Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém s msmfgplbm.exe?

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Indy13
Návštěvník
Návštěvník
Příspěvky: 41
Registrován: 12 kvě 2009 22:32

Problém s msmfgplbm.exe?

#1 Příspěvek od Indy13 »

Dobrý den,

v počítači mi neustále běž process "msmfgplbm.exe", který trvale konzumuje téměř 50% CPU (viz screenshot). Vůbec netuším, co je to zač, ani na Inetu jsem nenašel žádnou stopu. Můžete, prosím, poradit, co s tím?

Díky moc.

Logfile of random's system information tool 1.09 (written by random/random)
Run by JDA at 2014-04-13 15:41:53
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 6 GB (3%) free of 191 GB
Total RAM: 3326 MB (51% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:42:14, on 13.4.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16428)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DiskMonitor\dmti.exe
C:\Program Files\Acronis\DriveMonitor\adm_tray.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Users\Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\inf\msmfgplbm\msmfgplbm.exe
C:\Windows\system32\conhost.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\system32\SnippingTool.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Jirka\Downloads\RSIT.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\trend micro\JDA.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1me10IE11ENUS/MSE_WCP
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Speed Test 127 - {11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} - C:\Program Files\Speed Test 127\ScriptHost.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SNT - {2A8BD126-F193-5CF3-2386-2AF161EFB39E} - C:\Program Files\SNT\S34.dll
O2 - BHO: YoutubeAdblocker - {2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} - C:\Program Files\YoutubeAdblocker\F_RJexUJ.dll
O2 - BHO: ZGame Toolbar - {573bf47c-2566-449d-ba1b-417d5d3fb9fd} - C:\Program Files\zgametb\zgameDx.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: safewoeb - {BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F} - C:\Program Files\safewoeb\XNsWOr7Iu.dll
O2 - BHO: Free Games 111 - {C45EC9F0-8333-465D-9728-074BD41985C9} - C:\Program Files\Free Games 111\ScriptHost.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: ZGame Toolbar - {573bf47c-2566-449d-ba1b-417d5d3fb9fd} - C:\Program Files\zgametb\zgameDx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [DiskMonitor] C:\Program Files\DiskMonitor\dmti.exe
O4 - HKLM\..\Run: [adm_tray.exe] C:\Program Files\Acronis\DriveMonitor\adm_tray.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [mssgunSrv] C:\Windows\inf\mssgun.vbe
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe /s
O4 - HKCU\..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
O4 - HKCU\..\Run: [NextLive] C:\Windows\system32\rundll32.exe "C:\Users\JDA\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1957534622-2435220491-3010217779-1001\..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (User 'Jirka')
O4 - HKUS\S-1-5-21-1957534622-2435220491-3010217779-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1957534622-2435220491-3010217779-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - S-1-5-21-1957534622-2435220491-3010217779-1001 Startup: Dropbox.lnk = Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Jirka')
O4 - S-1-5-21-1957534622-2435220491-3010217779-1001 User Startup: Dropbox.lnk = Jirka\AppData\Roaming\Dropbox\bin\Dropbox.exe (User 'Jirka')
O4 - Startup: Dropbox.lnk = JDA\AppData\Roaming\Dropbox\bin\Dropbox.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~1\sw-boo~1\assist~1.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: DiskMonitor - Corner Bowl Software Corporation - C:\Program Files\DiskMonitor\diskmntr.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 9592 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job
C:\Windows\tasks\AmiUpdXp.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1957534622-2435220491-3010217779-1001Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1957534622-2435220491-3010217779-1001UA.job
C:\Windows\tasks\Norton Security Scan for JDA.job
C:\Windows\tasks\SW-Booster-S-619517029.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7}]
Speed Test 127 - C:\Program Files\Speed Test 127\ScriptHost.dll [2013-12-19 438784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A8BD126-F193-5CF3-2386-2AF161EFB39E}]
SNT - C:\Program Files\SNT\S34.dll [2013-03-26 423936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44}]
YoutubeAdblocker - C:\Program Files\YoutubeAdblocker\F_RJexUJ.dll [2013-03-26 423936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{573bf47c-2566-449d-ba1b-417d5d3fb9fd}]
ZGame Toolbar - C:\Program Files\zgametb\zgameDx.dll [2013-08-14 91712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-12-18 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-04-01 194504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2013-11-20 4502400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F}]
safewoeb - C:\Program Files\safewoeb\XNsWOr7Iu.dll [2014-03-26 423936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C45EC9F0-8333-465D-9728-074BD41985C9}]
Free Games 111 - C:\Program Files\Free Games 111\ScriptHost.dll [2014-01-02 438784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-12-18 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{573bf47c-2566-449d-ba1b-417d5d3fb9fd} - ZGame Toolbar - C:\Program Files\zgametb\zgameDx.dll [2013-08-14 91712]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2014-04-01 194504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
""= []
"DiskMonitor"=C:\Program Files\DiskMonitor\dmti.exe [2010-02-01 40968]
"adm_tray.exe"=C:\Program Files\Acronis\DriveMonitor\adm_tray.exe [2010-06-04 530768]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2009-10-27 365560]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-06-17 85160]
"KiesTrayAgent"=C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [2012-02-03 3508624]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"Nokia Tray Application"=C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe [2003-01-03 425984]
"mssgunSrv"=C:\Windows\inf\mssgun.vbe [2013-08-27 1558]
"mobilegeni daemon"=C:\Program Files\Mobogenie\DaemonProcess.exe []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-03-11 951576]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"KiesHelper"=C:\Program Files\Samsung\Kies\KiesHelper.exe [2012-02-03 943504]
"KiesPDLR"=C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [2012-02-03 21392]
"NextLive"=C:\Users\JDA\AppData\Roaming\newnext.me\nengine.dll [2014-01-06 1283584]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2014-02-10 20922016]

C:\Users\JDA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\JDA\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\progra~1\sw-boo~1\assist~1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-04-13 15:41:53 ----D---- C:\rsit
2014-04-13 15:41:53 ----D---- C:\Program Files\trend micro
2014-04-13 13:05:34 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-13 13:05:34 ----A---- C:\Windows\system32\elshyph.dll
2014-04-13 13:05:32 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2014-04-13 13:05:32 ----A---- C:\Windows\system32\jsIntl.dll
2014-04-13 13:05:31 ----A---- C:\Windows\system32\wininet.dll
2014-04-13 13:05:31 ----A---- C:\Windows\system32\urlmon.dll
2014-04-13 13:05:31 ----A---- C:\Windows\system32\msrating.dll
2014-04-13 13:05:31 ----A---- C:\Windows\system32\msls31.dll
2014-04-13 13:05:31 ----A---- C:\Windows\system32\jsproxy.dll
2014-04-13 13:05:31 ----A---- C:\Windows\system32\iertutil.dll
2014-04-13 13:05:30 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-13 13:05:30 ----A---- C:\Windows\system32\dxtrans.dll
2014-04-13 13:05:30 ----A---- C:\Windows\system32\dxtmsft.dll
2014-04-13 13:05:29 ----A---- C:\Windows\system32\url.dll
2014-04-13 13:05:29 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-04-13 13:05:29 ----A---- C:\Windows\system32\iesetup.dll
2014-04-13 13:05:29 ----A---- C:\Windows\system32\iernonce.dll
2014-04-13 13:05:29 ----A---- C:\Windows\system32\iedkcs32.dll
2014-04-13 13:05:29 ----A---- C:\Windows\system32\ieapfltr.dll
2014-04-13 13:05:29 ----A---- C:\Windows\system32\ieapfltr.dat
2014-04-13 13:05:29 ----A---- C:\Windows\system32\ie4uinit.exe
2014-04-13 13:05:29 ----A---- C:\Windows\system32\icardie.dll
2014-04-13 13:05:28 ----A---- C:\Windows\system32\wextract.exe
2014-04-13 13:05:28 ----A---- C:\Windows\system32\webcheck.dll
2014-04-13 13:05:28 ----A---- C:\Windows\system32\vbscript.dll
2014-04-13 13:05:28 ----A---- C:\Windows\system32\mshtmled.dll
2014-04-13 13:05:28 ----A---- C:\Windows\system32\msfeeds.dll
2014-04-13 13:05:28 ----A---- C:\Windows\system32\licmgr10.dll
2014-04-13 13:05:28 ----A---- C:\Windows\system32\inseng.dll
2014-04-13 13:05:28 ----A---- C:\Windows\system32\iexpress.exe
2014-04-13 13:05:27 ----A---- C:\Windows\system32\mshtml.dll
2014-04-13 13:05:27 ----A---- C:\Windows\system32\ieUnatt.exe
2014-04-13 13:05:26 ----A---- C:\Windows\system32\pngfilt.dll
2014-04-13 13:05:26 ----A---- C:\Windows\system32\occache.dll
2014-04-13 13:05:26 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-04-13 13:05:26 ----A---- C:\Windows\system32\mshta.exe
2014-04-13 13:05:26 ----A---- C:\Windows\system32\jscript.dll
2014-04-13 13:05:26 ----A---- C:\Windows\system32\imgutil.dll
2014-04-13 13:05:26 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-04-13 13:05:26 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-04-13 13:05:26 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-04-13 13:05:25 ----A---- C:\Windows\system32\msfeedssync.exe
2014-04-13 13:05:25 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-04-13 13:05:25 ----A---- C:\Windows\system32\iepeers.dll
2014-04-13 13:05:25 ----A---- C:\Windows\system32\IEAdvpack.dll
2014-04-13 13:05:24 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2014-04-13 13:05:24 ----A---- C:\Windows\system32\mshtmler.dll
2014-04-13 13:05:24 ----A---- C:\Windows\system32\jscript9diag.dll
2014-04-13 13:05:24 ----A---- C:\Windows\system32\jscript9.dll
2014-04-13 13:05:24 ----A---- C:\Windows\system32\ieui.dll
2014-04-13 13:05:24 ----A---- C:\Windows\system32\iesysprep.dll
2014-04-13 13:05:24 ----A---- C:\Windows\system32\ieframe.dll
2014-04-13 13:04:15 ----A---- C:\Windows\system32\tdh.dll
2014-04-13 13:04:15 ----A---- C:\Windows\system32\smss.exe
2014-04-13 13:04:15 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-04-13 13:04:15 ----A---- C:\Windows\system32\ntkrnlpa.exe
2014-04-13 13:04:15 ----A---- C:\Windows\system32\ntdll.dll
2014-04-13 13:04:15 ----A---- C:\Windows\system32\csrsrv.dll
2014-04-13 13:04:15 ----A---- C:\Windows\system32\advapi32.dll
2014-04-13 13:03:44 ----A---- C:\Windows\system32\mswsock.dll
2014-04-13 13:03:44 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-04-13 13:03:44 ----A---- C:\Windows\system32\drivers\netio.sys
2014-04-13 13:03:44 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-04-13 13:03:44 ----A---- C:\Windows\system32\drivers\afd.sys
2014-04-13 13:03:22 ----A---- C:\Windows\system32\taskhost.exe
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-04-13 13:02:21 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-04-13 13:02:21 ----A---- C:\Windows\system32\winsrv.dll
2014-04-13 13:02:21 ----A---- C:\Windows\system32\KernelBase.dll
2014-04-13 13:02:21 ----A---- C:\Windows\system32\kernel32.dll
2014-04-13 13:02:21 ----A---- C:\Windows\system32\conhost.exe
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-04-13 13:02:20 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-04-13 13:00:05 ----AH---- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-04-13 13:00:05 ----AH---- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-04-13 13:00:05 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-04-13 13:00:05 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-04-13 13:00:05 ----AH---- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-04-13 13:00:05 ----AH---- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-04-13 13:00:05 ----AH---- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-04-13 13:00:05 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-04-13 13:00:05 ----AH---- C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-04-13 13:00:05 ----A---- C:\Windows\system32\XpsPrint.dll
2014-04-13 13:00:05 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2014-04-13 13:00:05 ----A---- C:\Windows\system32\WMPhoto.dll
2014-04-13 13:00:05 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2014-04-13 13:00:05 ----A---- C:\Windows\system32\FntCache.dll
2014-04-13 13:00:05 ----A---- C:\Windows\system32\DWrite.dll
2014-04-13 13:00:04 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2014-04-13 13:00:04 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-04-13 13:00:04 ----A---- C:\Windows\system32\d3d10warp.dll
2014-04-13 13:00:04 ----A---- C:\Windows\system32\d3d10level9.dll
2014-04-13 13:00:04 ----A---- C:\Windows\system32\d3d10core.dll
2014-04-13 13:00:04 ----A---- C:\Windows\system32\d3d10_1core.dll
2014-04-13 13:00:04 ----A---- C:\Windows\system32\d3d10_1.dll
2014-04-13 13:00:04 ----A---- C:\Windows\system32\d3d10.dll
2014-04-13 13:00:04 ----A---- C:\Windows\system32\d2d1.dll
2014-04-13 13:00:03 ----A---- C:\Windows\system32\UIAnimation.dll
2014-04-13 13:00:03 ----A---- C:\Windows\system32\dxgi.dll
2014-04-13 12:57:10 ----A---- C:\Windows\system32\d3d11.dll
2014-04-13 12:30:40 ----D---- C:\Program Files\Microsoft Security Client
2014-04-13 12:15:54 ----D---- C:\Users\JDA\AppData\Roaming\Oracle
2014-04-13 11:50:16 ----D---- C:\Archive
2014-04-13 11:19:46 ----D---- C:\ProgramData\Oracle
2014-04-13 11:19:24 ----D---- C:\Program Files\Common Files\Java
2014-04-13 11:19:14 ----A---- C:\Windows\system32\javaws.exe
2014-04-13 11:19:02 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2014-04-13 11:19:02 ----A---- C:\Windows\system32\javaw.exe
2014-04-13 11:19:02 ----A---- C:\Windows\system32\java.exe
2014-04-13 11:09:44 ----D---- C:\Users\JDA\AppData\Roaming\Skype
2014-04-13 11:08:38 ----D---- C:\Users\JDA\AppData\Roaming\NVIDIA
2014-04-05 20:32:24 ----D---- C:\Program Files\Just Cause 2
2014-04-05 20:32:00 ----D---- C:\Program Files\Just-Cause-2-etina
2014-04-01 21:31:44 ----D---- C:\ProgramData\Battle.net
2014-04-01 21:24:45 ----D---- C:\Program Files\World of Warcraft
2014-04-01 21:24:45 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2014-04-01 21:23:40 ----D---- C:\ProgramData\Blizzard Entertainment
2014-03-26 22:25:48 ----D---- C:\ProgramData\SNT
2014-03-26 22:25:47 ----D---- C:\Program Files\SNT
2014-03-26 22:25:19 ----D---- C:\ProgramData\Puresafe
2014-03-26 22:25:13 ----D---- C:\Program Files\SW-Booster
2014-03-26 22:24:52 ----D---- C:\ProgramData\YoutubeAdblocker
2014-03-26 22:24:51 ----D---- C:\Program Files\YoutubeAdblocker
2014-03-26 22:24:45 ----D---- C:\ProgramData\safewoeb
2014-03-26 22:24:45 ----D---- C:\Program Files\safewoeb
2014-03-26 22:24:41 ----D---- C:\ProgramData\a956c69f9e08b4ea
2014-03-26 22:20:56 ----D---- C:\ProgramData\InstallMate
2014-03-26 22:12:59 ----D---- C:\Program Files\zgametb
2014-03-21 20:59:28 ----D---- C:\Windows\3F5C371F8EA24F259D3DD0B4526E3AEA.TMP
2014-03-21 20:59:25 ----A---- C:\Windows\system32\XAudio2_7.dll
2014-03-21 20:59:25 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2014-03-21 20:59:25 ----A---- C:\Windows\system32\xactengine3_7.dll
2014-03-21 20:59:24 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-03-21 20:59:24 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-03-21 20:59:24 ----A---- C:\Windows\system32\d3dcsx_43.dll

======List of files/folders modified in the last 1 month======

2014-04-13 15:42:02 ----D---- C:\Windows\Temp
2014-04-13 15:41:53 ----RD---- C:\Program Files
2014-04-13 15:40:09 ----D---- C:\Temp
2014-04-13 15:17:54 ----RD---- C:\Dropbox
2014-04-13 15:07:00 ----D---- C:\ProgramData\NVIDIA
2014-04-13 15:05:17 ----D---- C:\Windows\system32\config
2014-04-13 15:02:52 ----D---- C:\Shared
2014-04-13 13:57:36 ----D---- C:\Windows\System32
2014-04-13 13:57:36 ----D---- C:\Windows\inf
2014-04-13 13:57:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-04-13 13:24:00 ----D---- C:\Users\JDA\AppData\Roaming\Dropbox
2014-04-13 13:22:25 ----D---- C:\Users\JDA\AppData\Roaming\newnext.me
2014-04-13 13:19:40 ----D---- C:\Windows\winsxs
2014-04-13 13:16:08 ----D---- C:\Windows\system32\migration
2014-04-13 13:16:08 ----D---- C:\Windows\system32\en-US
2014-04-13 13:16:08 ----D---- C:\Windows\system32\cs-CZ
2014-04-13 13:16:08 ----D---- C:\Windows\PolicyDefinitions
2014-04-13 13:16:08 ----D---- C:\Program Files\Internet Explorer
2014-04-13 13:16:06 ----RSD---- C:\Windows\Fonts
2014-04-13 13:16:06 ----D---- C:\Windows\system32\drivers
2014-04-13 13:16:05 ----D---- C:\Windows\system32\zh-TW
2014-04-13 13:16:05 ----D---- C:\Windows\system32\zh-HK
2014-04-13 13:16:05 ----D---- C:\Windows\system32\zh-CN
2014-04-13 13:16:05 ----D---- C:\Windows\system32\tr-TR
2014-04-13 13:16:05 ----D---- C:\Windows\system32\sv-SE
2014-04-13 13:16:05 ----D---- C:\Windows\system32\ru-RU
2014-04-13 13:16:05 ----D---- C:\Windows\system32\pt-PT
2014-04-13 13:16:05 ----D---- C:\Windows\system32\pt-BR
2014-04-13 13:16:05 ----D---- C:\Windows\system32\pl-PL
2014-04-13 13:16:05 ----D---- C:\Windows\system32\nl-NL
2014-04-13 13:16:05 ----D---- C:\Windows\system32\nb-NO
2014-04-13 13:16:05 ----D---- C:\Windows\system32\ko-KR
2014-04-13 13:16:05 ----D---- C:\Windows\system32\ja-JP
2014-04-13 13:16:05 ----D---- C:\Windows\system32\it-IT
2014-04-13 13:16:05 ----D---- C:\Windows\system32\hu-HU
2014-04-13 13:16:05 ----D---- C:\Windows\system32\fr-FR
2014-04-13 13:16:05 ----D---- C:\Windows\system32\fi-FI
2014-04-13 13:16:05 ----D---- C:\Windows\system32\es-ES
2014-04-13 13:16:05 ----D---- C:\Windows\system32\el-GR
2014-04-13 13:16:05 ----D---- C:\Windows\system32\de-DE
2014-04-13 13:16:05 ----D---- C:\Windows\system32\da-DK
2014-04-13 13:11:32 ----HD---- C:\Windows\msdownld.tmp
2014-04-13 13:11:08 ----D---- C:\Windows\Logs
2014-04-13 13:10:36 ----D---- C:\Windows\system32\catroot
2014-04-13 13:10:34 ----SHD---- C:\System Volume Information
2014-04-13 13:08:36 ----D---- C:\Windows\system32\catroot2
2014-04-13 12:55:19 ----D---- C:\Windows
2014-04-13 12:54:28 ----SD---- C:\Users\JDA\AppData\Roaming\Microsoft
2014-04-13 12:43:32 ----D---- C:\Backup
2014-04-13 12:31:11 ----SHD---- C:\Windows\Installer
2014-04-13 12:31:09 ----HD---- C:\Config.Msi
2014-04-13 12:30:46 ----SD---- C:\ProgramData\Microsoft
2014-04-13 11:19:46 ----HD---- C:\ProgramData
2014-04-13 11:19:24 ----D---- C:\Program Files\Common Files
2014-04-13 11:19:02 ----D---- C:\Program Files\Java
2014-04-06 20:01:54 ----D---- C:\Games
2014-04-06 16:46:01 ----D---- C:\Install
2014-03-31 09:35:10 ----N---- C:\Windows\system32\MpSigStub.exe
2014-03-26 22:25:20 ----D---- C:\Windows\Tasks
2014-03-26 22:25:20 ----D---- C:\Windows\system32\Tasks
2014-03-26 22:24:39 ----RD---- C:\Users
2014-03-26 22:13:20 ----D---- C:\Windows\Prefetch
2014-03-22 15:38:54 ----SHD---- C:\Windows\system32\AI_RecycleBin
2014-03-22 15:37:15 ----D---- C:\Users\JDA\AppData\Roaming\PerformerSoft
2014-03-21 20:59:05 ----RSD---- C:\Windows\assembly
2014-03-19 20:11:45 ----RD---- C:\Program Files\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2014-01-25 231960]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 175360]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 388096]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2009-12-18 26024]
R2 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2014-03-11 104264]
R3 E100B;Intel(R) PRO Adapter Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2009-07-14 159232]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2013-04-04 22856]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2009-08-09 29696]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 atikmdag;atikmdag; C:\Windows\system32\drivers\atikmdag.sys [2009-07-14 4194816]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmb.sys [2012-01-09 18176]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbo.sys [2012-01-09 23168]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2012-06-11 19072]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 133632]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 28032]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys [2012-01-09 8192]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 35840]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2010-11-20 27648]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys [2012-01-09 8192]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 17920]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2009-10-27 660504]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-03-03 1363584]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-03-03 1748608]
R2 c67abfdb;SW-Sustainer; c:\progra~1\sw-boo~1\AssistantSvc.dll [2014-03-26 174928]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiskMonitor;DiskMonitor; C:\Program Files\DiskMonitor\diskmntr.exe [2010-02-01 30728]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-03-11 22216]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2011-10-15 1136448]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-10-15 2253120]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-10-15 381248]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-03-11 279776]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2012-06-11 724376]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-10-07 136176]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-12 257928]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-10-07 136176]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-10-07 194032]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-04-13 108032]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2014-02-25 568512]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-11-21 1343400]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s msmfgplbm.exe?

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Indy13
Návštěvník
Návštěvník
Příspěvky: 41
Registrován: 12 kvě 2009 22:32

Re: Problém s msmfgplbm.exe?

#3 Příspěvek od Indy13 »

Postup jsem realizoval, log přikládám. Nicméně zmíněný proces tam zatím sedí stále a konzumuje spoustu CPU.

Díky.


Zoek.exe v5.0.0.0 Updated 14-April-2014
Tool run by JDA on st 16.04.2014 at 20:25:44,77.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Jirka\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

16.4.2014 20:27:50 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Users\JDA\AppData\LocalLow\{2A8BD126-F193-5CF3-2386-2AF161EFB39E} deleted
C:\Users\JDA\AppData\LocalLow\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} deleted
C:\Users\JDA\AppData\LocalLow\{BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F} deleted
C:\Users\Jirka\AppData\LocalLow\{2A8BD126-F193-5CF3-2386-2AF161EFB39E} deleted
C:\Users\Jirka\AppData\LocalLow\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} deleted
C:\Users\JDA\AppData\Local\genienext deleted
C:\Users\JDA\daemonprocess.txt deleted
C:\Users\JDA\.android deleted
C:\Users\Jirka\daemonprocess.txt deleted
C:\PROGRA~2\SNT deleted
C:\Program Files\SNT deleted
C:\PROGRA~2\YoutubeAdblocker deleted
C:\Program Files\YoutubeAdblocker deleted
C:\PROGRA~2\safewoeb deleted
C:\Program Files\safewoeb deleted
C:\Program Files\Speed Test 127 deleted
C:\Program Files\zgametb deleted
C:\Users\JDA\AppData\Roaming\newnext.me deleted
C:\Users\JDA\AppData\Roaming\PerformerSoft deleted
C:\Users\JDA\AppData\Roaming\OpenCandy deleted
C:\Users\Jirka\AppData\Roaming\PerformerSoft deleted
C:\PROGRA~2\InstallMate deleted
C:\Users\JDA\AppData\Local\OpenCandy deleted
C:\Users\JDA\AppData\Local\cache deleted
C:\Users\JDA\AppData\Local\SwvUpdater deleted
C:\Users\JDA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FTDownloader.com deleted
C:\Users\JDA\AppData\LocalLow\zgametb deleted
C:\Users\Jirka\AppData\LocalLow\zgametb deleted
C:\Windows\system32\tasks\AmiUpdXp deleted
C:\Windows\system32\roboot.exe deleted
C:\Windows\System32\AI_RecycleBin deleted
C:\Users\JDA\Documents\Mobogenie deleted
C:\Users\JDA\Desktop\FTDownloader.lnk deleted
C:\Users\JDA\AppData\Roaming\Mozilla\Extensions\freegames4357@BestOffers deleted
"C:\PROGRA~2\a956c69f9e08b4ea\{4820778D-AB0D-6D18-C316-52A6A0E1D507}" deleted
"C:\PROGRA~2\a956c69f9e08b4ea\{497C131E-2032-051B-B32A-C69A960FBB13}" deleted
"C:\PROGRA~2\a956c69f9e08b4ea\{497C131E-2032-051B-B32A-C69A960FBB13}.old" deleted
"C:\PROGRA~2\a956c69f9e08b4ea\{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}" deleted
"C:\PROGRA~2\a956c69f9e08b4ea\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}" deleted
"C:\PROGRA~2\a956c69f9e08b4ea" deleted
"C:\Users\JDA\AppData\Local\Mobogenie" deleted
"C:\Users\JDA\AppData\Roaming\Mozilla\Extensions\speedtest4354@BestOffers" deleted

==== Firefox Extensions Registry ======================

[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"speedtest4354@BestOffers"="C:\Users\JDA\AppData\Roaming\Mozilla\Extensions\speedtest4354@BestOffers" []

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
aknhaddjojgaldaffefbdhafiioikajl - C:\Program Files\zgametb\chrome-newtab-search.crx[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[03.03.2014 10:53]

YoutubeAdblocker - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Administrator\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Administrator\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Administrator\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Administrator\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Guest\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Guest\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Guest\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Guest\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - JDA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - JDA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - JDA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - JDA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - JDA\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Skype Click to Call - JDA\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Smart Coupon - JDA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - JDA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - JDA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - JDA\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - JDA\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - JDA\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - JDA\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - JDA\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - JDA\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - JDA\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - JDA\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Jirka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Jirka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Jirka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Jirka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
New Tab Search - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknhaddjojgaldaffefbdhafiioikajl
YoutubeAdblocker - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
http //mail.google.com/ - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\fabbdelcjjonmiacdcaanldmljppppbf
Skype Click to Call - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
St\u0159\u00EDle\u010Dky - online hry zdarma - webgames.cz - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkbnipcjmoipoachkeanicnojfeimjeb
Smart Coupon - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Jirka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Jirka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Jirka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Jirka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - Jirka\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - Jirka\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - Jirka\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - Jirka\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak
YoutubeAdblocker - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib
Smart Coupon - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok
safeeweb - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf
SNT - UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak

==== Chrome Fix ======================

C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.amaizingsearches.info_0.localstorage deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.amaizingsearches.info_0.localstorage-journal deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.amaizingsearches.info_0.localstorage deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.amaizingsearches.info_0.localstorage-journal deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage-journal deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage-journal deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknhaddjojgaldaffefbdhafiioikajl deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\JDA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\JDA\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Jirka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Jirka\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bglmhhahjkkodjkckhbjagkgmopnjmib_0.localstorage deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bglmhhahjkkodjkckhbjagkgmopnjmib_0.localstorage-journal deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bglmhhahjkkodjkckhbjagkgmopnjmib_0.localstorage deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bglmhhahjkkodjkckhbjagkgmopnjmib_0.localstorage-journal deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bglmhhahjkkodjkckhbjagkgmopnjmib deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\JDA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\JDA\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Jirka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\Jirka\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\mdapmeleikeppmfgadilffngabfpibok deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mdapmeleikeppmfgadilffngabfpibok_0.localstorage deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mdapmeleikeppmfgadilffngabfpibok_0.localstorage-journal deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mdapmeleikeppmfgadilffngabfpibok_0.localstorage deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mdapmeleikeppmfgadilffngabfpibok_0.localstorage-journal deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\JDA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\JDA\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Jirka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Jirka\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nidbpamkhaaamefbgnigjgnlppjfljhf_0.localstorage deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nidbpamkhaaamefbgnigjgnlppjfljhf_0.localstorage-journal deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nidbpamkhaaamefbgnigjgnlppjfljhf_0.localstorage deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nidbpamkhaaamefbgnigjgnlppjfljhf_0.localstorage-journal deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nidbpamkhaaamefbgnigjgnlppjfljhf deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Guest\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\JDA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\JDA\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Jirka\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Jirka\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\UpdatusUser\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\UpdatusUser\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\UpdatusUser\AppData\Local\Torch\User Data\Default\Extensions\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ogmbkcnnmfmgficlcohfefcoadhjehak_0.localstorage deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ogmbkcnnmfmgficlcohfefcoadhjehak_0.localstorage-journal deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ogmbkcnnmfmgficlcohfefcoadhjehak_0.localstorage deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ogmbkcnnmfmgficlcohfefcoadhjehak_0.localstorage-journal deleted successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ogmbkcnnmfmgficlcohfefcoadhjehak deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/?ocid=U221DHP&pc=U221"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/?ocid=U221DHP&pc=U221"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{16AA1D11-1026-4704-9BA7-69074E6DBFE5}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Unknown Url="Not_Found"
{16AA1D11-1026-4704-9BA7-69074E6DBFE5} Bing Url="http://www.bing.com/search?FORM=U221DF& ... -SearchBox"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{A3C678DC-979B-48E6-9C21-D94C502C1194} Wikipedie (cs) Url="http://cs.wikipedia.org/w/index.php?tit ... earchTerms}"

==== Reset Google Chrome ======================

C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{573bf47c-2566-449d-ba1b-417d5d3fb9fd} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{573bf47c-2566-449d-ba1b-417d5d3fb9fd} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{573bf47c-2566-449d-ba1b-417d5d3fb9fd} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{573bf47c-2566-449d-ba1b-417d5d3fb9fd} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A8BD126-F193-5CF3-2386-2AF161EFB39E} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A8BD126-F193-5CF3-2386-2AF161EFB39E} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A8BD126-F193-5CF3-2386-2AF161EFB39E} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A8BD126-F193-5CF3-2386-2AF161EFB39E} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{573bf47c-2566-449d-ba1b-417d5d3fb9fd} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{573bf47c-2566-449d-ba1b-417d5d3fb9fd} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2A8BD126-F193-5CF3-2386-2AF161EFB39E} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{2A8BD126-F193-5CF3-2386-2AF161EFB39E} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A8BD126-F193-5CF3-2386-2AF161EFB39E} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2D1D3380-C8B5-FF2F-EA67-B9D2FCDBCA44} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDD5D8D2-6F6E-6FC3-AC5A-E342EBEC286F} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{573bf47c-2566-449d-ba1b-417d5d3fb9fd} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{11C8C9C0-D918-44C0-8B5E-D297DA42F2C7} deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Mozilla\Firefox\Extensions\freegames4357@BestOffers deleted successfully
HKEY_USERS\S-1-5-21-1957534622-2435220491-3010217779-1000\Software\Mozilla\Firefox\Extensions\speedtest4354@BestOffers deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{573bf47c-2566-449d-ba1b-417d5d3fb9fd} deleted successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\b147798f-05f3-4e23-b7c5-0bfa5e6db492 deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\aknhaddjojgaldaffefbdhafiioikajl deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{497C131E-2032-051B-B32A-C69A960FBB13} deleted successfully

==== Empty IE Cache ======================

C:\Users\JDA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\JDA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\JDA\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\JDA\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache is not empty, a reboot is needed

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=2585 folders=391 126318307 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\JDA\AppData\Local\Temp will be emptied at reboot
C:\Users\Jirka\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\JDA\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied
C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Jirka\AppData\Local\Temp\FXSAPIDebugLogFile.txt" not found
"C:\Users\JDA\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\447F6EGK\localhost" not found
"C:\Users\Jirka\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\TCWC9EUJ\cache.lego.com" not found
"C:\Users\Jirka\AppData\Local\Temp\08f56ff6-864d-4a92-944a-57b870198cb2" not found
"C:\Users\Jirka\AppData\Local\Temp\scoped_dir3420_17771" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted

==== EOF on st 16.04.2014 at 21:35:39,14 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s msmfgplbm.exe?

#4 Příspěvek od vyosek »

:arrow: Vsak taky jeste nekoncime :arcisit:

:arrow: Stahnete Malwarebytes Anti-Rootkit http://www.bleepingcomputer.com/downloa ... i-rootkit/
  • Ulozte nejlepe na Plochu a rozbalte
  • Spustte kliknutim na mbar
  • Nyni postupne kliknete na Next a Update
  • Po dokonceni update (aktualizace) databaze kliknete opet na Next
  • Nechte zaskrtnute vsechny tri moznosti a klinete na Scan cimz spustite prohledavani PC
  • Po dokonceni skenu (cca 5 minutek) zkontrolujte, zda-li je u vsech nalezu (samozrejme pokud budou) zatrzitko
  • Tez zkontrolujte, jetsli je zatrzitko u Create Restore point
  • Nyni kliknete na CleanUp cimz nalezenou infekci odstranime
  • PC bude restartovan
  • Slozka mbar by mela obsahovat log (a zrejme se i sam otevre) mbar-log-rok-mesic-den (hodina-minuta-sekunda).txt, ten mi sem dejte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Indy13
Návštěvník
Návštěvník
Příspěvky: 41
Registrován: 12 kvě 2009 22:32

Re: Problém s msmfgplbm.exe?

#5 Příspěvek od Indy13 »

Tak tentokrát jsme se posunuli, podezřelý proces je pryč, děkuji velmi! :-) V té souvislosti bych se rád zeptal:
- MSSE neměl tušení, že tam něco takového je. Znamená to, že je tak špatný? Doporučíte nějaký jiný AV?
- toto PC je součástí domácí sítě, je možné, že se mi to rozšířilo na ostatní PC?

Ještě jednou děkuji a zdravím.

Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org

Database version: v2014.04.17.02

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16428
JDA :: JUNIOR [administrator]

17.4.2014 12:46:45
mbar-log-2014-04-17 (12-46-45).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 296351
Time elapsed: 27 minute(s), 53 second(s)

Memory Processes Detected: 1
C:\Windows\inf\msmfgplbm\msmfgplbm.exe (BitcoinMiner) -> 3040 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mssgunSrv (Trojan.Agent.VBSGen) -> Data: C:\Windows\inf\mssgun.vbe -> Delete on reboot.

Registry Data Items Detected: 1
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs (Trojan.SProtector) -> Bad: (c:\progra~1\sw-boo~1\assist~1.dll) Good: () -> Replace on reboot.

Folders Detected: 0
(No malicious items detected)

Files Detected: 5
C:\Program Files\SW-Booster\Assistant.dll (Trojan.SProtector) -> Delete on reboot.
C:\Program Files\SW-Booster\AssistantSvc.dll (Trojan.SProtector) -> Delete on reboot.
C:\Windows\inf\msmfgplbm\msmfgplbm.exe (BitcoinMiner) -> Delete on reboot.
C:\Users\Jirka\Downloads\Lego Universe.exe (Trojan.Agent) -> Delete on reboot.
C:\Windows\inf\mssgun.vbe (Trojan.Agent.VBSGen) -> Delete on reboot.

Physical Sectors Detected: 0
(No malicious items detected)

(end)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém s msmfgplbm.exe?

#6 Příspěvek od vyosek »

:arrow: Tak MSE nepatri k uplne nejkvalitnejsim, pokud jej vymenite napr. za Avast, urcite tim nic nezkazite

:arrow: Do site a na jina PC by se to sirit nemelo

:arrow: Poprosim nyni o log z FSRT http://forum.viry.cz/viewtopic.php?f=13&t=133100
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět