Problém s SpeedMyComputer a FixMyRegitry
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
-
JohnyPlzenak
- Návštěvník

- Příspěvky: 7
- Registrován: 09 Kvě 2014 10:04
Problém s SpeedMyComputer a FixMyRegitry
Dobrý den,
včera se "sám od sebe" nainstaloval program SpeedMyComputer. Po odinstalování se nainstaluje FixMyRegitry. Po jeho odinstalování se nainstaluje první¨¨ě zmínění program a tak je to stále dokola. Jako ochranu používám Essential. Snad je to dostatečná ochrana.
Předem moc děkuji za pomoc, protože fakt nevím, co udělat.
Zde je log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2014 01
Ran by Honza (administrator) on HONZA-PC on 09-05-2014 11:13:54
Running from C:\Users\Honza\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
() C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Honza\Desktop\FRST-OlderVersion\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [AutoKMS] => C:\Windows\AutoKMS.exe
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-01] (Google Inc.)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [icq] => C:\Users\Honza\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-08] (ICQ)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [SpeedUpMyComputer] => C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [FixMyRegistry] => C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe [1886840 2013-07-22] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {ad326ea0-90c4-11e3-87c6-94de8025d71c} - G:\AutoRun.exe /s
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {dfcb13e3-d681-11e3-9848-94de8025d71c} - F:\setup.exe
Startup: C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
SearchScopes: HKCU - {07436C38-B5AA-4D41-837B-EBA553014277} URL = http://www.firmy.cz/?q={searchTerms}&so ... earch_9973
SearchScopes: HKCU - {16816944-72D4-427B-942F-1A347F3D4E2D} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... earch_9973
SearchScopes: HKCU - {168A8C93-723C-4EFA-9230-6B4CCCA2673D} URL = http://www.mapy.cz/?query={searchTerms} ... earch_9973
SearchScopes: HKCU - {1A35AD7F-7892-4ABA-A3FB-719DE456C3BF} URL = http://slovnik.seznam.cz/?q={searchTerm ... earch_9973
SearchScopes: HKCU - {5DA88986-BC70-4D88-9FC8-134867001EBF} URL = http://encyklopedie.seznam.cz/search?q= ... earch_9973
SearchScopes: HKCU - {7BEF446A-7BFD-4872-873F-1866D768221C} URL = http://www.novinky.cz/hledej?w={searchT ... earch_9973
SearchScopes: HKCU - {A01D6497-C06F-455E-A9F2-F25B0D61F41C} URL = http://search.seznam.cz/?q={searchTerms ... earch_9973
SearchScopes: HKCU - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/search?query={searchTerms}&from=IE
SearchScopes: HKCU - {A567562B-91AA-4F87-B352-BF25B07D822A} URL = http://slovnik.seznam.cz/?q={searchTerm ... earch_9973
SearchScopes: HKCU - {ADFDF72A-C07F-4721-8C34-6E3ED8D76CFD} URL = http://tv.seznam.cz/hledej?w={searchTer ... earch_9973
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Honza\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {41545534-2D56-3700-76A7-7A786E7484D7} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.46
FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Honza\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR StartupUrls: "startup_urls_migration_time": "13034446865368657"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\gcswf32.dll No File
CHR Plugin: (Norton Confidential) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.0.0.72_0\npcoplgn.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Extension: (Google Translate) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2013-07-02]
CHR Extension: (Dokumenty Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-07]
CHR Extension: (Disk Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-07-02]
CHR Extension: (YouTube) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-03]
CHR Extension: (Vyhledávání Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-03]
CHR Extension: (AdBlock) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-07-02]
CHR Extension: (Peněženka Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR Extension: (Gmail) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-07-03]
==================== Services (Whitelisted) =================
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-01] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2014-05-01] ()
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
R3 KbFilter_Kb_FlexDef3x; C:\Windows\System32\DRIVERS\KbFilter_FlexDef3x.sys [22016 2012-10-16] (Siliten)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 vpnva; system32\DRIVERS\vpnva64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-09 11:13 - 2014-05-09 11:14 - 00019029 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00029696 _____ () C:\Users\Honza\AppData\Local\MSGBOX.EXE
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-09 11:13 - 2014-05-09 11:13 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-09 10:57 - 2014-05-09 10:57 - 00001212 _____ () C:\Users\Honza\Desktop\FixMyRegistry.lnk
2014-05-09 10:39 - 2014-05-09 11:13 - 00000000 ____D () C:\FRST
2014-05-09 10:37 - 2014-05-09 11:13 - 02064384 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-05-08 16:59 - 2014-05-08 16:59 - 00000730 _____ () C:\Users\Public\Desktop\Call of Juarez Gunslinger.lnk
2014-05-08 16:59 - 2014-05-08 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Juarez Gunslinger
2014-05-08 16:46 - 2014-05-09 10:57 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
2014-05-08 16:45 - 2014-05-09 10:57 - 00000000 ____D () C:\Program Files (x86)\SmartTweak
2014-05-06 13:09 - 2014-05-06 13:29 - 00000000 ____D () C:\Users\Honza\AppData\Local\The Witcher
2014-05-06 13:09 - 2014-05-06 13:20 - 00000000 ____D () C:\Users\Honza\Documents\The Witcher
2014-05-06 13:08 - 2014-05-06 13:08 - 00000000 ____D () C:\Users\Public\Documents\The Witcher
2014-05-06 11:34 - 2014-05-06 11:34 - 00000210 _____ () C:\Users\Honza\Desktop\The Witcher Enhanced Edition.url
2014-05-02 13:07 - 2014-05-02 13:07 - 00000211 _____ () C:\Users\Honza\Desktop\Torchlight II.url
2014-05-02 12:57 - 2014-05-02 12:57 - 00000209 _____ () C:\Users\Honza\Desktop\Titan Quest Immortal Throne.url
2014-05-02 12:53 - 2014-05-02 12:53 - 00000211 _____ () C:\Users\Honza\Desktop\War Thunder.url
2014-05-02 12:28 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-02 12:28 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-02 12:28 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-02 12:28 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-01 14:19 - 2014-05-01 14:19 - 00000000 ____D () C:\Users\Honza\AppData\Local\CrashRpt
2014-05-01 14:17 - 2014-05-01 14:17 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls
2014-04-24 13:20 - 2014-04-24 13:20 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-04-24 13:20 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-24 13:19 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-24 13:17 - 2014-04-24 13:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-24 13:17 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-24 13:17 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-23 13:34 - 2014-04-23 13:34 - 00000000 ____D () C:\Users\dub_cm_auto
2014-04-19 14:04 - 2014-04-19 14:46 - 00000000 ____D () C:\Users\Honza\Documents\NCSOFT
2014-04-19 12:25 - 2014-04-19 14:46 - 00000000 ____D () C:\Users\Honza\AppData\Local\NCSOFT
2014-04-19 12:25 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\NCSOFT
2014-04-18 11:13 - 2014-04-18 11:13 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 11:13 - 2014-04-18 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-09 11:52 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-09 11:52 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-09 11:52 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-09 11:52 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-09 11:52 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-09 11:52 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-09 11:52 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-09 11:52 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-09 11:52 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-09 11:52 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-09 11:52 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-09 11:52 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-09 11:52 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-09 11:52 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-09 11:52 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-09 11:52 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-09 11:52 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-09 11:52 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-09 11:52 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-09 11:52 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-09 11:52 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-09 11:52 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-09 11:52 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-09 11:52 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-09 11:52 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-09 11:52 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-09 11:52 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-09 11:52 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-09 11:52 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-09 11:52 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-09 11:52 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-09 11:52 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-09 11:52 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-09 11:52 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-09 11:52 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-09 11:52 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-09 11:52 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-09 11:52 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-09 11:52 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-09 11:52 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-09 11:52 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-09 11:52 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-09 11:52 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-09 11:52 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 10:52 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 10:52 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 10:52 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 10:52 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 10:52 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 10:52 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 10:52 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 10:52 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 10:52 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 10:52 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 10:52 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 10:52 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
==================== One Month Modified Files and Folders =======
2014-05-09 11:14 - 2014-05-09 11:13 - 00019029 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00029696 _____ () C:\Users\Honza\AppData\Local\MSGBOX.EXE
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-09 11:13 - 2014-05-09 11:13 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-09 11:13 - 2014-05-09 10:39 - 00000000 ____D () C:\FRST
2014-05-09 11:13 - 2014-05-09 10:37 - 02064384 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-05-09 11:12 - 2014-02-18 11:00 - 00003948 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1cf2c87e8d87286
2014-05-09 11:12 - 2014-02-18 11:00 - 00003696 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1cf2c87e8c97e2e
2014-05-09 11:12 - 2014-02-18 11:00 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf2c87e8d87286.job
2014-05-09 11:12 - 2014-02-18 11:00 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf2c87e8c97e2e.job
2014-05-09 10:57 - 2014-05-09 10:57 - 00001212 _____ () C:\Users\Honza\Desktop\FixMyRegistry.lnk
2014-05-09 10:57 - 2014-05-08 16:46 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
2014-05-09 10:57 - 2014-05-08 16:45 - 00000000 ____D () C:\Program Files (x86)\SmartTweak
2014-05-09 10:42 - 2013-07-01 13:32 - 01246435 _____ () C:\Windows\WindowsUpdate.log
2014-05-09 10:38 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-09 10:38 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-09 10:37 - 2011-04-12 10:34 - 00668866 _____ () C:\Windows\system32\perfh005.dat
2014-05-09 10:37 - 2011-04-12 10:34 - 00141526 _____ () C:\Windows\system32\perfc005.dat
2014-05-09 10:37 - 2009-07-14 07:13 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-09 10:36 - 2013-07-02 20:44 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Seznam.cz
2014-05-09 10:34 - 2013-07-02 20:01 - 00000000 ____D () C:\Programy
2014-05-09 10:31 - 2013-07-01 14:12 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-09 10:31 - 2010-11-21 05:47 - 01456240 _____ () C:\Windows\PFRO.log
2014-05-09 10:31 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-09 10:31 - 2009-07-14 06:51 - 00109435 _____ () C:\Windows\setupact.log
2014-05-08 16:59 - 2014-05-08 16:59 - 00000730 _____ () C:\Users\Public\Desktop\Call of Juarez Gunslinger.lnk
2014-05-08 16:59 - 2014-05-08 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Juarez Gunslinger
2014-05-08 16:43 - 2013-07-02 20:00 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\uTorrent
2014-05-08 10:10 - 2013-07-07 08:36 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Skype
2014-05-07 14:25 - 2013-07-02 12:26 - 00000000 ____D () C:\Users\Honza\AppData\Local\Microsoft Games
2014-05-06 13:29 - 2014-05-06 13:09 - 00000000 ____D () C:\Users\Honza\AppData\Local\The Witcher
2014-05-06 13:20 - 2014-05-06 13:09 - 00000000 ____D () C:\Users\Honza\Documents\The Witcher
2014-05-06 13:09 - 2013-07-01 14:37 - 00776356 _____ () C:\Windows\DirectX.log
2014-05-06 13:08 - 2014-05-06 13:08 - 00000000 ____D () C:\Users\Public\Documents\The Witcher
2014-05-06 11:34 - 2014-05-06 11:34 - 00000210 _____ () C:\Users\Honza\Desktop\The Witcher Enhanced Edition.url
2014-05-02 13:07 - 2014-05-02 13:07 - 00000211 _____ () C:\Users\Honza\Desktop\Torchlight II.url
2014-05-02 12:57 - 2014-05-02 12:57 - 00000209 _____ () C:\Users\Honza\Desktop\Titan Quest Immortal Throne.url
2014-05-02 12:53 - 2014-05-02 12:53 - 00000211 _____ () C:\Users\Honza\Desktop\War Thunder.url
2014-05-01 14:19 - 2014-05-01 14:19 - 00000000 ____D () C:\Users\Honza\AppData\Local\CrashRpt
2014-05-01 14:18 - 2013-07-03 21:16 - 00000000 ____D () C:\Users\Honza\Documents\my games
2014-05-01 14:17 - 2014-05-01 14:17 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls
2014-05-01 14:17 - 2013-07-30 18:47 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-05-01 12:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-29 16:01 - 2014-05-02 12:28 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-02 12:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-02 12:28 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-02 12:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-28 14:55 - 2013-12-15 09:58 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Spotify
2014-04-28 11:41 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-04-27 12:38 - 2013-07-01 13:54 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-27 11:46 - 2013-11-15 16:38 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-04-25 11:45 - 2013-12-15 09:58 - 00000000 ____D () C:\Users\Honza\AppData\Local\Spotify
2014-04-24 13:20 - 2014-04-24 13:20 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-04-24 13:20 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-24 13:20 - 2014-04-24 13:19 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-24 13:20 - 2013-07-02 19:51 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-04-24 13:19 - 2013-07-01 13:54 - 00000000 ____D () C:\ProgramData\Norton
2014-04-24 13:17 - 2014-04-24 13:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-23 13:34 - 2014-04-23 13:34 - 00000000 ____D () C:\Users\dub_cm_auto
2014-04-19 14:46 - 2014-04-19 14:04 - 00000000 ____D () C:\Users\Honza\Documents\NCSOFT
2014-04-19 14:46 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Local\NCSOFT
2014-04-19 12:25 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\NCSOFT
2014-04-18 11:13 - 2014-04-18 11:13 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 11:13 - 2014-04-18 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-18 11:13 - 2013-10-18 10:03 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-18 11:13 - 2013-07-04 18:34 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-14 20:13 - 2013-07-04 18:34 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2013-10-18 09:55 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2013-07-04 18:34 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2013-07-04 18:34 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-14 04:24 - 2014-04-24 13:17 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-04-24 13:17 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-09 11:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-09 11:52 - 2013-07-16 11:51 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 11:51 - 2013-07-03 16:39 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Honza\AppData\Local\Temp\bitool.dll
C:\Users\Honza\AppData\Local\Temp\DTLite4491-0356.exe
C:\Users\Honza\AppData\Local\Temp\FixMyRegistry.exe
C:\Users\Honza\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Honza\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Honza\AppData\Local\Temp\SpeedUpMyComputer.exe
C:\Users\Honza\AppData\Local\Temp\Wildstar.exe
C:\Users\Honza\AppData\Local\Temp\_is2A8F.exe
C:\Users\Honza\AppData\Local\Temp\_is42DD.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-01 12:17
==================== End Of Log ============================
včera se "sám od sebe" nainstaloval program SpeedMyComputer. Po odinstalování se nainstaluje FixMyRegitry. Po jeho odinstalování se nainstaluje první¨¨ě zmínění program a tak je to stále dokola. Jako ochranu používám Essential. Snad je to dostatečná ochrana.
Předem moc děkuji za pomoc, protože fakt nevím, co udělat.
Zde je log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-05-2014 01
Ran by Honza (administrator) on HONZA-PC on 09-05-2014 11:13:54
Running from C:\Users\Honza\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
() C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Honza\Desktop\FRST-OlderVersion\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [AutoKMS] => C:\Windows\AutoKMS.exe
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-01] (Google Inc.)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [icq] => C:\Users\Honza\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-08] (ICQ)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [SpeedUpMyComputer] => C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [FixMyRegistry] => C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe [1886840 2013-07-22] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {ad326ea0-90c4-11e3-87c6-94de8025d71c} - G:\AutoRun.exe /s
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {dfcb13e3-d681-11e3-9848-94de8025d71c} - F:\setup.exe
Startup: C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
SearchScopes: HKCU - {07436C38-B5AA-4D41-837B-EBA553014277} URL = http://www.firmy.cz/?q={searchTerms}&so ... earch_9973
SearchScopes: HKCU - {16816944-72D4-427B-942F-1A347F3D4E2D} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... earch_9973
SearchScopes: HKCU - {168A8C93-723C-4EFA-9230-6B4CCCA2673D} URL = http://www.mapy.cz/?query={searchTerms} ... earch_9973
SearchScopes: HKCU - {1A35AD7F-7892-4ABA-A3FB-719DE456C3BF} URL = http://slovnik.seznam.cz/?q={searchTerm ... earch_9973
SearchScopes: HKCU - {5DA88986-BC70-4D88-9FC8-134867001EBF} URL = http://encyklopedie.seznam.cz/search?q= ... earch_9973
SearchScopes: HKCU - {7BEF446A-7BFD-4872-873F-1866D768221C} URL = http://www.novinky.cz/hledej?w={searchT ... earch_9973
SearchScopes: HKCU - {A01D6497-C06F-455E-A9F2-F25B0D61F41C} URL = http://search.seznam.cz/?q={searchTerms ... earch_9973
SearchScopes: HKCU - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/search?query={searchTerms}&from=IE
SearchScopes: HKCU - {A567562B-91AA-4F87-B352-BF25B07D822A} URL = http://slovnik.seznam.cz/?q={searchTerm ... earch_9973
SearchScopes: HKCU - {ADFDF72A-C07F-4721-8C34-6E3ED8D76CFD} URL = http://tv.seznam.cz/hledej?w={searchTer ... earch_9973
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\Honza\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll (qip.ru)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - No Name - {41545534-2D56-3700-76A7-7A786E7484D7} - No File
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.46
FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Honza\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR StartupUrls: "startup_urls_migration_time": "13034446865368657"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\gcswf32.dll No File
CHR Plugin: (Norton Confidential) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.0.0.72_0\npcoplgn.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Extension: (Google Translate) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2013-07-02]
CHR Extension: (Dokumenty Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-07]
CHR Extension: (Disk Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-07-02]
CHR Extension: (YouTube) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-03]
CHR Extension: (Vyhledávání Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-03]
CHR Extension: (AdBlock) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-07-02]
CHR Extension: (Peněženka Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR Extension: (Gmail) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-07-03]
==================== Services (Whitelisted) =================
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-01] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2014-05-01] ()
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
R3 KbFilter_Kb_FlexDef3x; C:\Windows\System32\DRIVERS\KbFilter_FlexDef3x.sys [22016 2012-10-16] (Siliten)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 vpnva; system32\DRIVERS\vpnva64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-09 11:13 - 2014-05-09 11:14 - 00019029 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00029696 _____ () C:\Users\Honza\AppData\Local\MSGBOX.EXE
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-09 11:13 - 2014-05-09 11:13 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-09 10:57 - 2014-05-09 10:57 - 00001212 _____ () C:\Users\Honza\Desktop\FixMyRegistry.lnk
2014-05-09 10:39 - 2014-05-09 11:13 - 00000000 ____D () C:\FRST
2014-05-09 10:37 - 2014-05-09 11:13 - 02064384 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-05-08 16:59 - 2014-05-08 16:59 - 00000730 _____ () C:\Users\Public\Desktop\Call of Juarez Gunslinger.lnk
2014-05-08 16:59 - 2014-05-08 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Juarez Gunslinger
2014-05-08 16:46 - 2014-05-09 10:57 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
2014-05-08 16:45 - 2014-05-09 10:57 - 00000000 ____D () C:\Program Files (x86)\SmartTweak
2014-05-06 13:09 - 2014-05-06 13:29 - 00000000 ____D () C:\Users\Honza\AppData\Local\The Witcher
2014-05-06 13:09 - 2014-05-06 13:20 - 00000000 ____D () C:\Users\Honza\Documents\The Witcher
2014-05-06 13:08 - 2014-05-06 13:08 - 00000000 ____D () C:\Users\Public\Documents\The Witcher
2014-05-06 11:34 - 2014-05-06 11:34 - 00000210 _____ () C:\Users\Honza\Desktop\The Witcher Enhanced Edition.url
2014-05-02 13:07 - 2014-05-02 13:07 - 00000211 _____ () C:\Users\Honza\Desktop\Torchlight II.url
2014-05-02 12:57 - 2014-05-02 12:57 - 00000209 _____ () C:\Users\Honza\Desktop\Titan Quest Immortal Throne.url
2014-05-02 12:53 - 2014-05-02 12:53 - 00000211 _____ () C:\Users\Honza\Desktop\War Thunder.url
2014-05-02 12:28 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-02 12:28 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-02 12:28 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-02 12:28 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-01 14:19 - 2014-05-01 14:19 - 00000000 ____D () C:\Users\Honza\AppData\Local\CrashRpt
2014-05-01 14:17 - 2014-05-01 14:17 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls
2014-04-24 13:20 - 2014-04-24 13:20 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-04-24 13:20 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-24 13:19 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-24 13:17 - 2014-04-24 13:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-24 13:17 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-24 13:17 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-23 13:34 - 2014-04-23 13:34 - 00000000 ____D () C:\Users\dub_cm_auto
2014-04-19 14:04 - 2014-04-19 14:46 - 00000000 ____D () C:\Users\Honza\Documents\NCSOFT
2014-04-19 12:25 - 2014-04-19 14:46 - 00000000 ____D () C:\Users\Honza\AppData\Local\NCSOFT
2014-04-19 12:25 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\NCSOFT
2014-04-18 11:13 - 2014-04-18 11:13 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 11:13 - 2014-04-18 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-09 11:52 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-09 11:52 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-09 11:52 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-09 11:52 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-09 11:52 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-09 11:52 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-09 11:52 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-09 11:52 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-09 11:52 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-09 11:52 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-09 11:52 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-09 11:52 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-09 11:52 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-09 11:52 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-09 11:52 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-09 11:52 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-09 11:52 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-09 11:52 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-09 11:52 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-09 11:52 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-09 11:52 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-09 11:52 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-09 11:52 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-09 11:52 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-09 11:52 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-09 11:52 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-09 11:52 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-09 11:52 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-09 11:52 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-09 11:52 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-09 11:52 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-09 11:52 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-09 11:52 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-09 11:52 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-09 11:52 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-09 11:52 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-09 11:52 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-09 11:52 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-09 11:52 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-09 11:52 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-09 11:52 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-09 11:52 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-09 11:52 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-09 11:52 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 10:52 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 10:52 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 10:52 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 10:52 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 10:52 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 10:52 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 10:52 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 10:52 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 10:52 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 10:52 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 10:52 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 10:52 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 10:52 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
==================== One Month Modified Files and Folders =======
2014-05-09 11:14 - 2014-05-09 11:13 - 00019029 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00029696 _____ () C:\Users\Honza\AppData\Local\MSGBOX.EXE
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-09 11:13 - 2014-05-09 11:13 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-09 11:13 - 2014-05-09 10:39 - 00000000 ____D () C:\FRST
2014-05-09 11:13 - 2014-05-09 10:37 - 02064384 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-05-09 11:12 - 2014-02-18 11:00 - 00003948 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1cf2c87e8d87286
2014-05-09 11:12 - 2014-02-18 11:00 - 00003696 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1cf2c87e8c97e2e
2014-05-09 11:12 - 2014-02-18 11:00 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf2c87e8d87286.job
2014-05-09 11:12 - 2014-02-18 11:00 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf2c87e8c97e2e.job
2014-05-09 10:57 - 2014-05-09 10:57 - 00001212 _____ () C:\Users\Honza\Desktop\FixMyRegistry.lnk
2014-05-09 10:57 - 2014-05-08 16:46 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
2014-05-09 10:57 - 2014-05-08 16:45 - 00000000 ____D () C:\Program Files (x86)\SmartTweak
2014-05-09 10:42 - 2013-07-01 13:32 - 01246435 _____ () C:\Windows\WindowsUpdate.log
2014-05-09 10:38 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-09 10:38 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-09 10:37 - 2011-04-12 10:34 - 00668866 _____ () C:\Windows\system32\perfh005.dat
2014-05-09 10:37 - 2011-04-12 10:34 - 00141526 _____ () C:\Windows\system32\perfc005.dat
2014-05-09 10:37 - 2009-07-14 07:13 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-09 10:36 - 2013-07-02 20:44 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Seznam.cz
2014-05-09 10:34 - 2013-07-02 20:01 - 00000000 ____D () C:\Programy
2014-05-09 10:31 - 2013-07-01 14:12 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-09 10:31 - 2010-11-21 05:47 - 01456240 _____ () C:\Windows\PFRO.log
2014-05-09 10:31 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-09 10:31 - 2009-07-14 06:51 - 00109435 _____ () C:\Windows\setupact.log
2014-05-08 16:59 - 2014-05-08 16:59 - 00000730 _____ () C:\Users\Public\Desktop\Call of Juarez Gunslinger.lnk
2014-05-08 16:59 - 2014-05-08 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Juarez Gunslinger
2014-05-08 16:43 - 2013-07-02 20:00 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\uTorrent
2014-05-08 10:10 - 2013-07-07 08:36 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Skype
2014-05-07 14:25 - 2013-07-02 12:26 - 00000000 ____D () C:\Users\Honza\AppData\Local\Microsoft Games
2014-05-06 13:29 - 2014-05-06 13:09 - 00000000 ____D () C:\Users\Honza\AppData\Local\The Witcher
2014-05-06 13:20 - 2014-05-06 13:09 - 00000000 ____D () C:\Users\Honza\Documents\The Witcher
2014-05-06 13:09 - 2013-07-01 14:37 - 00776356 _____ () C:\Windows\DirectX.log
2014-05-06 13:08 - 2014-05-06 13:08 - 00000000 ____D () C:\Users\Public\Documents\The Witcher
2014-05-06 11:34 - 2014-05-06 11:34 - 00000210 _____ () C:\Users\Honza\Desktop\The Witcher Enhanced Edition.url
2014-05-02 13:07 - 2014-05-02 13:07 - 00000211 _____ () C:\Users\Honza\Desktop\Torchlight II.url
2014-05-02 12:57 - 2014-05-02 12:57 - 00000209 _____ () C:\Users\Honza\Desktop\Titan Quest Immortal Throne.url
2014-05-02 12:53 - 2014-05-02 12:53 - 00000211 _____ () C:\Users\Honza\Desktop\War Thunder.url
2014-05-01 14:19 - 2014-05-01 14:19 - 00000000 ____D () C:\Users\Honza\AppData\Local\CrashRpt
2014-05-01 14:18 - 2013-07-03 21:16 - 00000000 ____D () C:\Users\Honza\Documents\my games
2014-05-01 14:17 - 2014-05-01 14:17 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls
2014-05-01 14:17 - 2013-07-30 18:47 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-05-01 12:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-29 16:01 - 2014-05-02 12:28 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-02 12:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-02 12:28 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-02 12:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-28 14:55 - 2013-12-15 09:58 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Spotify
2014-04-28 11:41 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-04-27 12:38 - 2013-07-01 13:54 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-27 11:46 - 2013-11-15 16:38 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-04-25 11:45 - 2013-12-15 09:58 - 00000000 ____D () C:\Users\Honza\AppData\Local\Spotify
2014-04-24 13:20 - 2014-04-24 13:20 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-04-24 13:20 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-24 13:20 - 2014-04-24 13:19 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-24 13:20 - 2013-07-02 19:51 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-04-24 13:19 - 2013-07-01 13:54 - 00000000 ____D () C:\ProgramData\Norton
2014-04-24 13:17 - 2014-04-24 13:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-23 13:34 - 2014-04-23 13:34 - 00000000 ____D () C:\Users\dub_cm_auto
2014-04-19 14:46 - 2014-04-19 14:04 - 00000000 ____D () C:\Users\Honza\Documents\NCSOFT
2014-04-19 14:46 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Local\NCSOFT
2014-04-19 12:25 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\NCSOFT
2014-04-18 11:13 - 2014-04-18 11:13 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 11:13 - 2014-04-18 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-18 11:13 - 2013-10-18 10:03 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-18 11:13 - 2013-07-04 18:34 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-14 20:13 - 2013-07-04 18:34 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2013-10-18 09:55 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2013-07-04 18:34 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2013-07-04 18:34 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-14 04:24 - 2014-04-24 13:17 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-04-24 13:17 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-09 11:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-09 11:52 - 2013-07-16 11:51 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 11:51 - 2013-07-03 16:39 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Honza\AppData\Local\Temp\bitool.dll
C:\Users\Honza\AppData\Local\Temp\DTLite4491-0356.exe
C:\Users\Honza\AppData\Local\Temp\FixMyRegistry.exe
C:\Users\Honza\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Honza\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Honza\AppData\Local\Temp\SpeedUpMyComputer.exe
C:\Users\Honza\AppData\Local\Temp\Wildstar.exe
C:\Users\Honza\AppData\Local\Temp\_is2A8F.exe
C:\Users\Honza\AppData\Local\Temp\_is42DD.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-01 12:17
==================== End Of Log ============================
- Přílohy
-
- Addition.rar
- (7.65 KiB) Staženo 44 x
Re: Problém s SpeedMyComputer a FixMyRegitry
Zdravim
Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
- Ulozte nejlepe na plochu
- Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
- Probehne vytvoreni zalohy a nasledne prohledavani
- Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
-
JohnyPlzenak
- Návštěvník

- Příspěvky: 7
- Registrován: 09 Kvě 2014 10:04
Re: Problém s SpeedMyComputer a FixMyRegitry
JRT log:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Honza on p 10.05.2014 at 11:22:16,29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\speedupmycomputer
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Bar
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smarttweak
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A01D6497-C06F-455E-A9F2-F25B0D61F41C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{95289393-33EA-4F8D-B952-483415B9C955}
~~~ Files
Successfully deleted: [File] "C:\Users\Honza\AppData\Roaming\microsoft\internet explorer\qipsearchbar.dll"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Honza\AppData\Roaming\getrighttogo"
Successfully deleted: [Folder] "C:\Program Files (x86)\smarttweak"
Successfully deleted: [Folder] "C:\Users\Honza\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p 10.05.2014 at 11:25:45,44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Honza on p 10.05.2014 at 11:22:16,29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\speedupmycomputer
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Bar
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Search Page
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smarttweak
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A01D6497-C06F-455E-A9F2-F25B0D61F41C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{95289393-33EA-4F8D-B952-483415B9C955}
~~~ Files
Successfully deleted: [File] "C:\Users\Honza\AppData\Roaming\microsoft\internet explorer\qipsearchbar.dll"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Honza\AppData\Roaming\getrighttogo"
Successfully deleted: [Folder] "C:\Program Files (x86)\smarttweak"
Successfully deleted: [Folder] "C:\Users\Honza\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p 10.05.2014 at 11:25:45,44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-
JohnyPlzenak
- Návštěvník

- Příspěvky: 7
- Registrován: 09 Kvě 2014 10:04
Re: Problém s SpeedMyComputer a FixMyRegitry
AdwCleaner log:
# AdwCleaner v3.207 - Report created 10/05/2014 at 11:33:07
# Updated 05/05/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Honza - HONZA-PC
# Running from : C:\Users\Honza\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Honza\AppData\Local\genienext
File Deleted : C:\Users\Honza\daemonprocess.txt
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FixMyRegistry]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FixMyRegistry
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17041
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
-\\ Google Chrome v34.0.1847.131
[ File : C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://www.super.cz/dosearch?q={searchTerms}&x=0&y=0
*************************
AdwCleaner[R0].txt - [2821 octets] - [25/12/2013 10:42:00]
AdwCleaner[R1].txt - [870 octets] - [25/12/2013 10:47:13]
AdwCleaner[R2].txt - [1649 octets] - [10/05/2014 11:25:45]
AdwCleaner[S0].txt - [2840 octets] - [25/12/2013 10:45:04]
AdwCleaner[S1].txt - [930 octets] - [25/12/2013 10:50:23]
AdwCleaner[S2].txt - [1534 octets] - [10/05/2014 11:33:07]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1594 octets] ##########
# AdwCleaner v3.207 - Report created 10/05/2014 at 11:33:07
# Updated 05/05/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Honza - HONZA-PC
# Running from : C:\Users\Honza\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\Honza\AppData\Local\genienext
File Deleted : C:\Users\Honza\daemonprocess.txt
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FixMyRegistry]
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FixMyRegistry
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17041
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
-\\ Google Chrome v34.0.1847.131
[ File : C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Deleted [Search Provider] : hxxp://www.super.cz/dosearch?q={searchTerms}&x=0&y=0
*************************
AdwCleaner[R0].txt - [2821 octets] - [25/12/2013 10:42:00]
AdwCleaner[R1].txt - [870 octets] - [25/12/2013 10:47:13]
AdwCleaner[R2].txt - [1649 octets] - [10/05/2014 11:25:45]
AdwCleaner[S0].txt - [2840 octets] - [25/12/2013 10:45:04]
AdwCleaner[S1].txt - [930 octets] - [25/12/2013 10:50:23]
AdwCleaner[S2].txt - [1534 octets] - [10/05/2014 11:33:07]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1594 octets] ##########
Re: Problém s SpeedMyComputer a FixMyRegitry
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
-
JohnyPlzenak
- Návštěvník

- Příspěvky: 7
- Registrován: 09 Kvě 2014 10:04
Re: Problém s SpeedMyComputer a FixMyRegitry
Zoek.exe v5.0.0.0 Updated 14-April-2014
Tool run by Honza on so 10.05.2014 at 12:48:41,46.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Honza\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
10.5.2014 12:49:28 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{41545534-2D56-3700-76A7-7A786E7484D7} deleted successfully
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\Users\Honza\.android deleted
C:\extensions.sqlite deleted
C:\extensions.ini deleted
C:\Users\Honza\AppData\Roaming\AutoGK.ini deleted
C:\PROGRA~3\xml421E.tmp deleted
C:\PROGRA~3\xml43F3.tmp deleted
C:\PROGRA~3\xml43F4.tmp deleted
C:\PROGRA~3\xml4404.tmp deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Honza\AppData\Local\cache deleted
C:\Windows\Syswow64\tmpA8AE.tmp deleted
C:\Windows\Syswow64\tmpA8AF.tmp deleted
C:\Users\Honza\AppData\Local\MSGBOX.EXE deleted
==== Chrome Look ======================
Google Translate - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb
AdBlock - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Use Search Asst"="yes"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
"Use Search Asst"="no"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{07436C38-B5AA-4D41-837B-EBA553014277} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... earch_9973"
{16816944-72D4-427B-942F-1A347F3D4E2D} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... earch_9973"
{168A8C93-723C-4EFA-9230-6B4CCCA2673D} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... earch_9973"
{1A35AD7F-7892-4ABA-A3FB-719DE456C3BF} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... earch_9973"
{5DA88986-BC70-4D88-9FC8-134867001EBF} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... earch_9973"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{7BEF446A-7BFD-4872-873F-1866D768221C} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... earch_9973"
{A567562B-91AA-4F87-B352-BF25B07D822A} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... earch_9973"
{ADFDF72A-C07F-4721-8C34-6E3ED8D76CFD} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... earch_9973"
==== Reset Google Chrome ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=133 folders=35 19225164 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Honza\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Honza\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on so 10.05.2014 at 12:56:05,52 ======================
Tool run by Honza on so 10.05.2014 at 12:48:41,46.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Honza\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
10.5.2014 12:49:28 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{41545534-2D56-3700-76A7-7A786E7484D7} deleted successfully
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\Users\Honza\.android deleted
C:\extensions.sqlite deleted
C:\extensions.ini deleted
C:\Users\Honza\AppData\Roaming\AutoGK.ini deleted
C:\PROGRA~3\xml421E.tmp deleted
C:\PROGRA~3\xml43F3.tmp deleted
C:\PROGRA~3\xml43F4.tmp deleted
C:\PROGRA~3\xml4404.tmp deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Honza\AppData\Local\cache deleted
C:\Windows\Syswow64\tmpA8AE.tmp deleted
C:\Windows\Syswow64\tmpA8AF.tmp deleted
C:\Users\Honza\AppData\Local\MSGBOX.EXE deleted
==== Chrome Look ======================
Google Translate - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb
AdBlock - Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Use Search Asst"="yes"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
"Use Search Asst"="no"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{07436C38-B5AA-4D41-837B-EBA553014277} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... earch_9973"
{16816944-72D4-427B-942F-1A347F3D4E2D} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... earch_9973"
{168A8C93-723C-4EFA-9230-6B4CCCA2673D} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... earch_9973"
{1A35AD7F-7892-4ABA-A3FB-719DE456C3BF} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... earch_9973"
{5DA88986-BC70-4D88-9FC8-134867001EBF} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... earch_9973"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{7BEF446A-7BFD-4872-873F-1866D768221C} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... earch_9973"
{A567562B-91AA-4F87-B352-BF25B07D822A} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... earch_9973"
{ADFDF72A-C07F-4721-8C34-6E3ED8D76CFD} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... earch_9973"
==== Reset Google Chrome ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=133 folders=35 19225164 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Honza\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Honza\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on so 10.05.2014 at 12:56:05,52 ======================
Re: Problém s SpeedMyComputer a FixMyRegitry
Dejte novy log z FRST
-
JohnyPlzenak
- Návštěvník

- Příspěvky: 7
- Registrován: 09 Kvě 2014 10:04
Re: Problém s SpeedMyComputer a FixMyRegitry
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-05-2014
Ran by Honza (administrator) on HONZA-PC on 10-05-2014 13:08:46
Running from C:\Users\Honza\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
() C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [AutoKMS] => C:\Windows\AutoKMS.exe
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-01] (Google Inc.)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [icq] => C:\Users\Honza\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-08] (ICQ)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {ad326ea0-90c4-11e3-87c6-94de8025d71c} - G:\AutoRun.exe /s
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {dfcb13e3-d681-11e3-9848-94de8025d71c} - F:\setup.exe
Startup: C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... GM_csCZ568
SearchScopes: HKCU - {07436C38-B5AA-4D41-837B-EBA553014277} URL = http://www.firmy.cz/?q={searchTerms}&so ... earch_9973
SearchScopes: HKCU - {16816944-72D4-427B-942F-1A347F3D4E2D} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... earch_9973
SearchScopes: HKCU - {168A8C93-723C-4EFA-9230-6B4CCCA2673D} URL = http://www.mapy.cz/?query={searchTerms} ... earch_9973
SearchScopes: HKCU - {1A35AD7F-7892-4ABA-A3FB-719DE456C3BF} URL = http://slovnik.seznam.cz/?q={searchTerm ... earch_9973
SearchScopes: HKCU - {5DA88986-BC70-4D88-9FC8-134867001EBF} URL = http://encyklopedie.seznam.cz/search?q= ... earch_9973
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... GM_csCZ568
SearchScopes: HKCU - {7BEF446A-7BFD-4872-873F-1866D768221C} URL = http://www.novinky.cz/hledej?w={searchT ... earch_9973
SearchScopes: HKCU - {A567562B-91AA-4F87-B352-BF25B07D822A} URL = http://slovnik.seznam.cz/?q={searchTerm ... earch_9973
SearchScopes: HKCU - {ADFDF72A-C07F-4721-8C34-6E3ED8D76CFD} URL = http://tv.seznam.cz/hledej?w={searchTer ... earch_9973
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.46
FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Honza\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR Extension: (Google Translate) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2014-05-10]
CHR Extension: (Dokumenty Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-07]
CHR Extension: (Disk Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-07-02]
CHR Extension: (YouTube) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-03]
CHR Extension: (Vyhledávání Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-03]
CHR Extension: (AdBlock) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-10]
CHR Extension: (Peněženka Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR Extension: (Gmail) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-07-03]
==================== Services (Whitelisted) =================
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-01] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2014-05-01] ()
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
R3 KbFilter_Kb_FlexDef3x; C:\Windows\System32\DRIVERS\KbFilter_FlexDef3x.sys [22016 2012-10-16] (Siliten)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 vpnva; system32\DRIVERS\vpnva64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-10 13:08 - 2014-05-10 13:08 - 00016951 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-05-10 12:55 - 2014-05-10 12:48 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-10 12:49 - 2014-05-10 12:56 - 00007702 _____ () C:\zoek-results.log
2014-05-10 12:48 - 2014-05-10 12:54 - 00000000 ____D () C:\zoek_backup
2014-05-10 12:48 - 2014-05-10 12:47 - 01285120 _____ () C:\Users\Honza\Desktop\zoek.exe
2014-05-10 11:25 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-10 11:23 - 2014-05-10 11:25 - 00002123 _____ () C:\Users\Honza\Desktop\JRT.txt
2014-05-10 11:19 - 2014-05-10 11:18 - 01316991 _____ () C:\Users\Honza\Desktop\adwcleaner.exe
2014-05-09 12:22 - 2014-05-09 12:22 - 00000000 ____D () C:\Windows\ERUNT
2014-05-09 11:14 - 2014-05-09 11:14 - 00028728 _____ () C:\Users\Honza\Desktop\Addition.txt
2014-05-09 11:13 - 2014-05-10 13:08 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-09 11:13 - 2014-05-09 11:14 - 00038952 _____ () C:\Users\Honza\Desktop\FRST1.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-09 10:39 - 2014-05-10 13:08 - 00000000 ____D () C:\FRST
2014-05-09 10:37 - 2014-05-10 13:08 - 02065408 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-05-08 16:59 - 2014-05-08 16:59 - 00000730 _____ () C:\Users\Public\Desktop\Call of Juarez Gunslinger.lnk
2014-05-08 16:59 - 2014-05-08 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Juarez Gunslinger
2014-05-06 13:09 - 2014-05-06 13:29 - 00000000 ____D () C:\Users\Honza\AppData\Local\The Witcher
2014-05-06 13:09 - 2014-05-06 13:20 - 00000000 ____D () C:\Users\Honza\Documents\The Witcher
2014-05-06 13:08 - 2014-05-06 13:08 - 00000000 ____D () C:\Users\Public\Documents\The Witcher
2014-05-06 11:34 - 2014-05-06 11:34 - 00000210 _____ () C:\Users\Honza\Desktop\The Witcher Enhanced Edition.url
2014-05-02 13:07 - 2014-05-02 13:07 - 00000211 _____ () C:\Users\Honza\Desktop\Torchlight II.url
2014-05-02 12:57 - 2014-05-02 12:57 - 00000209 _____ () C:\Users\Honza\Desktop\Titan Quest Immortal Throne.url
2014-05-02 12:53 - 2014-05-02 12:53 - 00000211 _____ () C:\Users\Honza\Desktop\War Thunder.url
2014-05-02 12:28 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-02 12:28 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-02 12:28 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-02 12:28 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-01 14:19 - 2014-05-01 14:19 - 00000000 ____D () C:\Users\Honza\AppData\Local\CrashRpt
2014-05-01 14:17 - 2014-05-01 14:17 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls
2014-04-24 13:20 - 2014-04-24 13:20 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-04-24 13:20 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-24 13:19 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-24 13:17 - 2014-04-24 13:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-24 13:17 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-24 13:17 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-23 13:34 - 2014-04-23 13:34 - 00000000 ____D () C:\Users\dub_cm_auto
2014-04-19 14:04 - 2014-04-19 14:46 - 00000000 ____D () C:\Users\Honza\Documents\NCSOFT
2014-04-19 12:25 - 2014-04-19 14:46 - 00000000 ____D () C:\Users\Honza\AppData\Local\NCSOFT
2014-04-19 12:25 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\NCSOFT
2014-04-18 11:13 - 2014-04-18 11:13 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 11:13 - 2014-04-18 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
==================== One Month Modified Files and Folders =======
2014-05-10 13:08 - 2014-05-10 13:08 - 00016951 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-05-10 13:08 - 2014-05-09 11:13 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-10 13:08 - 2014-05-09 10:39 - 00000000 ____D () C:\FRST
2014-05-10 13:08 - 2014-05-09 10:37 - 02065408 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-05-10 13:03 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-10 13:03 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-10 13:01 - 2013-07-02 20:44 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Seznam.cz
2014-05-10 13:01 - 2011-04-12 10:34 - 00668866 _____ () C:\Windows\system32\perfh005.dat
2014-05-10 13:01 - 2011-04-12 10:34 - 00141526 _____ () C:\Windows\system32\perfc005.dat
2014-05-10 13:01 - 2009-07-14 07:13 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-10 12:59 - 2013-07-01 13:32 - 01346090 _____ () C:\Windows\WindowsUpdate.log
2014-05-10 12:56 - 2014-05-10 12:49 - 00007702 _____ () C:\zoek-results.log
2014-05-10 12:56 - 2014-02-18 11:00 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf2c87e8c97e2e.job
2014-05-10 12:56 - 2009-07-14 06:51 - 00110611 _____ () C:\Windows\setupact.log
2014-05-10 12:55 - 2013-07-01 14:12 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-10 12:55 - 2010-11-21 05:47 - 01459382 _____ () C:\Windows\PFRO.log
2014-05-10 12:55 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-10 12:54 - 2014-05-10 12:48 - 00000000 ____D () C:\zoek_backup
2014-05-10 12:54 - 2013-07-02 11:53 - 00000000 ____D () C:\Users\Honza
2014-05-10 12:48 - 2014-05-10 12:55 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-10 12:47 - 2014-05-10 12:48 - 01285120 _____ () C:\Users\Honza\Desktop\zoek.exe
2014-05-10 12:46 - 2014-02-18 11:00 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf2c87e8d87286.job
2014-05-10 11:33 - 2013-12-25 10:41 - 00000000 ____D () C:\AdwCleaner
2014-05-10 11:25 - 2014-05-10 11:23 - 00002123 _____ () C:\Users\Honza\Desktop\JRT.txt
2014-05-10 11:18 - 2014-05-10 11:19 - 01316991 _____ () C:\Users\Honza\Desktop\adwcleaner.exe
2014-05-09 12:22 - 2014-05-09 12:22 - 00000000 ____D () C:\Windows\ERUNT
2014-05-09 11:14 - 2014-05-09 11:14 - 00028728 _____ () C:\Users\Honza\Desktop\Addition.txt
2014-05-09 11:14 - 2014-05-09 11:13 - 00038952 _____ () C:\Users\Honza\Desktop\FRST1.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-09 11:12 - 2014-02-18 11:00 - 00003948 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1cf2c87e8d87286
2014-05-09 11:12 - 2014-02-18 11:00 - 00003696 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1cf2c87e8c97e2e
2014-05-09 10:34 - 2013-07-02 20:01 - 00000000 ____D () C:\Programy
2014-05-08 16:59 - 2014-05-08 16:59 - 00000730 _____ () C:\Users\Public\Desktop\Call of Juarez Gunslinger.lnk
2014-05-08 16:59 - 2014-05-08 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Juarez Gunslinger
2014-05-08 16:43 - 2013-07-02 20:00 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\uTorrent
2014-05-08 10:10 - 2013-07-07 08:36 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Skype
2014-05-07 14:25 - 2013-07-02 12:26 - 00000000 ____D () C:\Users\Honza\AppData\Local\Microsoft Games
2014-05-06 13:29 - 2014-05-06 13:09 - 00000000 ____D () C:\Users\Honza\AppData\Local\The Witcher
2014-05-06 13:20 - 2014-05-06 13:09 - 00000000 ____D () C:\Users\Honza\Documents\The Witcher
2014-05-06 13:09 - 2013-07-01 14:37 - 00776356 _____ () C:\Windows\DirectX.log
2014-05-06 13:08 - 2014-05-06 13:08 - 00000000 ____D () C:\Users\Public\Documents\The Witcher
2014-05-06 11:34 - 2014-05-06 11:34 - 00000210 _____ () C:\Users\Honza\Desktop\The Witcher Enhanced Edition.url
2014-05-02 13:07 - 2014-05-02 13:07 - 00000211 _____ () C:\Users\Honza\Desktop\Torchlight II.url
2014-05-02 12:57 - 2014-05-02 12:57 - 00000209 _____ () C:\Users\Honza\Desktop\Titan Quest Immortal Throne.url
2014-05-02 12:53 - 2014-05-02 12:53 - 00000211 _____ () C:\Users\Honza\Desktop\War Thunder.url
2014-05-01 14:19 - 2014-05-01 14:19 - 00000000 ____D () C:\Users\Honza\AppData\Local\CrashRpt
2014-05-01 14:18 - 2013-07-03 21:16 - 00000000 ____D () C:\Users\Honza\Documents\my games
2014-05-01 14:17 - 2014-05-01 14:17 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls
2014-05-01 14:17 - 2013-07-30 18:47 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-05-01 12:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-29 16:01 - 2014-05-02 12:28 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-02 12:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-02 12:28 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-02 12:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-28 14:55 - 2013-12-15 09:58 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Spotify
2014-04-28 11:41 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-04-27 12:38 - 2013-07-01 13:54 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-27 11:46 - 2013-11-15 16:38 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-04-25 11:45 - 2013-12-15 09:58 - 00000000 ____D () C:\Users\Honza\AppData\Local\Spotify
2014-04-24 13:20 - 2014-04-24 13:20 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-04-24 13:20 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-24 13:20 - 2014-04-24 13:19 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-24 13:20 - 2013-07-02 19:51 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-04-24 13:19 - 2013-07-01 13:54 - 00000000 ____D () C:\ProgramData\Norton
2014-04-24 13:17 - 2014-04-24 13:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-23 13:34 - 2014-04-23 13:34 - 00000000 ____D () C:\Users\dub_cm_auto
2014-04-19 14:46 - 2014-04-19 14:04 - 00000000 ____D () C:\Users\Honza\Documents\NCSOFT
2014-04-19 14:46 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Local\NCSOFT
2014-04-19 12:25 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\NCSOFT
2014-04-18 11:13 - 2014-04-18 11:13 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 11:13 - 2014-04-18 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-18 11:13 - 2013-10-18 10:03 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-18 11:13 - 2013-07-04 18:34 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-14 20:13 - 2013-07-04 18:34 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2013-10-18 09:55 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2013-07-04 18:34 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2013-07-04 18:34 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-14 04:24 - 2014-04-24 13:17 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-04-24 13:17 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-01 12:17
==================== End Of Log ============================
Ran by Honza (administrator) on HONZA-PC on 10-05-2014 13:08:46
Running from C:\Users\Honza\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
() C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028896 2013-08-27] (NVIDIA Corporation)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [AutoKMS] => C:\Windows\AutoKMS.exe
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2012-02-01] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-01] (Google Inc.)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [icq] => C:\Users\Honza\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-08] (ICQ)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {ad326ea0-90c4-11e3-87c6-94de8025d71c} - G:\AutoRun.exe /s
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {dfcb13e3-d681-11e3-9848-94de8025d71c} - F:\setup.exe
Startup: C:\Users\Honza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... GM_csCZ568
SearchScopes: HKCU - {07436C38-B5AA-4D41-837B-EBA553014277} URL = http://www.firmy.cz/?q={searchTerms}&so ... earch_9973
SearchScopes: HKCU - {16816944-72D4-427B-942F-1A347F3D4E2D} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... earch_9973
SearchScopes: HKCU - {168A8C93-723C-4EFA-9230-6B4CCCA2673D} URL = http://www.mapy.cz/?query={searchTerms} ... earch_9973
SearchScopes: HKCU - {1A35AD7F-7892-4ABA-A3FB-719DE456C3BF} URL = http://slovnik.seznam.cz/?q={searchTerm ... earch_9973
SearchScopes: HKCU - {5DA88986-BC70-4D88-9FC8-134867001EBF} URL = http://encyklopedie.seznam.cz/search?q= ... earch_9973
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... GM_csCZ568
SearchScopes: HKCU - {7BEF446A-7BFD-4872-873F-1866D768221C} URL = http://www.novinky.cz/hledej?w={searchT ... earch_9973
SearchScopes: HKCU - {A567562B-91AA-4F87-B352-BF25B07D822A} URL = http://slovnik.seznam.cz/?q={searchTerm ... earch_9973
SearchScopes: HKCU - {ADFDF72A-C07F-4721-8C34-6E3ED8D76CFD} URL = http://tv.seznam.cz/hledej?w={searchTer ... earch_9973
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.46
FireFox:
========
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Honza\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR Extension: (Google Translate) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2014-05-10]
CHR Extension: (Dokumenty Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-07-07]
CHR Extension: (Disk Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-07-02]
CHR Extension: (YouTube) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-07-03]
CHR Extension: (Vyhledávání Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-07-03]
CHR Extension: (AdBlock) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-10]
CHR Extension: (Peněženka Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
CHR Extension: (Gmail) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-07-03]
==================== Services (Whitelisted) =================
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-05-01] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2014-05-01] ()
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22680 2012-10-25] ()
R3 KbFilter_Kb_FlexDef3x; C:\Windows\System32\DRIVERS\KbFilter_FlexDef3x.sys [22016 2012-10-16] (Siliten)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [110744 2012-07-19] (Qualcomm Atheros Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-08-20] (NVIDIA Corporation)
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 vpnva; system32\DRIVERS\vpnva64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-10 13:08 - 2014-05-10 13:08 - 00016951 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-05-10 12:55 - 2014-05-10 12:48 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-10 12:49 - 2014-05-10 12:56 - 00007702 _____ () C:\zoek-results.log
2014-05-10 12:48 - 2014-05-10 12:54 - 00000000 ____D () C:\zoek_backup
2014-05-10 12:48 - 2014-05-10 12:47 - 01285120 _____ () C:\Users\Honza\Desktop\zoek.exe
2014-05-10 11:25 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-10 11:23 - 2014-05-10 11:25 - 00002123 _____ () C:\Users\Honza\Desktop\JRT.txt
2014-05-10 11:19 - 2014-05-10 11:18 - 01316991 _____ () C:\Users\Honza\Desktop\adwcleaner.exe
2014-05-09 12:22 - 2014-05-09 12:22 - 00000000 ____D () C:\Windows\ERUNT
2014-05-09 11:14 - 2014-05-09 11:14 - 00028728 _____ () C:\Users\Honza\Desktop\Addition.txt
2014-05-09 11:13 - 2014-05-10 13:08 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-09 11:13 - 2014-05-09 11:14 - 00038952 _____ () C:\Users\Honza\Desktop\FRST1.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-09 10:39 - 2014-05-10 13:08 - 00000000 ____D () C:\FRST
2014-05-09 10:37 - 2014-05-10 13:08 - 02065408 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-05-08 16:59 - 2014-05-08 16:59 - 00000730 _____ () C:\Users\Public\Desktop\Call of Juarez Gunslinger.lnk
2014-05-08 16:59 - 2014-05-08 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Juarez Gunslinger
2014-05-06 13:09 - 2014-05-06 13:29 - 00000000 ____D () C:\Users\Honza\AppData\Local\The Witcher
2014-05-06 13:09 - 2014-05-06 13:20 - 00000000 ____D () C:\Users\Honza\Documents\The Witcher
2014-05-06 13:08 - 2014-05-06 13:08 - 00000000 ____D () C:\Users\Public\Documents\The Witcher
2014-05-06 11:34 - 2014-05-06 11:34 - 00000210 _____ () C:\Users\Honza\Desktop\The Witcher Enhanced Edition.url
2014-05-02 13:07 - 2014-05-02 13:07 - 00000211 _____ () C:\Users\Honza\Desktop\Torchlight II.url
2014-05-02 12:57 - 2014-05-02 12:57 - 00000209 _____ () C:\Users\Honza\Desktop\Titan Quest Immortal Throne.url
2014-05-02 12:53 - 2014-05-02 12:53 - 00000211 _____ () C:\Users\Honza\Desktop\War Thunder.url
2014-05-02 12:28 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-02 12:28 - 2014-04-29 15:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-02 12:28 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-02 12:28 - 2014-04-29 14:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-01 14:19 - 2014-05-01 14:19 - 00000000 ____D () C:\Users\Honza\AppData\Local\CrashRpt
2014-05-01 14:17 - 2014-05-01 14:17 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls
2014-04-24 13:20 - 2014-04-24 13:20 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-04-24 13:20 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-24 13:19 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-24 13:17 - 2014-04-24 13:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-24 13:17 - 2014-04-14 04:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-24 13:17 - 2014-04-14 04:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-04-23 13:34 - 2014-04-23 13:34 - 00000000 ____D () C:\Users\dub_cm_auto
2014-04-19 14:04 - 2014-04-19 14:46 - 00000000 ____D () C:\Users\Honza\Documents\NCSOFT
2014-04-19 12:25 - 2014-04-19 14:46 - 00000000 ____D () C:\Users\Honza\AppData\Local\NCSOFT
2014-04-19 12:25 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\NCSOFT
2014-04-18 11:13 - 2014-04-18 11:13 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 11:13 - 2014-04-18 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
==================== One Month Modified Files and Folders =======
2014-05-10 13:08 - 2014-05-10 13:08 - 00016951 _____ () C:\Users\Honza\Desktop\FRST.txt
2014-05-10 13:08 - 2014-05-09 11:13 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-10 13:08 - 2014-05-09 10:39 - 00000000 ____D () C:\FRST
2014-05-10 13:08 - 2014-05-09 10:37 - 02065408 _____ (Farbar) C:\Users\Honza\Desktop\FRST64.exe
2014-05-10 13:03 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-05-10 13:03 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-05-10 13:01 - 2013-07-02 20:44 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Seznam.cz
2014-05-10 13:01 - 2011-04-12 10:34 - 00668866 _____ () C:\Windows\system32\perfh005.dat
2014-05-10 13:01 - 2011-04-12 10:34 - 00141526 _____ () C:\Windows\system32\perfc005.dat
2014-05-10 13:01 - 2009-07-14 07:13 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-10 12:59 - 2013-07-01 13:32 - 01346090 _____ () C:\Windows\WindowsUpdate.log
2014-05-10 12:56 - 2014-05-10 12:49 - 00007702 _____ () C:\zoek-results.log
2014-05-10 12:56 - 2014-02-18 11:00 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf2c87e8c97e2e.job
2014-05-10 12:56 - 2009-07-14 06:51 - 00110611 _____ () C:\Windows\setupact.log
2014-05-10 12:55 - 2013-07-01 14:12 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-10 12:55 - 2010-11-21 05:47 - 01459382 _____ () C:\Windows\PFRO.log
2014-05-10 12:55 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-10 12:54 - 2014-05-10 12:48 - 00000000 ____D () C:\zoek_backup
2014-05-10 12:54 - 2013-07-02 11:53 - 00000000 ____D () C:\Users\Honza
2014-05-10 12:48 - 2014-05-10 12:55 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-10 12:47 - 2014-05-10 12:48 - 01285120 _____ () C:\Users\Honza\Desktop\zoek.exe
2014-05-10 12:46 - 2014-02-18 11:00 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf2c87e8d87286.job
2014-05-10 11:33 - 2013-12-25 10:41 - 00000000 ____D () C:\AdwCleaner
2014-05-10 11:25 - 2014-05-10 11:23 - 00002123 _____ () C:\Users\Honza\Desktop\JRT.txt
2014-05-10 11:18 - 2014-05-10 11:19 - 01316991 _____ () C:\Users\Honza\Desktop\adwcleaner.exe
2014-05-09 12:22 - 2014-05-09 12:22 - 00000000 ____D () C:\Windows\ERUNT
2014-05-09 11:14 - 2014-05-09 11:14 - 00028728 _____ () C:\Users\Honza\Desktop\Addition.txt
2014-05-09 11:14 - 2014-05-09 11:13 - 00038952 _____ () C:\Users\Honza\Desktop\FRST1.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-09 11:12 - 2014-02-18 11:00 - 00003948 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1cf2c87e8d87286
2014-05-09 11:12 - 2014-02-18 11:00 - 00003696 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1cf2c87e8c97e2e
2014-05-09 10:34 - 2013-07-02 20:01 - 00000000 ____D () C:\Programy
2014-05-08 16:59 - 2014-05-08 16:59 - 00000730 _____ () C:\Users\Public\Desktop\Call of Juarez Gunslinger.lnk
2014-05-08 16:59 - 2014-05-08 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Call of Juarez Gunslinger
2014-05-08 16:43 - 2013-07-02 20:00 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\uTorrent
2014-05-08 10:10 - 2013-07-07 08:36 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Skype
2014-05-07 14:25 - 2013-07-02 12:26 - 00000000 ____D () C:\Users\Honza\AppData\Local\Microsoft Games
2014-05-06 13:29 - 2014-05-06 13:09 - 00000000 ____D () C:\Users\Honza\AppData\Local\The Witcher
2014-05-06 13:20 - 2014-05-06 13:09 - 00000000 ____D () C:\Users\Honza\Documents\The Witcher
2014-05-06 13:09 - 2013-07-01 14:37 - 00776356 _____ () C:\Windows\DirectX.log
2014-05-06 13:08 - 2014-05-06 13:08 - 00000000 ____D () C:\Users\Public\Documents\The Witcher
2014-05-06 11:34 - 2014-05-06 11:34 - 00000210 _____ () C:\Users\Honza\Desktop\The Witcher Enhanced Edition.url
2014-05-02 13:07 - 2014-05-02 13:07 - 00000211 _____ () C:\Users\Honza\Desktop\Torchlight II.url
2014-05-02 12:57 - 2014-05-02 12:57 - 00000209 _____ () C:\Users\Honza\Desktop\Titan Quest Immortal Throne.url
2014-05-02 12:53 - 2014-05-02 12:53 - 00000211 _____ () C:\Users\Honza\Desktop\War Thunder.url
2014-05-01 14:19 - 2014-05-01 14:19 - 00000000 ____D () C:\Users\Honza\AppData\Local\CrashRpt
2014-05-01 14:18 - 2013-07-03 21:16 - 00000000 ____D () C:\Users\Honza\Documents\my games
2014-05-01 14:17 - 2014-05-01 14:17 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-05-01 14:17 - 2014-05-01 14:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Chart Controls
2014-05-01 14:17 - 2013-07-30 18:47 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-05-01 12:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-29 16:01 - 2014-05-02 12:28 - 23547904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-29 15:40 - 2014-05-02 12:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-29 14:48 - 2014-05-02 12:28 - 17384448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-29 14:34 - 2014-05-02 12:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-28 14:55 - 2013-12-15 09:58 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Spotify
2014-04-28 11:41 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-04-27 12:38 - 2013-07-01 13:54 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-27 11:46 - 2013-11-15 16:38 - 00000000 ____D () C:\ProgramData\Ubisoft
2014-04-25 11:45 - 2013-12-15 09:58 - 00000000 ____D () C:\Users\Honza\AppData\Local\Spotify
2014-04-24 13:20 - 2014-04-24 13:20 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-04-24 13:20 - 2014-04-24 13:20 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-24 13:20 - 2014-04-24 13:19 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-24 13:20 - 2013-07-02 19:51 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-04-24 13:19 - 2013-07-01 13:54 - 00000000 ____D () C:\ProgramData\Norton
2014-04-24 13:17 - 2014-04-24 13:17 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-04-23 13:34 - 2014-04-23 13:34 - 00000000 ____D () C:\Users\dub_cm_auto
2014-04-19 14:46 - 2014-04-19 14:04 - 00000000 ____D () C:\Users\Honza\Documents\NCSOFT
2014-04-19 14:46 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Local\NCSOFT
2014-04-19 12:25 - 2014-04-19 12:25 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\NCSOFT
2014-04-18 11:13 - 2014-04-18 11:13 - 00004129 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-18 11:13 - 2014-04-18 11:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-18 11:13 - 2013-10-18 10:03 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-18 11:13 - 2013-07-04 18:34 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-14 20:13 - 2013-07-04 18:34 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2013-10-18 09:55 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2013-07-04 18:34 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2013-07-04 18:34 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-14 04:24 - 2014-04-24 13:17 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-04-14 04:19 - 2014-04-24 13:17 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-01 12:17
==================== End Of Log ============================
Re: Problém s SpeedMyComputer a FixMyRegitry
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [AutoKMS] => C:\Windows\AutoKMS.exe C:\Windows\AutoKMS.exe HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] () HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] () HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] () HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-01] (Google Inc.) HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [icq] => C:\Users\Honza\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-08] (ICQ) HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {ad326ea0-90c4-11e3-87c6-94de8025d71c} - G:\AutoRun.exe /s HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {dfcb13e3-d681-11e3-9848-94de8025d71c} - F:\setup.exe HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} S3 gdrv; \??\C:\Windows\gdrv.sys [X] S3 vpnva; system32\DRIVERS\vpnva64.sys [X] 2014-05-10 12:55 - 2014-05-10 12:48 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-05-10 12:49 - 2014-05-10 12:56 - 00007702 _____ () C:\zoek-results.log 2014-05-10 12:48 - 2014-05-10 12:54 - 00000000 ____D () C:\zoek_backup 2014-05-10 12:48 - 2014-05-10 12:47 - 01285120 _____ () C:\Users\Honza\Desktop\zoek.exe 2014-05-09 11:14 - 2014-05-09 11:14 - 00028728 _____ () C:\Users\Honza\Desktop\Addition.txt 2014-05-09 11:13 - 2014-05-10 13:08 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion 2014-05-09 11:13 - 2014-05-09 11:14 - 00038952 _____ () C:\Users\Honza\Desktop\FRST1.txt 2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat 2014-05-10 11:23 - 2014-05-10 11:25 - 00002123 _____ () C:\Users\Honza\Desktop\JRT.txt 2014-05-10 11:19 - 2014-05-10 11:18 - 01316991 _____ () C:\Users\Honza\Desktop\adwcleaner.exe Host: End- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
-
JohnyPlzenak
- Návštěvník

- Příspěvky: 7
- Registrován: 09 Kvě 2014 10:04
Re: Problém s SpeedMyComputer a FixMyRegitry
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-05-2014
Ran by Honza at 2014-05-11 10:17:19 Run:2
Running from C:\Users\Honza\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [AutoKMS] => C:\Windows\AutoKMS.exe
C:\Windows\AutoKMS.exe
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-01] (Google Inc.)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [icq] => C:\Users\Honza\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-08] (ICQ)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {ad326ea0-90c4-11e3-87c6-94de8025d71c} - G:\AutoRun.exe /s
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {dfcb13e3-d681-11e3-9848-94de8025d71c} - F:\setup.exe
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 vpnva; system32\DRIVERS\vpnva64.sys [X]
2014-05-10 12:55 - 2014-05-10 12:48 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-10 12:49 - 2014-05-10 12:56 - 00007702 _____ () C:\zoek-results.log
2014-05-10 12:48 - 2014-05-10 12:54 - 00000000 ____D () C:\zoek_backup
2014-05-10 12:48 - 2014-05-10 12:47 - 01285120 _____ () C:\Users\Honza\Desktop\zoek.exe
2014-05-09 11:14 - 2014-05-09 11:14 - 00028728 _____ () C:\Users\Honza\Desktop\Addition.txt
2014-05-09 11:13 - 2014-05-10 13:08 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-09 11:13 - 2014-05-09 11:14 - 00038952 _____ () C:\Users\Honza\Desktop\FRST1.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-10 11:23 - 2014-05-10 11:25 - 00002123 _____ () C:\Users\Honza\Desktop\JRT.txt
2014-05-10 11:19 - 2014-05-10 11:18 - 01316991 _____ () C:\Users\Honza\Desktop\adwcleaner.exe
Host:
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BCSSync => Value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AutoKMS => Value not found.
"C:\Windows\AutoKMS.exe" => File/Directory not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Windows\CurrentVersion\Run\\icq => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad326ea0-90c4-11e3-87c6-94de8025d71c} => Key not found.
HKCR\CLSID\{ad326ea0-90c4-11e3-87c6-94de8025d71c} => Key not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{dfcb13e3-d681-11e3-9848-94de8025d71c} => Key not found.
HKCR\CLSID\{dfcb13e3-d681-11e3-9848-94de8025d71c} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => Value not found.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully.
gdrv => Service not found.
vpnva => Service not found.
"C:\Windows\zoek-delete.exe" => File/Directory not found.
"C:\zoek-results.log" => File/Directory not found.
"C:\zoek_backup" => File/Directory not found.
"C:\Users\Honza\Desktop\zoek.exe" => File/Directory not found.
"C:\Users\Honza\Desktop\Addition.txt" => File/Directory not found.
"C:\Users\Honza\Desktop\FRST-OlderVersion" => File/Directory not found.
"C:\Users\Honza\Desktop\FRST1.txt" => File/Directory not found.
"C:\Users\Honza\Desktop\LM.bat" => File/Directory not found.
"C:\Users\Honza\Desktop\JRT.txt" => File/Directory not found.
"C:\Users\Honza\Desktop\adwcleaner.exe" => File/Directory not found.
==== End of Fixlog ====
Ran by Honza at 2014-05-11 10:17:19 Run:2
Running from C:\Users\Honza\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [AutoKMS] => C:\Windows\AutoKMS.exe
C:\Windows\AutoKMS.exe
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Honza\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Honza\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2013-07-01] (Google Inc.)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\Run: [icq] => C:\Users\Honza\AppData\Roaming\ICQM\icq.exe [33664344 2014-01-08] (ICQ)
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {ad326ea0-90c4-11e3-87c6-94de8025d71c} - G:\AutoRun.exe /s
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\...\MountPoints2: {dfcb13e3-d681-11e3-9848-94de8025d71c} - F:\setup.exe
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages =
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 vpnva; system32\DRIVERS\vpnva64.sys [X]
2014-05-10 12:55 - 2014-05-10 12:48 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-10 12:49 - 2014-05-10 12:56 - 00007702 _____ () C:\zoek-results.log
2014-05-10 12:48 - 2014-05-10 12:54 - 00000000 ____D () C:\zoek_backup
2014-05-10 12:48 - 2014-05-10 12:47 - 01285120 _____ () C:\Users\Honza\Desktop\zoek.exe
2014-05-09 11:14 - 2014-05-09 11:14 - 00028728 _____ () C:\Users\Honza\Desktop\Addition.txt
2014-05-09 11:13 - 2014-05-10 13:08 - 00000000 ____D () C:\Users\Honza\Desktop\FRST-OlderVersion
2014-05-09 11:13 - 2014-05-09 11:14 - 00038952 _____ () C:\Users\Honza\Desktop\FRST1.txt
2014-05-09 11:13 - 2014-05-09 11:13 - 00015327 _____ () C:\Users\Honza\Desktop\LM.bat
2014-05-10 11:23 - 2014-05-10 11:25 - 00002123 _____ () C:\Users\Honza\Desktop\JRT.txt
2014-05-10 11:19 - 2014-05-10 11:18 - 01316991 _____ () C:\Users\Honza\Desktop\adwcleaner.exe
Host:
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BCSSync => Value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AutoKMS => Value not found.
"C:\Windows\AutoKMS.exe" => File/Directory not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\Software\Microsoft\Windows\CurrentVersion\Run\\icq => Value not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad326ea0-90c4-11e3-87c6-94de8025d71c} => Key not found.
HKCR\CLSID\{ad326ea0-90c4-11e3-87c6-94de8025d71c} => Key not found.
HKU\S-1-5-21-682846028-3898002777-1719525626-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{dfcb13e3-d681-11e3-9848-94de8025d71c} => Key not found.
HKCR\CLSID\{dfcb13e3-d681-11e3-9848-94de8025d71c} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Main\\Secondary Start Pages => Value not found.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => Value deleted successfully.
gdrv => Service not found.
vpnva => Service not found.
"C:\Windows\zoek-delete.exe" => File/Directory not found.
"C:\zoek-results.log" => File/Directory not found.
"C:\zoek_backup" => File/Directory not found.
"C:\Users\Honza\Desktop\zoek.exe" => File/Directory not found.
"C:\Users\Honza\Desktop\Addition.txt" => File/Directory not found.
"C:\Users\Honza\Desktop\FRST-OlderVersion" => File/Directory not found.
"C:\Users\Honza\Desktop\FRST1.txt" => File/Directory not found.
"C:\Users\Honza\Desktop\LM.bat" => File/Directory not found.
"C:\Users\Honza\Desktop\JRT.txt" => File/Directory not found.
"C:\Users\Honza\Desktop\adwcleaner.exe" => File/Directory not found.
==== End of Fixlog ====
Re: Problém s SpeedMyComputer a FixMyRegitry
Jak se chova PC???
-
JohnyPlzenak
- Návštěvník

- Příspěvky: 7
- Registrován: 09 Kvě 2014 10:04
Re: Problém s SpeedMyComputer a FixMyRegitry
Musím poděkovat. PC se chová standardně. V nainstalovaných programech ani jeden zmíněný "program" není. Ještě jednou děkuji za pomoc
Rozhodně ode mne odejde podpora zdejšímu fóru. Bez Vás bych to nikdy nevyřešil. 
Re: Problém s SpeedMyComputer a FixMyRegitry
Nemate zac, rad jsem pomohl
Zase nekdy 
Za podporu fora jmenem celeho tymu dekuji
A na zaklade Pravidla o zamykani temat

Za podporu fora jmenem celeho tymu dekuji
A na zaklade Pravidla o zamykani temat


Přispějete na provoz fóra?