Folder Deleted : C:\Users\Marek\AppData\Local\OpenCandy
Folder Deleted : C:\Users\Marek\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default

\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
File Deleted : C:\windows\System32\dmwu.exe
File Deleted : C:\windows\System32\ImhxxpComm.dll
File Deleted : C:\Users\Marek\Desktop\sweetpcfix.url
File Deleted : C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles

\dgiit9b9.default\searchplugins\buenosearch.xml
File Deleted : C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles

\dgiit9b9.default\searchplugins\MyStart.xml
File Deleted : C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles

\dgiit9b9.default\searchplugins\Sweetpacks Search.xml
File Deleted : C:\windows\System32\Tasks\EPUpdater

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions

\ogccgbmabaphcakpiclgcnmcnimhokcj
Key Deleted : HKLM\SOFTWARE\Classes\buenosearch.buenosearchappCore
Key Deleted : HKLM\SOFTWARE\Classes\buenosearch.buenosearchappCore.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-

30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A2773ED4-83BD-488A-A186-

73590706C916}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{828DC97A-2277-4E10-92A9-

4907FA0922A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-

F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F1C81E40-2485-4DB6-8C9D-

04BD596B281E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-

8885F097A9B1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser

Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser

Helper Objects\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats

\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings

\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved

\{A97B89CD-B65C-49DD-AF46-2B772C627456}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights

\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights

\ElevationPolicy\{50190B20-95AB-44B8-8C55-354778ED8ED4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights

\ElevationPolicy\{09C16FFF-8CB8-4562-9D11-96A05326A11B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes

\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{828DC97A-

2277-4E10-92A9-4907FA0922A9}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{BF7380FA-

E3B4-4DB2-AF3E-9D8783A45BFC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser

[{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks

[{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks

[{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-

F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-

2AAEDCAE67D7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-

001320C79847}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer

\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\wnlt
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\Software\installedbrowserextensions
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\Trymedia Systems
Key Deleted : HKLM\Software\wnlt
Key Deleted : HKLM\Software\uTorrentBar
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

\uTorrentBar Toolbar
Key Deleted : HKLM\Software\Classes\Installer\Features

\EB6AF8AEEB922FA4392548F13812E50B
Key Deleted : HKLM\Software\Classes\Installer\Products

\EB6AF8AEEB922FA4392548F13812E50B

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521


-\\ Mozilla Firefox v28.0 (cs)

[ File : C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles

\dgiit9b9.default\prefs.js ]

Line Deleted : user_pref

("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?

name=OtherApps&locale=EB_LOCALE&ctid=CT2786678", "9uXRY86McHhmOreOHsv6MA==");
Line Deleted : user_pref

("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?

name=OtherApps&locale=en&ctid=CT2786678", "9uXRY86McHhmOreOHsv6MA==");
Line Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\

\Users\\Marek\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\dgiit9b9.default

\\conduitCommon\\modules\\3.18.0.7");
Line Deleted : user_pref("browser.newtab.url",

"hxxp://mystart.incredibar.com/?a=&i=26&loc=skw");
Line Deleted : user_pref("browser.startup.homepage",

"hxxp://mystart.incredibar.com/?a=&i=26&loc=skw");
Line Deleted : user_pref("sweetim.toolbar.scripts.0.domain-whitelist",

"hxxp://(www.|apps.)?facebook\\.com.*");
Line Deleted : user_pref("sweetim.toolbar.scripts.1.domain-whitelist",

"hxxps://(www.|apps.)?facebook\\.com.*");

-\\ Google Chrome v34.0.1847.116

[ File : C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default

\preferences ]

Deleted : icon_url
Deleted : keyword

*************************

AdwCleaner[R0].txt - [6433 octets] - [12/04/2014 11:57:58]
AdwCleaner[S0].txt - [6283 octets] - [12/04/2014 11:59:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6343 octets] ##########

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: zasekaný netobook prosím o kontrolu

#4 Příspěvek od vyosek »

:arrow: Fajn, jdeme dale :James008:

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

trken
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 12 Dub 2014 09:37

Re: zasekaný netobook prosím o kontrolu

#5 Příspěvek od trken »

Zoek.exe v5.0.0.0 Updated 07-March-2014
Tool run by Marek on so 12.04.2014 at 12:15:54,92.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Marek\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

12.4.2014 12:17:31 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Windows\CurrentVersion\Ext\Stats\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Windows\CurrentVersion\Ext\Settings\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Windows\CurrentVersion\Ext\Stats\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Windows\CurrentVersion\Ext\Settings\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}

deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{e5701415-ce52-4171-aae1-618d6d24dc15}

deleted successfully
HKEY_CLASSES_ROOT\CLSID\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} deleted

successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser

Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted

successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser

Helper Objects\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Internet Explorer\Approved Extensions\{e5701415-ce52-4171-aae1-618d6d24dc15}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Internet Explorer\Approved Extensions\{D4027C7F-154A-4066-A1AD-4243D8127440}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Internet Explorer\Approved Extensions\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Internet Explorer\Approved Extensions\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Internet Explorer\Approved Extensions\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Internet Explorer\Approved Extensions\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

deleted successfully
HKEY_USERS\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft

\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}

deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{318A227B-

5E9F-45BD-8999-7F8F10CA4CF5} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions

\otis@digitalpersona.com deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions

\ext@VideoPlayerV3beta706.net deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles

\dgiit9b9.default\prefs.js:
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("browser.search.useDBForOrder", "false");

Added to C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles

\dgiit9b9.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?

btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google

+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles

\dgiit9b9.default

user.js not found
---- Lines buenosearch removed from prefs.js ----
user_pref("extensions.buenosearch.admin", false);
user_pref("extensions.buenosearch.aflt", "babsst");
user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-

147EC6D7BF5F}");
user_pref("extensions.buenosearch.autoRvrt", "false");
user_pref("extensions.buenosearch.dfltLng", "en");
user_pref("extensions.buenosearch.excTlbr", false);
user_pref("extensions.buenosearch.ffxUnstlRst", true);
user_pref("extensions.buenosearch.id", "5071a0a600000000000022df9a8342f4");
user_pref("extensions.buenosearch.instlDay", "16168");
user_pref("extensions.buenosearch.instlRef", "sst");
user_pref("extensions.buenosearch.newTab", false);
user_pref("extensions.buenosearch.prdct", "buenosearch");
user_pref("extensions.buenosearch.prtnrId", "buenosearch");
user_pref("extensions.buenosearch.rvrt", "false");
user_pref("extensions.buenosearch.smplGrp", "none");
user_pref("extensions.buenosearch.tlbrId", "base");
user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
user_pref("extensions.buenosearch.vrsnTs", "1.8.28.721:36:14");
---- Lines buenosearch modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",

\"addons\":{\"wrc@avast.com\":{\"descriptor\":\"C:\\\\Program Files\\\\AVAST

So
---- Lines

aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728com51386

removed from prefs.js ----
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.active", true);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.addressbar", "NA");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.addressbarenhanced", "");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.asyncdb.was_copied", "true");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.asyncdb_dbWasSet", true);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.asyncdb_dbWasSet_FF25_FIX", true);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.asyncinternaldb.was_copied", "true");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.asyncinternaldb_dbWasSet", true);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.backgroundver", 4);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.certdomaininstaller", "");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.au.expiration", "Fri Feb 01 2030 00:00:00
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.au.value", "%222014-4-12%22");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.cnt.expiration", "Fri Feb 01 2030 00:00:0
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.cnt.value", "%22CZ%22");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.first_run.expiration", "Fri Feb 01 2030 0
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.first_run.value", "%221%22");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.install.expiration", "Fri Feb 01 2030 00:
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.install.value", "%222014-4-8%22");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.InstallationTime.value", "%221396985642%2
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.InstallerParams.value", "%7B%22source_id%
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.cookie.testingGaq.expiration", "Fri Feb 01 2030
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.description", "Turn your pc into a TV Enjoy endl
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.domain", "");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.enablesearch", false);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.homepage", "");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.changeprevious", false);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.iframe", false);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.InstallationThankYouPage", true);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.InstallationTime", 1396985642);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.__defualt_browser__.expiration", "Fri
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.__defualt_browser__.value", "%22ff%22
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.installer.expiration", "Fri Feb 01 20
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.installer.value", "%7B%22InstallerIde
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.InstallerParams.expiration", "Fri Feb
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.InstallerParams.value", "%7B%22source
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.InstallerParamsCache.expiration", "Fr
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.InstallerUserIdentifiersCache.expirat
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.InstallerUserIdentifiersCache.value",
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.monetization_plugin_bundledUrls.expir
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.monetization_plugin_bundledUrls.value
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.monetization_plugin_bundledWithHash.e
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.monetization_plugin_bundledWithHash.v
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.monetization_plugin_last_executable_r
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.monetization_plugin_last_executable_r
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.monetization_plugin_notBundledArr_.ex
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.monetization_plugin_notBundledArr_.va
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_appVer.value", "38");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_lastVersion.expiration", "F
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_lastVersion.value", "2");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_meta.expiration", "Fri Feb
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_meta.value", "%7B%7D");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_nextCheck.expiration", "Sat
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_nextCheck.value", "true");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_queue.expiration", "Fri Feb
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_queue.value", "%7B%7D");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_remote_resources.expiration
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.internaldb.Resources_remote_resources.value", "%
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.lastDailyReport", "1397288339594");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.lastUpdate", "1397288340955");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.manifesturl", "");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.name", "FreeHD-Sport TV V9.0");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.newtab", "");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.opensearch", "");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.pluginsurl", "http://js.clientdemocloud.com/plug
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.pluginsversion", 33);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.publisher", "installdaddy");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.searchstatus", 0);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.setnewtab", false);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.thankyou", "");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.updateinterval", 360);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.51386.ver", 38);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.apps", "51386");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.bic", "14542d72c885399648caafb181e472c4");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.cid", 51386);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.FilesValidatorDueTime", "1397288381440");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.firstrun", false);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.hadappinstalled", true);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.installationdate", 1396985769);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.modetype", "production");
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.reportInstall", true);
user_pref

("extensions.aaba3db73c9bd47b399c1ebaf0b0b87adc43641375195433981ddebf2e8579728

com51386.statsDailyCounter", 11);
---- FireFox user.js and prefs.js backups ----

prefs_12.04.2014_1244_.backup

==== Batch Command(s) Run By Tool======================

C:\windows\system32\appdata deleted

==== Deleting Files \ Folders ======================

C:\PROGRA~3\{9BF4D58B-C6D6-467B-BC5A-FD0C1278F4AF} deleted
C:\PROGRA~3\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C} deleted
C:\windows\syswow64\appdata deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\autoconfig.js deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\Users\Marek\AppData\Roaming\buenosearch LTD deleted
C:\Users\Marek\Downloads\SoftonicDownloader_for_hijackthis.exe deleted
C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default

\CT2786678 deleted
C:\Users\Marek\Desktop\BundleSweetIMSetup.exe deleted
C:\Users\Marek\AppData\Local\MSGBOX.EXE deleted
C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default

\extensions\aba3db73-c9bd-47b3-99c1-ebaf0b0b87ad@c4364137-5195-4339-81dd-

ebf2e8579728.com deleted
C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default

\extensions\ffxtlbr@buenosearch.com deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [20.05.2013

14:15]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles

\dgiit9b9.default
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- esk slovnk pro kontrolu pravopisu - %ProfilePath%\extensions

\cs@dictionaries.addons.mozilla.org
- DoNotTrackMe: Online Privacy Protection - %ProfilePath%\extensions

\donottrackplus@abine.com
- Temp Installer - %ProfilePath%\extensions\{77868449-f49d-d6ec-3145-

e651161b1ff8}
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-

7a972ff7c30b}
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-

2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- Skype Click to Call - %AppDir%\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-

43525BDAD38A}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles

\dgiit9b9.default
ABE2E50533899C45DFA03E1D8767648F - C:\windows\SysWOW64\Macromed\Flash

\NPSWF32_13_0_0_182.dll - Shockwave Flash


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
bejbohlohkkgompgecdcbbglkpjfjgdj - C:\Users\Marek\AppData\Local\Temp

\crx13D0.tmp[]
kebgadnalhlpkjgjldclfinbfldjhpba - C:\Program Files

(x86)\VideoPlayerV3\VideoPlayerV3beta706\ch\VideoPlayerV3beta706.crx[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars

\ChromeExtension\skype_chrome_extension.crx[03.03.2014 10:53]

uTorrentBar - Marek\AppData\Local\Chromium\User Data\Default\Extensions

\bejbohlohkkgompgecdcbbglkpjfjgdj
avast WebRep - Marek\AppData\Local\Chromium\User Data\Default\Extensions

\icmlaeflemplmjndnaapfdbbnpncnbda
Seznam Li\u0161ti\u010Dka - Email - Marek\AppData\Local\Google\Chrome\User

Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam Li\u0161ti\u010Dka - Slovn\u00EDk - Marek\AppData\Local\Google\Chrome

\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
FreeHD-Sport TV V9.0 - Marek\AppData\Local\Google\Chrome\User Data\Default

\Extensions\clkckblnmlbemmgefidhlmjcfboijafe
Video Player - Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions

\kebgadnalhlpkjgjldclfinbfldjhpba
Skype Click to Call - Marek\AppData\Local\Google\Chrome\User Data\Default

\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Seznam Lištička - Rychlá volba - Marek\AppData\Local\Google\Chrome\User

Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak

==== Chrome Fix ======================

C:\Users\Marek\AppData\Local\Chromium\User Data\Default\Extensions

\bejbohlohkkgompgecdcbbglkpjfjgdj deleted successfully
C:\Users\Marek\AppData\Local\Chromium\User Data\Default\Local Storage\chrome-

extension_bejbohlohkkgompgecdcbbglkpjfjgdj_0.localstorage deleted successfully
C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions

\kebgadnalhlpkjgjldclfinbfldjhpba deleted successfully
C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions

\clkckblnmlbemmgefidhlmjcfboijafe deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?

q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{081195C4-99E7-43AE-827C-4C0E73F36079} Encyklopedie Seznam

Url="http://encyklopedie.seznam.cz/search?q={searchTerms}

&sourceid=QuickSearch_16194"
{328E4130-2CF7-4428-B221-2FFC6F23E707} Seznam TV Program

Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_16194"
{46681A16-F188-4F4E-B5E0-B1B6CEAA2949} Firmy.cz Url="http://www.firmy.cz/?q=

{searchTerms}&sourceid=QuickSearch_16194"
{64C1301A-8756-4AB3-A952-CF5F712FCA3B} Mapy.cz Url="http://www.mapy.cz/?

query={searchTerms}&sourceid=QuickSearch_16194"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google

Url="http://www.google.com/search?q={searchT ... .microsoft:

{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}

&startPage={startPage}"
{BCD40402-51BD-4984-A396-EB39C29F9735} Novinky.cz

Url="http://www.novinky.cz/hledej?w={searchT ... arch_16194"
{C2E7B0A1-F210-4BF8-9DAE-671BE418AE12} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q=

{searchTerms}&r=campmoz&sourceid=QuickSearch_16194"
{E2F0CC30-E546-4367-A763-B651B2849BD5} Slovnˇk CZ/EN

Url="http://slovnik.seznam.cz/?q={searchTerms}

&lang=cz_en&sourceid=QuickSearch_16194"
{ec29edf6-ad3c-4e1c-a087-d6cb81400c43} Bing Url="http://www.bing.com/search?

q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox"
{F2968A10-6F79-4FEB-BF75-BE8CDFF6DEFA} Slovnˇk EN/CZ

Url="http://slovnik.seznam.cz/?q={searchTerms}

&lang=en_cz&sourceid=QuickSearch_16194"

==== Reset Google Chrome ======================

C:\Users\Marek\AppData\Local\Chromium\User Data\Default\Preferences was reset

successfully
C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\preferences was

reset successfully
C:\Users\Marek\AppData\Local\Chromium\User Data\Default\Web Data was reset

successfully
C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Web Data was

reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions

\bejbohlohkkgompgecdcbbglkpjfjgdj deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions

\kebgadnalhlpkjgjldclfinbfldjhpba deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion

\Uninstall\Video Player deleted successfully

==== Empty IE Cache ======================

C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows

\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files

\Content.IE5 emptied successfully
C:\Users\Marek\AppData\Local\Microsoft\Windows\Temporary Internet Files

\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows

\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows

\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows

\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows

\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows

\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Marek\AppData\Local\Mozilla\Firefox\Profiles\dgiit9b9.default\Cache

emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Marek\AppData\Local\Chromium\User Data\Default\Cache emptied

successfully
C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Cache emptied

successfully

==== Empty All Flash Cache ======================

Flash Cache is not empty, a reboot is needed

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=538 folders=109 12629177 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Marek\AppData\Local\Temp will be emptied at reboot
C:\windows\SysNative\config\systemprofile\AppData\Local\Temp emptied

successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Temp emptied

successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied

at reboot
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied

successfully
C:\windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\windows\Temp successfully emptied
C:\Users\Marek\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Marek\AppData\Roaming\Macromedia\Flash Player\#SharedObjects

\23BP6GAV\www.player.lcfc.com" not found
"C:\windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted

==== EOF on so 12.04.2014 at 12:54:51,59 ======================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: zasekaný netobook prosím o kontrolu

#6 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

trken
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 12 Dub 2014 09:37

Re: zasekaný netobook prosím o kontrolu

#7 Příspěvek od trken »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-04-2014
Ran by Marek (administrator) on MAREK-HP on 12-04-2014 11:15:27
Running from C:\Users\Marek\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(AMD) C:\windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Hewlett-Packard Company) C:\windows\system32\Hpservice.exe
(Validity Sensors, Inc.) C:\windows\system32\vcsFPService.exe
(AMD) C:\windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hewlett-Packard Company) c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
() C:\windows\system32\dmwu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
() C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe
() C:\windows\SysWOW64\PnkBstrA.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(ArcSoft, Inc.) C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
() C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(SweetIM Technologies Ltd.) C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
() C:\Windows\SysWOW64\jmdp\stij.exe
() C:\Windows\System32\ljkb\stij.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Portrait Displays, Inc) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe
(Intel Corporation) C:\windows\system32\igfxext.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Users\Marek\Downloads\FRST64(1).exe
(forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\windows\SysWOW64\PING.EXE


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HPPowerAssistant] - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2919992 2011-01-27] (Hewlett-Packard Company)
HKLM\...\Run: [MfeEpePcMonitor] - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [200704 2013-02-01] ()
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-05-29] (IDT, Inc.)
HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-08-19] (Qualcomm Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-12-18] (Synaptics Incorporated)
HKLM-x32\...\Run: [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [12274688 2011-02-07] (Hewlett-Packard)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] - c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [HP HD Webcam [Fixed]_Monitor] - C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [267128 2010-11-26] ()
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [DTRun] - c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [517456 2010-11-24] (ArcSoft Inc.)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [Sweetpacks Communicator] - C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM-x32\...\Run: [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [333728 2012-06-20] (Hewlett-Packard Company)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [HPQuickWebProxy] - C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [169528 2013-08-14] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [184736 2012-09-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-08-11] (PDF Complete Inc)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\windows\System32\SPReview\SPReview.exe [301568 2013-03-21] (Microsoft Corporation)
HKU\.DEFAULT\...\Policies\system: [LogonHoursAction] 2
HKU\.DEFAULT\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-19\...\RunOnce: [] - [X]
HKU\S-1-5-20\...\RunOnce: [] - [X]
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [PCSpeedUp] - C:\Program Files (x86)\Zrychleni Pocitace\PCSpeedUp.lnk [2421 2011-10-07] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1632680 2013-03-15] (Valve Corporation)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [RoboForm] - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [96056 2012-07-01] (Siber Systems)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [DAEMON Tools Lite] - C:\Users\Marek\Desktop\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Marek\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: D - D:\LaunchU3.exe -a
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: G - G:\Autorun.exe
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {4945ed31-e8f7-11e0-91ff-d0df9a83b284} - D:\LaunchU3.exe -a
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {675cb4f5-110d-11e2-8c8c-d0df9a83b284} - D:\autorun.exe
Lsa: [Notification Packages] EpePcNp64 DPPassFilter scecli

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.buenosearch.com/?babsrc=HP_s ... 3&tsp=5211
URLSearchHook: HKLM-x32 - (No Name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
URLSearchHook: HKCU - (No Name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKLM-x32 - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... earchTerms}
SearchScopes: HKCU - {081195C4-99E7-43AE-827C-4C0E73F36079} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.buenosearch.com/?q={searchTe ... 3&tsp=5211
SearchScopes: HKCU - {1C2920AB-9D92-458F-BEB6-605293C9B344} URL = http://websearch.ask.com/redirect?clien ... 23779F55B5
SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF
SearchScopes: HKCU - {328E4130-2CF7-4428-B221-2FFC6F23E707} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {46681A16-F188-4F4E-B5E0-B1B6CEAA2949} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKCU - {58288FB1-5AB9-4ACE-B2ED-8C5C00655A58} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
SearchScopes: HKCU - {64C1301A-8756-4AB3-A952-CF5F712FCA3B} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKCU - {BCD40402-51BD-4984-A396-EB39C29F9735} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKCU - {C2E7B0A1-F210-4BF8-9DAE-671BE418AE12} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKCU - {E2F0CC30-E546-4367-A763-B651B2849BD5} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://mysearch.sweetpacks.com?src=6&q= ... id=&&st=23
SearchScopes: HKCU - {F2968A10-6F79-4FEB-BF75-BE8CDFF6DEFA} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
BHO-x32: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
BHO-x32: buenosearch Helper Object - {F1C81E40-2485-4DB6-8C9D-04BD596B281E} - C:\Program Files (x86)\buenosearch LTD\buenosearch\1.8.28.7\bh\buenosearch.dll (Montiera Technologies LTD)
Toolbar: HKLM - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - No Name - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
Toolbar: HKLM-x32 - No Name - {98889811-442D-49dd-99D7-DC866BE87DBC} - No File
Toolbar: HKLM-x32 - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - buenosearch Toolbar - {828DC97A-2277-4E10-92A9-4907FA0922A9} - C:\Program Files (x86)\buenosearch LTD\buenosearch\1.8.28.7\buenosearchTlbr.dll (Montiera Technologies LTD)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - avast! EasyPass Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.3.1

FireFox:
========
FF ProfilePath: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default
FF user.js: detected! => C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\user.js
FF NewTab: hxxp://www.sweetpacks-search.com/?barid=&src=97&&st=23
FF DefaultSearchEngine: Sweetpacks Search
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Sweetpacks Search
FF Homepage: hxxp://www.sweetpacks-search.com/?barid=&src=10&&st=23
FF Keyword.URL: hxxp://mysearch.sweetpacks.com?src=6&barid=&&st=23&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\buenosearch.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\conduit.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\MyStart Search.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\MyStart.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\sweetim.xml
FF SearchPlugin: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\searchplugins\Sweetpacks Search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: FreeHD-Sport TV V9.0 - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\aba3db73-c9bd-47b3-99c1-ebaf0b0b87ad@c4364137-5195-4339-81dd-ebf2e8579728.com [2014-04-08]
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\cs@dictionaries.addons.mozilla.org [2013-01-12]
FF Extension: DoNotTrackMe: Online Privacy Protection - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\donottrackplus@abine.com [2014-03-13]
FF Extension: BuenoSearch - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\ffxtlbr@buenosearch.com [2014-04-08]
FF Extension: Temp Installer - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{77868449-f49d-d6ec-3145-e651161b1ff8} [2013-06-14]
FF Extension: Seznam lištička - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-06-14]
FF Extension: Adblock Plus - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-07-29]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-30]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-11-27]
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta706.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta706\ff
FF Extension: Video Player - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta706\ff [2014-01-10]

Chrome:
=======
CHR HomePage: hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5211
CHR DefaultSearchKeyword: sweetpacks-search.com
CHR DefaultSearchProvider: Sweetpacks
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U6) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Uplay PC) - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_110.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.60.24) - C:\windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (Google Drive) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-11-09]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2013-06-14]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-06-14]
CHR Extension: (YouTube) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-09]
CHR Extension: (FreeHD-Sport TV V9.0) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\clkckblnmlbemmgefidhlmjcfboijafe [2014-04-08]
CHR Extension: (Google Search) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-09]
CHR Extension: (Video Player) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\kebgadnalhlpkjgjldclfinbfldjhpba [2014-01-10]
CHR Extension: (Skype Click to Call) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-07-20]
CHR Extension: (Google Wallet) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-30]
CHR Extension: (SweetPacks Chrome Extension) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2013-09-27]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-06-14]
CHR Extension: (Gmail) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-09]
CHR HKLM-x32\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\Marek\AppData\Local\Temp\crx13D0.tmp [2012-11-09]
CHR HKLM-x32\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2012-11-09]
CHR HKLM-x32\...\Chrome\Extension: [kebgadnalhlpkjgjldclfinbfldjhpba] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta706\ch\VideoPlayerV3beta706.crx [2014-01-07]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03]
CHR HKLM-x32\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Windows\SysWOW64\jmdp\SweetNT.crx [2014-04-06]

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-19] (Qualcomm Atheros Commnucations)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [486224 2011-11-10] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [464480 2011-02-04] (Hewlett-Packard Company)
R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [133688 2011-01-28] (Hewlett-Packard Company)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-06-20] (Hewlett-Packard Company)
R2 IBUpdaterService; C:\Windows\system32\dmwu.exe [2276144 2014-04-07] ()
R2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1323008 2013-02-01] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-11] (PDF Complete Inc)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75136 2012-10-11] ()
R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc.)
S2 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [62184 2011-03-07] (Xobni Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-19] (Atheros)

==================== Drivers (Whitelisted) ====================

R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-27] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-27] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-27] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-03-14] ()
R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2012-08-19] (Qualcomm Atheros)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [63336 2011-02-07] (Hewlett-Packard Company)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2012-10-08] (DT Soft Ltd)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-03-14] ()
R0 MfeEpeOpal; C:\Windows\System32\Drivers\MfeEpeOpal.sys [101288 2013-02-01] (McAfee, Inc.)
R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [158888 2013-02-01] (McAfee, Inc.)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [2611704 2011-01-12] (Sunplus Technology)
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Classic\safedrv.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-12 11:15 - 2014-04-12 11:15 - 00034906 _____ () C:\Users\Marek\Desktop\FRST.txt
2014-04-12 11:15 - 2014-04-12 11:15 - 00015327 _____ () C:\Users\Marek\Desktop\LM.bat
2014-04-12 11:14 - 2014-04-12 11:15 - 00029696 _____ () C:\Users\Marek\AppData\Local\MSGBOX.EXE
2014-04-12 11:13 - 2014-04-12 11:13 - 00000097 _____ () C:\Users\Marek\Downloads\FRST.txt
2014-04-12 11:09 - 2014-04-12 11:09 - 00112640 _____ (forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
2014-04-12 11:08 - 2014-04-12 11:09 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64(1).exe
2014-04-12 11:02 - 2014-04-12 11:02 - 00000000 _____ () C:\windows\SysWOW64\sho649D.tmp
2014-04-12 11:01 - 2014-04-12 11:01 - 00000000 ____D () C:\windows\SysWOW64\jmdp
2014-04-12 11:01 - 2014-04-12 11:01 - 00000000 ____D () C:\windows\system32\ljkb
2014-04-12 10:55 - 2014-04-12 11:13 - 00045306 _____ () C:\Users\Marek\Downloads\Addition.txt
2014-04-12 10:53 - 2014-04-12 11:15 - 00000000 ____D () C:\FRST
2014-04-12 10:50 - 2014-04-12 10:51 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64.exe
2014-04-09 12:50 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-09 12:50 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-09 12:50 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-04-09 12:50 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-04-09 12:50 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2014-04-09 12:49 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2014-04-09 12:49 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2014-04-09 12:49 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2014-04-09 12:49 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2014-04-09 12:49 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2014-04-09 12:48 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2014-04-09 12:48 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2014-04-09 12:48 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2014-04-09 12:48 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2014-04-09 12:48 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2014-04-09 12:48 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2014-04-08 23:03 - 2014-04-08 23:03 - 00000000 _____ () C:\windows\SysWOW64\sho7E43.tmp
2014-04-08 21:37 - 2014-04-08 21:37 - 00003158 _____ () C:\windows\System32\Tasks\{7A144C18-F2E8-4018-83D9-818D6C8A98E8}
2014-04-08 21:36 - 2014-04-08 21:36 - 00003388 _____ () C:\windows\System32\Tasks\EPUpdater
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Users\Marek\AppData\Roaming\buenosearch LTD
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Program Files (x86)\buenosearch LTD
2014-04-08 21:35 - 2014-04-12 11:04 - 00003132 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job
2014-04-08 21:35 - 2014-04-12 11:04 - 00002544 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job
2014-04-08 21:35 - 2014-04-12 11:04 - 00001622 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job
2014-04-08 21:35 - 2014-04-12 11:04 - 00001538 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job
2014-04-08 21:35 - 2014-04-08 21:35 - 00006162 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3
2014-04-08 21:35 - 2014-04-08 21:35 - 00005574 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4
2014-04-08 21:35 - 2014-04-08 21:35 - 00004652 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5
2014-04-08 21:35 - 2014-04-08 21:35 - 00004568 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1
2014-04-08 21:34 - 2014-04-08 21:35 - 00000000 ____D () C:\Program Files (x86)\FreeHD-Sport TV V9.0
2014-04-08 21:24 - 2014-04-08 21:25 - 00565320 _____ () C:\Users\Marek\Downloads\NeoliveApp_setup(18_3f)_ff.exe
2014-04-07 22:44 - 2014-04-07 22:44 - 00000000 _____ () C:\windows\SysWOW64\sho9EAF.tmp
2014-04-03 21:48 - 2014-04-03 21:48 - 00219550 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society(1).pptx
2014-04-03 21:47 - 2014-03-31 13:07 - 00022449 _____ () C:\Users\Marek\Downloads\food and meal prezentace.odp
2014-04-03 21:46 - 2014-04-03 21:46 - 00065992 _____ () C:\Users\Marek\Downloads\Traveling.pptx
2014-04-03 10:47 - 2014-04-03 10:47 - 00219533 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society.pptx
2014-04-02 23:13 - 2014-04-02 23:13 - 00000000 _____ () C:\windows\SysWOW64\sho78A8.tmp
2014-04-02 10:48 - 2014-04-10 17:09 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForMarek
2014-04-02 10:48 - 2014-04-10 17:09 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForMarek.job
2014-04-01 23:10 - 2014-04-01 23:10 - 00000000 _____ () C:\windows\SysWOW64\sho667D.tmp
2014-03-31 13:32 - 2014-03-31 13:34 - 00699763 _____ () C:\Users\Marek\Downloads\NATURE, ENVIROMENT, ECOLOGY.pptx
2014-03-30 21:04 - 2014-03-30 21:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 01:06 - 2014-03-27 01:06 - 00000000 _____ () C:\windows\SysWOW64\sho872C.tmp
2014-03-26 00:08 - 2014-03-26 00:08 - 00000000 _____ () C:\windows\SysWOW64\sho6BA0.tmp
2014-03-25 20:19 - 2014-03-25 20:19 - 00066695 _____ () C:\Users\Marek\Downloads\School and education, your studies.pptx
2014-03-24 23:59 - 2014-03-24 23:59 - 00000000 _____ () C:\windows\SysWOW64\shoD96E.tmp
2014-03-24 13:18 - 2014-03-24 13:18 - 00751791 _____ () C:\Users\Marek\Downloads\Prezentace Opava.pptx
2014-03-24 00:32 - 2014-03-24 00:32 - 00000000 _____ () C:\windows\SysWOW64\shoAD5A.tmp
2014-03-21 00:20 - 2014-03-21 00:20 - 00000000 _____ () C:\windows\SysWOW64\sho6808.tmp
2014-03-18 23:10 - 2014-03-18 23:10 - 00000000 _____ () C:\windows\SysWOW64\shoB471.tmp
2014-03-15 02:47 - 2014-03-15 02:47 - 00000000 _____ () C:\windows\SysWOW64\sho61B2.tmp
2014-03-13 08:42 - 2014-04-09 07:12 - 00004582 _____ () C:\windows\PFRO.log

==================== One Month Modified Files and Folders =======

2014-04-12 11:15 - 2014-04-12 11:15 - 00034906 _____ () C:\Users\Marek\Desktop\FRST.txt
2014-04-12 11:15 - 2014-04-12 11:15 - 00015327 _____ () C:\Users\Marek\Desktop\LM.bat
2014-04-12 11:15 - 2014-04-12 11:14 - 00029696 _____ () C:\Users\Marek\AppData\Local\MSGBOX.EXE
2014-04-12 11:15 - 2014-04-12 10:53 - 00000000 ____D () C:\FRST
2014-04-12 11:13 - 2014-04-12 11:13 - 00000097 _____ () C:\Users\Marek\Downloads\FRST.txt
2014-04-12 11:13 - 2014-04-12 10:55 - 00045306 _____ () C:\Users\Marek\Downloads\Addition.txt
2014-04-12 11:12 - 2009-07-14 06:45 - 00020944 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-12 11:12 - 2009-07-14 06:45 - 00020944 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-12 11:11 - 2012-06-27 07:26 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-12 11:09 - 2014-04-12 11:09 - 00112640 _____ (forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
2014-04-12 11:09 - 2014-04-12 11:08 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64(1).exe
2014-04-12 11:09 - 2011-08-23 12:48 - 02060409 _____ () C:\windows\WindowsUpdate.log
2014-04-12 11:06 - 2011-11-16 16:50 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-04-12 11:06 - 2011-05-12 02:05 - 00000000 ____D () C:\ProgramData\PDFC
2014-04-12 11:04 - 2014-04-08 21:35 - 00003132 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job
2014-04-12 11:04 - 2014-04-08 21:35 - 00002544 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job
2014-04-12 11:04 - 2014-04-08 21:35 - 00001622 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job
2014-04-12 11:04 - 2014-04-08 21:35 - 00001538 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job
2014-04-12 11:04 - 2013-06-14 09:43 - 00000356 _____ () C:\windows\Tasks\AmiUpdXp.job
2014-04-12 11:04 - 2012-11-09 12:47 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-12 11:03 - 2014-03-11 10:35 - 00002750 _____ () C:\windows\setupact.log
2014-04-12 11:03 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-12 11:02 - 2014-04-12 11:02 - 00000000 _____ () C:\windows\SysWOW64\sho649D.tmp
2014-04-12 11:01 - 2014-04-12 11:01 - 00000000 ____D () C:\windows\SysWOW64\jmdp
2014-04-12 11:01 - 2014-04-12 11:01 - 00000000 ____D () C:\windows\system32\ljkb
2014-04-12 11:00 - 2012-08-21 18:09 - 00000000 ____D () C:\Users\Marek\AppData\Local\PMB Files
2014-04-12 10:51 - 2014-04-12 10:50 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64.exe
2014-04-12 10:47 - 2012-11-09 12:47 - 00000950 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-12 10:31 - 2013-04-13 15:46 - 00000000 ____D () C:\Users\Marek\AppData\Roaming\Skype
2014-04-12 09:40 - 2013-06-02 11:38 - 00000000 ____D () C:\windows\SysWOW64\WNLT
2014-04-12 09:40 - 2013-06-02 11:38 - 00000000 ____D () C:\windows\SysWOW64\ARFC
2014-04-12 00:24 - 2012-08-21 18:09 - 00000000 ____D () C:\ProgramData\PMB Files
2014-04-11 20:35 - 2011-09-28 12:26 - 00000000 ____D () C:\Users\Marek\AppData\Local\CrashDumps
2014-04-11 09:52 - 2012-11-09 12:50 - 00002143 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-11 09:35 - 2012-07-01 17:51 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-04-10 17:09 - 2014-04-02 10:48 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForMarek
2014-04-10 17:09 - 2014-04-02 10:48 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForMarek.job
2014-04-10 12:12 - 2012-08-29 11:41 - 00000000 ____D () C:\Users\Marek\AppData\Local\Adobe
2014-04-10 12:12 - 2012-06-27 07:26 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-04-10 12:12 - 2012-06-27 07:25 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-04-10 12:12 - 2011-09-29 11:00 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-10 12:08 - 2011-09-27 21:20 - 00000000 ____D () C:\windows\rescache
2014-04-10 08:50 - 2012-06-04 16:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-10 08:48 - 2013-07-22 07:14 - 00000000 ____D () C:\windows\system32\MRT
2014-04-10 08:43 - 2013-03-27 09:56 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-09 12:39 - 2013-12-25 11:44 - 00000052 _____ () C:\windows\SysWOW64\DOErrors.log
2014-04-09 12:38 - 2011-11-30 15:37 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-04-09 07:12 - 2014-03-13 08:42 - 00004582 _____ () C:\windows\PFRO.log
2014-04-08 23:03 - 2014-04-08 23:03 - 00000000 _____ () C:\windows\SysWOW64\sho7E43.tmp
2014-04-08 21:37 - 2014-04-08 21:37 - 00003158 _____ () C:\windows\System32\Tasks\{7A144C18-F2E8-4018-83D9-818D6C8A98E8}
2014-04-08 21:36 - 2014-04-08 21:36 - 00003388 _____ () C:\windows\System32\Tasks\EPUpdater
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Users\Marek\AppData\Roaming\buenosearch LTD
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Program Files (x86)\buenosearch LTD
2014-04-08 21:35 - 2014-04-08 21:35 - 00006162 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3
2014-04-08 21:35 - 2014-04-08 21:35 - 00005574 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4
2014-04-08 21:35 - 2014-04-08 21:35 - 00004652 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5
2014-04-08 21:35 - 2014-04-08 21:35 - 00004568 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1
2014-04-08 21:35 - 2014-04-08 21:34 - 00000000 ____D () C:\Program Files (x86)\FreeHD-Sport TV V9.0
2014-04-08 21:25 - 2014-04-08 21:24 - 00565320 _____ () C:\Users\Marek\Downloads\NeoliveApp_setup(18_3f)_ff.exe
2014-04-08 16:40 - 2012-09-12 08:16 - 00000000 ____D () C:\Users\Marek\Desktop\škola
2014-04-08 09:08 - 2011-05-12 02:04 - 00671360 _____ () C:\windows\system32\perfh005.dat
2014-04-08 09:08 - 2011-05-12 02:04 - 00142682 _____ () C:\windows\system32\perfc005.dat
2014-04-08 09:08 - 2009-07-14 07:13 - 01586106 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-07 22:44 - 2014-04-07 22:44 - 00000000 _____ () C:\windows\SysWOW64\sho9EAF.tmp
2014-04-07 16:57 - 2013-06-02 11:38 - 02276144 _____ () C:\windows\system32\dmwu.exe
2014-04-07 16:55 - 2013-06-02 11:38 - 00033792 _____ (IncrediMail, Ltd.) C:\windows\system32\ImHttpComm.dll
2014-04-07 10:05 - 2011-09-27 12:35 - 00000000 ____D () C:\Users\Marek\Documents\Bluetooth Folder
2014-04-03 21:48 - 2014-04-03 21:48 - 00219550 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society(1).pptx
2014-04-03 21:46 - 2014-04-03 21:46 - 00065992 _____ () C:\Users\Marek\Downloads\Traveling.pptx
2014-04-03 10:47 - 2014-04-03 10:47 - 00219533 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society.pptx
2014-04-03 07:42 - 2012-11-09 12:47 - 00003946 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-03 07:42 - 2012-11-09 12:47 - 00003694 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-02 23:13 - 2014-04-02 23:13 - 00000000 _____ () C:\windows\SysWOW64\sho78A8.tmp
2014-04-02 11:09 - 2011-09-27 12:25 - 00000000 ____D () C:\Users\Marek
2014-04-01 23:10 - 2014-04-01 23:10 - 00000000 _____ () C:\windows\SysWOW64\sho667D.tmp
2014-03-31 20:01 - 2012-08-13 20:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-31 13:34 - 2014-03-31 13:32 - 00699763 _____ () C:\Users\Marek\Downloads\NATURE, ENVIROMENT, ECOLOGY.pptx
2014-03-31 13:07 - 2014-04-03 21:47 - 00022449 _____ () C:\Users\Marek\Downloads\food and meal prezentace.odp
2014-03-31 03:16 - 2014-04-09 12:50 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 12:50 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 12:50 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 12:50 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-30 21:04 - 2014-03-30 21:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 08:20 - 2009-07-14 07:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2014-03-27 01:06 - 2014-03-27 01:06 - 00000000 _____ () C:\windows\SysWOW64\sho872C.tmp
2014-03-26 00:08 - 2014-03-26 00:08 - 00000000 _____ () C:\windows\SysWOW64\sho6BA0.tmp
2014-03-25 20:19 - 2014-03-25 20:19 - 00066695 _____ () C:\Users\Marek\Downloads\School and education, your studies.pptx
2014-03-24 23:59 - 2014-03-24 23:59 - 00000000 _____ () C:\windows\SysWOW64\shoD96E.tmp
2014-03-24 13:18 - 2014-03-24 13:18 - 00751791 _____ () C:\Users\Marek\Downloads\Prezentace Opava.pptx
2014-03-24 00:32 - 2014-03-24 00:32 - 00000000 _____ () C:\windows\SysWOW64\shoAD5A.tmp
2014-03-21 00:20 - 2014-03-21 00:20 - 00000000 _____ () C:\windows\SysWOW64\sho6808.tmp
2014-03-20 23:41 - 2011-09-27 12:25 - 00003218 _____ () C:\windows\System32\Tasks\HPCeeScheduleForMAREK-HP$
2014-03-20 23:41 - 2011-09-27 12:25 - 00000342 _____ () C:\windows\Tasks\HPCeeScheduleForMAREK-HP$.job
2014-03-18 23:10 - 2014-03-18 23:10 - 00000000 _____ () C:\windows\SysWOW64\shoB471.tmp
2014-03-16 11:18 - 2013-04-13 15:46 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-15 02:47 - 2014-03-15 02:47 - 00000000 _____ () C:\windows\SysWOW64\sho61B2.tmp
2014-03-13 08:45 - 2013-12-23 14:20 - 00444536 _____ () C:\windows\system32\FNTCACHE.DAT

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: zasekaný netobook prosím o kontrolu

#8 Příspěvek od vyosek »

Ja ale potrebuji, abyste udelal novy log, at vidim jake zmeny se provedly
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

trken
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 12 Dub 2014 09:37

Re: zasekaný netobook prosím o kontrolu

#9 Příspěvek od trken »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-04-2014
Ran by Marek (administrator) on MAREK-HP on 12-04-2014 13:36:11
Running from C:\Users\Marek\Desktop
Windows 7 Professional Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe
(AMD) C:\windows\system32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Hewlett-Packard Company) C:\windows\system32\Hpservice.exe
(Validity Sensors, Inc.) C:\windows\system32\vcsFPService.exe
(AMD) C:\windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Hewlett-Packard Company) c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
() C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
() C:\windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(ArcSoft, Inc.) C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe
() C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
() C:\Program Files (x86)\HP HD Webcam [Fixed]\Monitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Portrait Displays, Inc) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe
(Microsoft Corporation) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\windows\system32\igfxext.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
(Adobe Systems, Inc.) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [HPPowerAssistant] - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe [2919992 2011-01-27] (Hewlett-Packard Company)
HKLM\...\Run: [MfeEpePcMonitor] - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe [200704 2013-02-01] ()
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1664000 2013-05-29] (IDT, Inc.)
HKLM\...\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [127616 2012-08-19] (Qualcomm Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-12-18] (Synaptics Incorporated)
HKLM-x32\...\Run: [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe [12274688 2011-02-07] (Hewlett-Packard)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-26] (Intel Corporation)
HKLM-x32\...\Run: [NUSB3MON] - c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [HP HD Webcam [Fixed]_Monitor] - C:\Program Files (x86)\HP HD Webcam [Fixed]\monitor.exe [267128 2010-11-26] ()
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-28] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [DTRun] - c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe [517456 2010-11-24] (ArcSoft Inc.)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software)
HKLM-x32\...\Run: [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [333728 2012-06-20] (Hewlett-Packard Company)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [HPQuickWebProxy] - C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe [169528 2013-08-14] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [184736 2012-09-05] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-08-11] (PDF Complete Inc)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-08] (Hewlett-Packard)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\windows\System32\SPReview\SPReview.exe [301568 2013-03-21] (Microsoft Corporation)
HKU\.DEFAULT\...\Policies\system: [LogonHoursAction] 2
HKU\.DEFAULT\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-19\...\RunOnce: [] - [X]
HKU\S-1-5-20\...\RunOnce: [] - [X]
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1632680 2013-03-15] (Valve Corporation)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [RoboForm] - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [96056 2012-07-01] (Siber Systems)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [DAEMON Tools Lite] - C:\Users\Marek\Desktop\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Marek\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: D - D:\LaunchU3.exe -a
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: G - G:\Autorun.exe
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {4945ed31-e8f7-11e0-91ff-d0df9a83b284} - D:\LaunchU3.exe -a
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {675cb4f5-110d-11e2-8c8c-d0df9a83b284} - D:\autorun.exe
Lsa: [Notification Packages] EpePcNp64 DPPassFilter scecli

==================== Internet (Whitelisted) ====================

SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {081195C4-99E7-43AE-827C-4C0E73F36079} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKCU - {328E4130-2CF7-4428-B221-2FFC6F23E707} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {46681A16-F188-4F4E-B5E0-B1B6CEAA2949} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKCU - {64C1301A-8756-4AB3-A952-CF5F712FCA3B} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {BCD40402-51BD-4984-A396-EB39C29F9735} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKCU - {C2E7B0A1-F210-4BF8-9DAE-671BE418AE12} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKCU - {E2F0CC30-E546-4367-A763-B651B2849BD5} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {F2968A10-6F79-4FEB-BF75-BE8CDFF6DEFA} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
BHO: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: File Sanitizer for HP ProtectTools - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
BHO-x32: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - avast! EasyPass Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.3.1

FireFox:
========
FF ProfilePath: C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: FreeHD-Sport TV V9.0 - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\aba3db73-c9bd-47b3-99c1-ebaf0b0b87ad@c4364137-5195-4339-81dd-ebf2e8579728.com [2014-04-12]
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\cs@dictionaries.addons.mozilla.org [2013-01-12]
FF Extension: DoNotTrackMe: Online Privacy Protection - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\donottrackplus@abine.com [2014-03-13]
FF Extension: Temp Installer - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{77868449-f49d-d6ec-3145-e651161b1ff8} [2013-06-14]
FF Extension: Seznam lištička - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-06-14]
FF Extension: Adblock Plus - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-07-29]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-30]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-11-27]

Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Google Drive) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-11-09]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2013-06-14]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-06-14]
CHR Extension: (YouTube) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-09]
CHR Extension: (No Name) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\clkckblnmlbemmgefidhlmjcfboijafe [2014-04-12]
CHR Extension: (Google Search) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-09]
CHR Extension: (Skype Click to Call) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-07-20]
CHR Extension: (Google Wallet) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-30]
CHR Extension: (No Name) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj [2013-09-27]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-06-14]
CHR Extension: (Gmail) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-09]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03]

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211584 2012-08-19] (Qualcomm Atheros Commnucations)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
R2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [486224 2011-11-10] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [464480 2011-02-04] (Hewlett-Packard Company)
R2 HPDayStarterService; c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [133688 2011-01-28] (Hewlett-Packard Company)
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [523680 2012-06-20] (Hewlett-Packard Company)
R2 McAfee Endpoint Encryption Agent; C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [1323008 2013-02-01] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1128952 2011-08-11] (PDF Complete Inc)
R2 PnkBstrA; C:\windows\SysWOW64\PnkBstrA.exe [75136 2012-10-11] ()
R2 uArcCapture; C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [502464 2010-11-11] (ArcSoft, Inc.)
S2 XobniService; C:\Program Files (x86)\Xobni\XobniService.exe [62184 2011-03-07] (Xobni Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-19] (Atheros)

==================== Drivers (Whitelisted) ====================

R3 ARCVCAM; C:\Windows\System32\DRIVERS\ArcSoftVCapture.sys [32192 2010-11-11] (ArcSoft, Inc.)
R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-27] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-27] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-27] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2012-03-14] ()
R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2012-08-19] (Qualcomm Atheros)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [63336 2011-02-07] (Hewlett-Packard Company)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2012-10-08] (DT Soft Ltd)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2012-03-14] ()
R0 MfeEpeOpal; C:\Windows\System32\Drivers\MfeEpeOpal.sys [101288 2013-02-01] (McAfee, Inc.)
R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [158888 2013-02-01] (McAfee, Inc.)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [2611704 2011-01-12] (Sunplus Technology)
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Classic\safedrv.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-12 12:51 - 2014-04-12 12:15 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-04-12 12:16 - 2014-04-12 12:54 - 00030278 _____ () C:\zoek-results.log
2014-04-12 12:14 - 2014-04-12 12:52 - 00000000 ____D () C:\zoek_backup
2014-04-12 12:13 - 2014-04-12 12:14 - 01285120 _____ () C:\Users\Marek\Downloads\zoek.exe
2014-04-12 11:57 - 2014-04-12 12:00 - 00000000 ____D () C:\AdwCleaner
2014-04-12 11:57 - 2014-04-12 11:57 - 00048143 _____ () C:\Users\Marek\Desktop\JRT.txt
2014-04-12 11:53 - 2014-04-12 11:53 - 01426178 _____ () C:\Users\Marek\Desktop\adwcleaner.exe
2014-04-12 11:31 - 2014-04-12 11:31 - 00000000 ____D () C:\windows\ERUNT
2014-04-12 11:30 - 2014-04-12 11:30 - 01016261 _____ (Thisisu) C:\Users\Marek\Desktop\JRT.exe
2014-04-12 11:22 - 2014-04-12 11:22 - 01145856 _____ (Farbar) C:\Users\Marek\Downloads\FRST.exe
2014-04-12 11:17 - 2014-04-12 11:17 - 00009399 _____ () C:\Users\Marek\Desktop\Addition.rar
2014-04-12 11:16 - 2014-04-12 11:21 - 00054926 _____ () C:\Users\Marek\Desktop\FRST2.txt
2014-04-12 11:16 - 2014-04-12 11:16 - 00034684 _____ () C:\Users\Marek\Desktop\Addition.txt
2014-04-12 11:15 - 2014-04-12 13:36 - 00026694 _____ () C:\Users\Marek\Desktop\FRST.txt
2014-04-12 11:15 - 2014-04-12 11:15 - 00015327 _____ () C:\Users\Marek\Desktop\LM.bat
2014-04-12 11:13 - 2014-04-12 11:13 - 00000097 _____ () C:\Users\Marek\Downloads\FRST.txt
2014-04-12 11:09 - 2014-04-12 11:09 - 00112640 _____ (forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
2014-04-12 11:08 - 2014-04-12 11:09 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64(1).exe
2014-04-12 10:55 - 2014-04-12 11:13 - 00045306 _____ () C:\Users\Marek\Downloads\Addition.txt
2014-04-12 10:53 - 2014-04-12 11:15 - 00000000 ____D () C:\FRST
2014-04-12 10:50 - 2014-04-12 10:51 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64.exe
2014-04-09 12:50 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-04-09 12:50 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-04-09 12:50 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-04-09 12:50 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-04-09 12:50 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2014-04-09 12:49 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2014-04-09 12:49 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2014-04-09 12:49 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Diskdump.sys
2014-04-09 12:49 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\iologmsg.dll
2014-04-09 12:49 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\iologmsg.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2014-04-09 12:48 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2014-04-09 12:48 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2014-04-09 12:48 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2014-04-09 12:48 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2014-04-09 12:48 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2014-04-09 12:48 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2014-04-09 12:48 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2014-04-08 21:37 - 2014-04-08 21:37 - 00003158 _____ () C:\windows\System32\Tasks\{7A144C18-F2E8-4018-83D9-818D6C8A98E8}
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Program Files (x86)\buenosearch LTD
2014-04-08 21:35 - 2014-04-12 12:54 - 00003132 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job
2014-04-08 21:35 - 2014-04-12 12:54 - 00002544 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job
2014-04-08 21:35 - 2014-04-12 12:54 - 00001622 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job
2014-04-08 21:35 - 2014-04-12 12:53 - 00001538 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job
2014-04-08 21:35 - 2014-04-08 21:35 - 00006162 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3
2014-04-08 21:35 - 2014-04-08 21:35 - 00005574 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4
2014-04-08 21:35 - 2014-04-08 21:35 - 00004652 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5
2014-04-08 21:35 - 2014-04-08 21:35 - 00004568 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1
2014-04-08 21:34 - 2014-04-08 21:35 - 00000000 ____D () C:\Program Files (x86)\FreeHD-Sport TV V9.0
2014-04-08 21:24 - 2014-04-08 21:25 - 00565320 _____ () C:\Users\Marek\Downloads\NeoliveApp_setup(18_3f)_ff.exe
2014-04-03 21:48 - 2014-04-03 21:48 - 00219550 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society(1).pptx
2014-04-03 21:47 - 2014-03-31 13:07 - 00022449 _____ () C:\Users\Marek\Downloads\food and meal prezentace.odp
2014-04-03 21:46 - 2014-04-03 21:46 - 00065992 _____ () C:\Users\Marek\Downloads\Traveling.pptx
2014-04-03 10:47 - 2014-04-03 10:47 - 00219533 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society.pptx
2014-04-02 10:48 - 2014-04-12 12:58 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForMarek
2014-04-02 10:48 - 2014-04-12 12:58 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForMarek.job
2014-03-31 13:32 - 2014-03-31 13:34 - 00699763 _____ () C:\Users\Marek\Downloads\NATURE, ENVIROMENT, ECOLOGY.pptx
2014-03-30 21:04 - 2014-03-30 21:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-25 20:19 - 2014-03-25 20:19 - 00066695 _____ () C:\Users\Marek\Downloads\School and education, your studies.pptx
2014-03-24 13:18 - 2014-03-24 13:18 - 00751791 _____ () C:\Users\Marek\Downloads\Prezentace Opava.pptx
2014-03-13 08:42 - 2014-04-12 12:52 - 00005140 _____ () C:\windows\PFRO.log

==================== One Month Modified Files and Folders =======

2014-04-12 13:36 - 2014-04-12 11:15 - 00026694 _____ () C:\Users\Marek\Desktop\FRST.txt
2014-04-12 13:11 - 2012-06-27 07:26 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-12 13:03 - 2009-07-14 06:45 - 00020944 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-12 13:03 - 2009-07-14 06:45 - 00020944 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-12 13:00 - 2011-08-23 12:48 - 02085027 _____ () C:\windows\WindowsUpdate.log
2014-04-12 12:58 - 2014-04-02 10:48 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForMarek
2014-04-12 12:58 - 2014-04-02 10:48 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForMarek.job
2014-04-12 12:58 - 2011-11-16 16:50 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-04-12 12:56 - 2011-05-12 02:05 - 00000000 ____D () C:\ProgramData\PDFC
2014-04-12 12:54 - 2014-04-12 12:16 - 00030278 _____ () C:\zoek-results.log
2014-04-12 12:54 - 2014-04-08 21:35 - 00003132 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job
2014-04-12 12:54 - 2014-04-08 21:35 - 00002544 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job
2014-04-12 12:54 - 2014-04-08 21:35 - 00001622 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job
2014-04-12 12:54 - 2012-11-09 12:47 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-12 12:53 - 2014-04-08 21:35 - 00001538 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job
2014-04-12 12:53 - 2014-03-11 10:35 - 00002918 _____ () C:\windows\setupact.log
2014-04-12 12:53 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-12 12:52 - 2014-04-12 12:14 - 00000000 ____D () C:\zoek_backup
2014-04-12 12:52 - 2014-03-13 08:42 - 00005140 _____ () C:\windows\PFRO.log
2014-04-12 12:47 - 2012-11-09 12:47 - 00000950 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-12 12:15 - 2014-04-12 12:51 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-04-12 12:14 - 2014-04-12 12:13 - 01285120 _____ () C:\Users\Marek\Downloads\zoek.exe
2014-04-12 12:00 - 2014-04-12 11:57 - 00000000 ____D () C:\AdwCleaner
2014-04-12 11:57 - 2014-04-12 11:57 - 00048143 _____ () C:\Users\Marek\Desktop\JRT.txt
2014-04-12 11:53 - 2014-04-12 11:53 - 01426178 _____ () C:\Users\Marek\Desktop\adwcleaner.exe
2014-04-12 11:44 - 2012-07-01 17:51 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-04-12 11:31 - 2014-04-12 11:31 - 00000000 ____D () C:\windows\ERUNT
2014-04-12 11:30 - 2014-04-12 11:30 - 01016261 _____ (Thisisu) C:\Users\Marek\Desktop\JRT.exe
2014-04-12 11:22 - 2014-04-12 11:22 - 01145856 _____ (Farbar) C:\Users\Marek\Downloads\FRST.exe
2014-04-12 11:21 - 2014-04-12 11:16 - 00054926 _____ () C:\Users\Marek\Desktop\FRST2.txt
2014-04-12 11:17 - 2014-04-12 11:17 - 00009399 _____ () C:\Users\Marek\Desktop\Addition.rar
2014-04-12 11:16 - 2014-04-12 11:16 - 00034684 _____ () C:\Users\Marek\Desktop\Addition.txt
2014-04-12 11:15 - 2014-04-12 11:15 - 00015327 _____ () C:\Users\Marek\Desktop\LM.bat
2014-04-12 11:15 - 2014-04-12 10:53 - 00000000 ____D () C:\FRST
2014-04-12 11:13 - 2014-04-12 11:13 - 00000097 _____ () C:\Users\Marek\Downloads\FRST.txt
2014-04-12 11:13 - 2014-04-12 10:55 - 00045306 _____ () C:\Users\Marek\Downloads\Addition.txt
2014-04-12 11:09 - 2014-04-12 11:09 - 00112640 _____ (forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
2014-04-12 11:09 - 2014-04-12 11:08 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64(1).exe
2014-04-12 11:00 - 2012-08-21 18:09 - 00000000 ____D () C:\Users\Marek\AppData\Local\PMB Files
2014-04-12 10:51 - 2014-04-12 10:50 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64.exe
2014-04-12 10:31 - 2013-04-13 15:46 - 00000000 ____D () C:\Users\Marek\AppData\Roaming\Skype
2014-04-12 00:24 - 2012-08-21 18:09 - 00000000 ____D () C:\ProgramData\PMB Files
2014-04-11 20:35 - 2011-09-28 12:26 - 00000000 ____D () C:\Users\Marek\AppData\Local\CrashDumps
2014-04-11 09:52 - 2012-11-09 12:50 - 00002143 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-10 12:12 - 2012-08-29 11:41 - 00000000 ____D () C:\Users\Marek\AppData\Local\Adobe
2014-04-10 12:12 - 2012-06-27 07:26 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-04-10 12:12 - 2012-06-27 07:25 - 00692400 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-04-10 12:12 - 2011-09-29 11:00 - 00070832 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-10 12:08 - 2011-09-27 21:20 - 00000000 ____D () C:\windows\rescache
2014-04-10 08:50 - 2012-06-04 16:11 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-10 08:48 - 2013-07-22 07:14 - 00000000 ____D () C:\windows\system32\MRT
2014-04-10 08:43 - 2013-03-27 09:56 - 90655440 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-04-09 12:39 - 2013-12-25 11:44 - 00000052 _____ () C:\windows\SysWOW64\DOErrors.log
2014-04-09 12:38 - 2011-11-30 15:37 - 00000000 _____ () C:\windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-04-08 21:37 - 2014-04-08 21:37 - 00003158 _____ () C:\windows\System32\Tasks\{7A144C18-F2E8-4018-83D9-818D6C8A98E8}
2014-04-08 21:36 - 2014-04-08 21:36 - 00000000 ____D () C:\Program Files (x86)\buenosearch LTD
2014-04-08 21:35 - 2014-04-08 21:35 - 00006162 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3
2014-04-08 21:35 - 2014-04-08 21:35 - 00005574 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4
2014-04-08 21:35 - 2014-04-08 21:35 - 00004652 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5
2014-04-08 21:35 - 2014-04-08 21:35 - 00004568 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1
2014-04-08 21:35 - 2014-04-08 21:34 - 00000000 ____D () C:\Program Files (x86)\FreeHD-Sport TV V9.0
2014-04-08 21:25 - 2014-04-08 21:24 - 00565320 _____ () C:\Users\Marek\Downloads\NeoliveApp_setup(18_3f)_ff.exe
2014-04-08 16:40 - 2012-09-12 08:16 - 00000000 ____D () C:\Users\Marek\Desktop\škola
2014-04-08 09:08 - 2011-05-12 02:04 - 00671360 _____ () C:\windows\system32\perfh005.dat
2014-04-08 09:08 - 2011-05-12 02:04 - 00142682 _____ () C:\windows\system32\perfc005.dat
2014-04-08 09:08 - 2009-07-14 07:13 - 01586106 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-07 10:05 - 2011-09-27 12:35 - 00000000 ____D () C:\Users\Marek\Documents\Bluetooth Folder
2014-04-03 21:48 - 2014-04-03 21:48 - 00219550 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society(1).pptx
2014-04-03 21:46 - 2014-04-03 21:46 - 00065992 _____ () C:\Users\Marek\Downloads\Traveling.pptx
2014-04-03 10:47 - 2014-04-03 10:47 - 00219533 _____ () C:\Users\Marek\Downloads\Family and relationship, problems in society.pptx
2014-04-03 07:42 - 2012-11-09 12:47 - 00003946 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-03 07:42 - 2012-11-09 12:47 - 00003694 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-02 11:09 - 2011-09-27 12:25 - 00000000 ____D () C:\Users\Marek
2014-03-31 20:01 - 2012-08-13 20:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-31 13:34 - 2014-03-31 13:32 - 00699763 _____ () C:\Users\Marek\Downloads\NATURE, ENVIROMENT, ECOLOGY.pptx
2014-03-31 13:07 - 2014-04-03 21:47 - 00022449 _____ () C:\Users\Marek\Downloads\food and meal prezentace.odp
2014-03-31 03:16 - 2014-04-09 12:50 - 23134208 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 12:50 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 12:50 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 12:50 - 17073152 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-03-30 21:04 - 2014-03-30 21:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 08:20 - 2009-07-14 07:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2014-03-25 20:19 - 2014-03-25 20:19 - 00066695 _____ () C:\Users\Marek\Downloads\School and education, your studies.pptx
2014-03-24 13:18 - 2014-03-24 13:18 - 00751791 _____ () C:\Users\Marek\Downloads\Prezentace Opava.pptx
2014-03-20 23:41 - 2011-09-27 12:25 - 00003218 _____ () C:\windows\System32\Tasks\HPCeeScheduleForMAREK-HP$
2014-03-20 23:41 - 2011-09-27 12:25 - 00000342 _____ () C:\windows\Tasks\HPCeeScheduleForMAREK-HP$.job
2014-03-16 11:18 - 2013-04-13 15:46 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-13 08:45 - 2013-12-23 14:20 - 00444536 _____ () C:\windows\system32\FNTCACHE.DAT

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-10 09:39

==================== End Of Log ============================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: zasekaný netobook prosím o kontrolu

#10 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM-x32\...\Run: [seznam-listicka-distribuce] - C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
    HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-08-11] (PDF Complete Inc)
    HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\windows\System32\SPReview\SPReview.exe [301568 2013-03-21] (Microsoft Corporation)
    HKU\.DEFAULT\...\Policies\system: [LogonHoursAction] 2
    HKU\.DEFAULT\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKU\S-1-5-19\...\RunOnce: [] - [X]
    HKU\S-1-5-20\...\RunOnce: [] - [X]
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1632680 2013-03-15] (Valve Corporation)
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [RoboForm] - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [96056 2012-07-01] (Siber Systems)
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [DAEMON Tools Lite] - C:\Users\Marek\Desktop\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Marek\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [LogonHoursAction] 2
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: D - D:\LaunchU3.exe -a
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: G - G:\Autorun.exe
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {4945ed31-e8f7-11e0-91ff-d0df9a83b284} - D:\LaunchU3.exe -a
    HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {675cb4f5-110d-11e2-8c8c-d0df9a83b284} - D:\autorun.exe
    
    SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    
    FF Extension: Temp Installer - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{77868449-f49d-d6ec-3145-e651161b1ff8} [2013-06-14]
    FF Extension: Seznam lištička - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-06-14]
    FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-30]
    
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03]
    CHR Extension: (Skype Click to Call) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-07-20]
    
    DisableService: c2cautoupdatesvc
    DisableService: c2cpnrsvc
    
    2014-04-12 12:51 - 2014-04-12 12:15 - 00024064 _____ () C:\windows\zoek-delete.exe
    2014-04-12 12:16 - 2014-04-12 12:54 - 00030278 _____ () C:\zoek-results.log
    2014-04-12 12:14 - 2014-04-12 12:52 - 00000000 ____D () C:\zoek_backup
    2014-04-12 12:13 - 2014-04-12 12:14 - 01285120 _____ () C:\Users\Marek\Downloads\zoek.exe
    2014-04-12 11:57 - 2014-04-12 11:57 - 00048143 _____ () C:\Users\Marek\Desktop\JRT.txt
    2014-04-12 11:53 - 2014-04-12 11:53 - 01426178 _____ () C:\Users\Marek\Desktop\adwcleaner.exe
    2014-04-12 11:30 - 2014-04-12 11:30 - 01016261 _____ (Thisisu) C:\Users\Marek\Desktop\JRT.exe
    2014-04-12 11:17 - 2014-04-12 11:17 - 00009399 _____ () C:\Users\Marek\Desktop\Addition.rar
    2014-04-12 11:16 - 2014-04-12 11:21 - 00054926 _____ () C:\Users\Marek\Desktop\FRST2.txt
    2014-04-12 11:16 - 2014-04-12 11:16 - 00034684 _____ () C:\Users\Marek\Desktop\Addition.txt
    2014-04-12 11:15 - 2014-04-12 13:36 - 00026694 _____ () C:\Users\Marek\Desktop\FRST.txt
    2014-04-12 11:15 - 2014-04-12 11:15 - 00015327 _____ () C:\Users\Marek\Desktop\LM.bat
    2014-04-12 11:13 - 2014-04-12 11:13 - 00000097 _____ () C:\Users\Marek\Downloads\FRST.txt
    2014-04-12 11:09 - 2014-04-12 11:09 - 00112640 _____ (forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
    2014-04-12 11:08 - 2014-04-12 11:09 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64(1).exe
    2014-04-12 10:55 - 2014-04-12 11:13 - 00045306 _____ () C:\Users\Marek\Downloads\Addition.txt
    2014-04-08 21:35 - 2014-04-12 12:54 - 00003132 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job
    2014-04-08 21:35 - 2014-04-12 12:54 - 00002544 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job
    2014-04-08 21:35 - 2014-04-12 12:54 - 00001622 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job
    2014-04-08 21:35 - 2014-04-12 12:53 - 00001538 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job
    2014-04-08 21:35 - 2014-04-08 21:35 - 00006162 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3
    2014-04-08 21:35 - 2014-04-08 21:35 - 00005574 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4
    2014-04-08 21:35 - 2014-04-08 21:35 - 00004652 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5
    2014-04-08 21:35 - 2014-04-08 21:35 - 00004568 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1
    2014-04-08 21:37 - 2014-04-08 21:37 - 00003158 _____ () C:\windows\System32\Tasks\{7A144C18-F2E8-4018-83D9-818D6C8A98E8}
    
    Task: C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job => C:\Program Files (x86)\FreeHD-Sport TV V9.0\FreeHD-Sport TV V9.0-codedownloader.exe
    Task: C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job => C:\Program Files (x86)\FreeHD-Sport TV V9.0\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.exe
    Task: C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job => C:\Program Files (x86)\FreeHD-Sport TV V9.0\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.exe
    Task: C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job => C:\Program Files (x86)\FreeHD-Sport TV V9.0\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.exe
    Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\windows\Tasks\AmiUpdXp.job => C:\Users\Marek\AppData\Local\SwvUpdater\Updater.exe <==== ATTENTION
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\HPCeeScheduleForMAREK-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
    Task: C:\windows\Tasks\HPCeeScheduleForMarek.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
    
    Hosts:
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

trken
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 12 Dub 2014 09:37

Re: zasekaný netobook prosím o kontrolu

#11 Příspěvek od trken »

Snad jsem to udelaj dobře :)

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-04-2014 01
Ran by Marek at 2014-04-12 20:49:51 Run:1
Running from C:\Users\Marek\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [seznam-listicka-distribuce] - C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe [658424 2011-08-11] (PDF Complete Inc)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\windows\System32\SPReview\SPReview.exe [301568 2013-03-21] (Microsoft Corporation)
HKU\.DEFAULT\...\Policies\system: [LogonHoursAction] 2
HKU\.DEFAULT\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-19\...\RunOnce: [] - [X]
HKU\S-1-5-20\...\RunOnce: [] - [X]
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1632680 2013-03-15] (Valve Corporation)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [RoboForm] - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [96056 2012-07-01] (Siber Systems)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [DAEMON Tools Lite] - C:\Users\Marek\Desktop\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Marek\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Marek\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: D - D:\LaunchU3.exe -a
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: G - G:\Autorun.exe
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {4945ed31-e8f7-11e0-91ff-d0df9a83b284} - D:\LaunchU3.exe -a
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\...\MountPoints2: {675cb4f5-110d-11e2-8c8c-d0df9a83b284} - D:\autorun.exe

SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

FF Extension: Temp Installer - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{77868449-f49d-d6ec-3145-e651161b1ff8} [2013-06-14]
FF Extension: Seznam lištička - C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-06-14]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-03-30]

CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03]
CHR Extension: (Skype Click to Call) - C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-07-20]

DisableService: c2cautoupdatesvc
DisableService: c2cpnrsvc

2014-04-12 12:51 - 2014-04-12 12:15 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-04-12 12:16 - 2014-04-12 12:54 - 00030278 _____ () C:\zoek-results.log
2014-04-12 12:14 - 2014-04-12 12:52 - 00000000 ____D () C:\zoek_backup
2014-04-12 12:13 - 2014-04-12 12:14 - 01285120 _____ () C:\Users\Marek\Downloads\zoek.exe
2014-04-12 11:57 - 2014-04-12 11:57 - 00048143 _____ () C:\Users\Marek\Desktop\JRT.txt
2014-04-12 11:53 - 2014-04-12 11:53 - 01426178 _____ () C:\Users\Marek\Desktop\adwcleaner.exe
2014-04-12 11:30 - 2014-04-12 11:30 - 01016261 _____ (Thisisu) C:\Users\Marek\Desktop\JRT.exe
2014-04-12 11:17 - 2014-04-12 11:17 - 00009399 _____ () C:\Users\Marek\Desktop\Addition.rar
2014-04-12 11:16 - 2014-04-12 11:21 - 00054926 _____ () C:\Users\Marek\Desktop\FRST2.txt
2014-04-12 11:16 - 2014-04-12 11:16 - 00034684 _____ () C:\Users\Marek\Desktop\Addition.txt
2014-04-12 11:15 - 2014-04-12 13:36 - 00026694 _____ () C:\Users\Marek\Desktop\FRST.txt
2014-04-12 11:15 - 2014-04-12 11:15 - 00015327 _____ () C:\Users\Marek\Desktop\LM.bat
2014-04-12 11:13 - 2014-04-12 11:13 - 00000097 _____ () C:\Users\Marek\Downloads\FRST.txt
2014-04-12 11:09 - 2014-04-12 11:09 - 00112640 _____ (forum.viry.cz) C:\Users\Marek\Desktop\FRSTLauncher.exe
2014-04-12 11:08 - 2014-04-12 11:09 - 02157056 _____ (Farbar) C:\Users\Marek\Desktop\FRST64(1).exe
2014-04-12 10:55 - 2014-04-12 11:13 - 00045306 _____ () C:\Users\Marek\Downloads\Addition.txt
2014-04-08 21:35 - 2014-04-12 12:54 - 00003132 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job
2014-04-08 21:35 - 2014-04-12 12:54 - 00002544 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job
2014-04-08 21:35 - 2014-04-12 12:54 - 00001622 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job
2014-04-08 21:35 - 2014-04-12 12:53 - 00001538 _____ () C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job
2014-04-08 21:35 - 2014-04-08 21:35 - 00006162 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3
2014-04-08 21:35 - 2014-04-08 21:35 - 00005574 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4
2014-04-08 21:35 - 2014-04-08 21:35 - 00004652 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5
2014-04-08 21:35 - 2014-04-08 21:35 - 00004568 _____ () C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1
2014-04-08 21:37 - 2014-04-08 21:37 - 00003158 _____ () C:\windows\System32\Tasks\{7A144C18-F2E8-4018-83D9-818D6C8A98E8}

Task: C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job => C:\Program Files (x86)\FreeHD-Sport TV V9.0\FreeHD-Sport TV V9.0-codedownloader.exe
Task: C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job => C:\Program Files (x86)\FreeHD-Sport TV V9.0\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.exe
Task: C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job => C:\Program Files (x86)\FreeHD-Sport TV V9.0\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.exe
Task: C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job => C:\Program Files (x86)\FreeHD-Sport TV V9.0\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.exe
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\AmiUpdXp.job => C:\Users\Marek\AppData\Local\SwvUpdater\Updater.exe <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForMAREK-HP$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\windows\Tasks\HPCeeScheduleForMarek.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

Hosts:
End
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\PDF Complete => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SPReview => Value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\system\\LogonHoursAction => Value deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DontDisplayLogonHoursWarnings => Value deleted successfully.
HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => Value deleted successfully.
HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\ => Value deleted successfully.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Steam => Value deleted successfully.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft\Windows\CurrentVersion\Run\\RoboForm => Value deleted successfully.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => Value deleted successfully.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => Value deleted successfully.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\LogonHoursAction => Value deleted successfully.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DontDisplayLogonHoursWarnings => Value deleted successfully.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-480172161-1048873251-2458544992-1001 => Key not found.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-480172161-1048873251-2458544992-1001 => Key not found.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4945ed31-e8f7-11e0-91ff-d0df9a83b284} => Key deleted successfully.
HKCR\CLSID\{4945ed31-e8f7-11e0-91ff-d0df9a83b284} => Key not found.
HKU\S-1-5-21-480172161-1048873251-2458544992-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{675cb4f5-110d-11e2-8c8c-d0df9a83b284} => Key deleted successfully.
HKCR\CLSID\{675cb4f5-110d-11e2-8c8c-d0df9a83b284} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key deleted successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => Key not found.
C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{77868449-f49d-d6ec-3145-e651161b1ff8} => Moved successfully.
C:\Users\Marek\AppData\Roaming\Mozilla\Firefox\Profiles\dgiit9b9.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} => Moved successfully.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi => Moved successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl => Key deleted successfully.
C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx => Moved successfully.
C:\Users\Marek\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl => Moved successfully.
c2cautoupdatesvc service was disabled
c2cpnrsvc service was disabled
C:\windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Marek\Downloads\zoek.exe => Moved successfully.
C:\Users\Marek\Desktop\JRT.txt => Moved successfully.
C:\Users\Marek\Desktop\adwcleaner.exe => Moved successfully.
C:\Users\Marek\Desktop\JRT.exe => Moved successfully.
C:\Users\Marek\Desktop\Addition.rar => Moved successfully.
C:\Users\Marek\Desktop\FRST2.txt => Moved successfully.
C:\Users\Marek\Desktop\Addition.txt => Moved successfully.
C:\Users\Marek\Desktop\FRST.txt => Moved successfully.
C:\Users\Marek\Desktop\LM.bat => Moved successfully.
C:\Users\Marek\Downloads\FRST.txt => Moved successfully.
"C:\Users\Marek\Desktop\FRSTLauncher.exe" => File/Directory not found.
"C:\Users\Marek\Desktop\FRST64(1).exe" => File/Directory not found.
C:\Users\Marek\Downloads\Addition.txt => Moved successfully.
C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job => Moved successfully.
C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job => Moved successfully.
C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job => Moved successfully.
C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job => Moved successfully.
C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3 => Moved successfully.
C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4 => Moved successfully.
C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5 => Moved successfully.
C:\windows\System32\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1 => Moved successfully.
C:\windows\System32\Tasks\{7A144C18-F2E8-4018-83D9-818D6C8A98E8} => Moved successfully.
C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-1.job not found.
C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3.job not found.
C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4.job not found.
C:\windows\Tasks\5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5.job not found.
C:\windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\windows\Tasks\AmiUpdXp.job not found.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\windows\Tasks\HPCeeScheduleForMAREK-HP$.job => Moved successfully.
C:\windows\Tasks\HPCeeScheduleForMarek.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

==== End of Fixlog ====

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: zasekaný netobook prosím o kontrolu

#12 Příspěvek od vyosek »

Jak se chova ntb???
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

trken
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 12 Dub 2014 09:37

Re: zasekaný netobook prosím o kontrolu

#13 Příspěvek od trken »

Je to určitě lepší něž předtím :thumbsup: . Jestli je to všechno tak Vám mockrát děkuju za Váš strávený čas semnou. Kdyby se mi cokolic dalšího stalo určitě se obrátím na Vás. Díky :)

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: zasekaný netobook prosím o kontrolu

#14 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

trken
Návštěvník
Návštěvník
Příspěvky: 27
Registrován: 12 Dub 2014 09:37

Re: zasekaný netobook prosím o kontrolu

#15 Příspěvek od trken »

Ještě se chci zeptat stažené programy a vytvořene logy můžu odstranit?

Zamčeno