Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

FRST prosím o kontrolu.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

FRST prosím o kontrolu.

#1 Příspěvek od Cizap »

Hezký den,
jsem tu zase před pár dny jsem zde díky vaší pomoci dal do pořádku svuj PC tímto ještě jednou děkuji všem kdo mi s tím pomohli a mam problém se sestry notebookem. Má práci, ve který volá přes internet připojuje se někam na slovensko, tak že je připojená přes wifi na internet a pak ještě přes nějakou síť CBC VPN (WAN Miniport (PPTP)) a v poslední době asi 2 týdny jí to zlobí. Nejdřív hovor vynechával pak jsem tam nainstaloval avast (starý antivir vypršel) a nějaký antispyware, udělal testy něco to našlo vyčistilo a na pár dní to bylo OK pak se to zase zpomalilo i web jde při připojení na to CBC VPN hodně pomalu dřív to bylo v pořádku, tak už nevim co jinýho s tim dělat. Předem děkuju za pomoc :)

Tady je ten log z FRST a pak také rar Addition v příloze:
Addition.rar
(6.95 KiB) Staženo 53 x

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-05-2014
Ran by Kateřina (administrator) on KATKRI on 14-05-2014 20:28:11
Running from C:\Users\Kateřina\Desktop
Platform: Windows 8 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corp.) C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe
(Threat Expert Ltd.) C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Program Files\mcafee\AppStats\MfeASUM.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(PC Tools) C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe
(PC Tools) C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(TeamViewer GmbH) C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Service_2014-05-14-18-50-47.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Gemfor s.r.o.) C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\ameisvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(PC Tools) C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
() C:\_callcentrum\Zoiper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
(Lavasoft) C:\ProgramData\Search Protection\SearchProtection.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(TeamViewer GmbH) C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer.exe
(TeamViewer GmbH) C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\tv_w32.exe
(TeamViewer GmbH) C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\tv_x64.exe
(TeamViewer GmbH) C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Desktop.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(forum.viry.cz) C:\Users\Kateřina\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2873744 2012-11-20] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AdAwareTray] => C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareTray.exe [4114264 2014-01-23] ()
HKLM-x32\...\Run: [LManager] => [X]
HKLM-x32\...\Run: [RadioController] => C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2013-03-25] (Dritek System Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-10-23] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-04-27] (AVAST Software)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] => C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [559696 2013-09-27] (Lavasoft)
HKLM-x32\...\Run: [Search Protection] => C:\ProgramData\Search Protection\SearchProtection.exe [949512 2014-02-17] (Lavasoft)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ISTray] => C:\Program Files (x86)\PC Tools\PC Tools Security\pctsGui.exe [2717816 2012-11-01] (PC Tools)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\Run: [T-Mobile Communication Centre] => C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\Manager.exe [1363984 2011-06-30] (Gemfor s.r.o.)
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {1e8e8bc4-dca3-11e2-be71-20898468bef8} - "F:\SETUP.EXE"
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {483f461a-e0c0-11e2-be7a-20898468bef8} - "E:\Autorun.exe"
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {483f4647-e0c0-11e2-be7a-20898468bef8} - "E:\Autorun.exe"
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {483f46b6-e0c0-11e2-be7a-20898468bef8} - "E:\Autorun.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk
ShortcutTarget: Acer Backup Manager Tray.lnk -> C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
Startup: C:\Users\Kateřina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2010.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
URLSearchHook: HKCU - PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
SearchScopes: HKLM - DefaultScope {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM - {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - DefaultScope {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKCU - {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL =
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://securedsearch2.lavasoft.com/resu ... earchTerms}
BHO: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx64.dll ()
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PC Tools Browser Guard BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
BHO-x32: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx64.dll ()
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
Toolbar: HKLM-x32 - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{5EBAE234-8DA9-4CF8-BE43-1D89008D74F4}: [NameServer]10.1.1.1
Tcpip\..\Interfaces\{8FBCC850-12A2-427E-80D9-2E1EB6D1EF16}: [NameServer]10.9.2.2 10.9.2.1

FireFox:
========
FF ProfilePath: C:\Users\Kateřina\AppData\Roaming\Mozilla\Firefox\Profiles\7sgeei22.default
FF Homepage: hxxp://acer13.msn.com
FF Keyword.URL: hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_8&idate=__installtime__&hsimp=yhs-lavasoft&ent=bs&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Kateřina\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\adawaretb.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Ad-Aware Security Add-on - C:\Users\Kateřina\AppData\Roaming\Mozilla\Firefox\Profiles\7sgeei22.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2014-04-27]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-05-12]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2012-11-22]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-27]
FF HKLM-x32\...\Firefox\Extensions: [{cb84136f-9c44-433a-9048-c5cd9df1dc16}] - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\Firefox\
FF Extension: Browser Guard Toolbar - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\Firefox\ []

==================== Services (Whitelisted) =================

R2 ameisvc; C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\ameisvc.exe [123120 2011-06-24] (Gemfor s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-27] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109048 2014-04-27] (AVAST Software)
R2 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-21] (Broadcom Corp.)
R2 Browser Defender Update Service; C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe [580728 2012-10-23] (Threat Expert Ltd.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2449552 2012-10-26] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-17] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658064 2012-10-23] (Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2012-11-20] (ELAN Microelectronics Corp.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 LavasoftAdAwareService11; C:\Program Files\Lavasoft\Ad-Aware Antivirus\Ad-Aware Antivirus\11.1.5354.0\AdAwareService.exe [702744 2014-01-23] ()
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [140424 2014-03-24] (McAfee, Inc.)
R2 MfeASUM; C:\Program Files\McAfee\AppStats\MfeASUM.exe [335216 2013-08-07] (McAfee, Inc.)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-11-03] (NTI Corporation)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [96880 2013-03-25] (Dritek System INC.)
R2 sdAuxService; C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe [403416 2012-10-31] (PC Tools)
R2 sdCoreService; C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe [1162360 2012-11-01] (PC Tools)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 TeamViewer7; C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Service.exe [2892160 2012-02-23] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

S2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-04-27] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-04-27] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-27] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [447888 2014-04-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-27] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-27] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-04-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-04-27] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-04-27] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-04-27] ()
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6835784 2013-03-25] (Broadcom Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-06-24] (DT Soft Ltd)
R1 MfeASKM; C:\Program Files\McAfee\AppStats\MfeASKM.sys [31408 2013-08-07] (McAfee, Inc.)
R3 PCTBD; C:\Windows\System32\Drivers\PCTBD64.sys [77144 2012-10-23] (PC Tools)
R0 PCTCore; C:\Windows\System32\drivers\PCTCore64.sys [413448 2012-10-22] (PC Tools)
R0 pctDS; C:\Windows\System32\drivers\pctDS64.sys [453896 2012-02-28] (PC Tools)
R0 pctEFA; C:\Windows\System32\drivers\pctEFA64.sys [1096176 2012-02-28] (PC Tools)
R1 pctgntdi; C:\Windows\System32\Drivers\pctgntdi64.sys [347016 2012-10-31] (PC Tools)
R3 pctplsg; C:\Windows\System32\Drivers\pctplsg64.sys [93600 2012-11-01] (PC Tools)
R3 pctplsm; C:\Windows\System32\Drivers\pctplsm64.sys [87968 2012-11-01] (PC Tools)
R1 PCTSD; C:\Windows\System32\Drivers\PCTSD64.sys [253256 2012-11-01] (PC Tools)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2013-03-25] (Dritek System Inc.)
R3 Trufos; C:\Windows\System32\DRIVERS\Trufos.sys [329800 2013-07-17] (BitDefender S.R.L.)
S3 athr; \SystemRoot\system32\DRIVERS\athrx.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-05-14 20:28 - 2014-05-14 20:28 - 00024376 _____ () C:\Users\Kateřina\Desktop\FRST.txt
2014-05-14 20:27 - 2014-05-14 20:28 - 00000000 ____D () C:\FRST
2014-05-14 20:26 - 2014-05-14 20:26 - 00112640 _____ (forum.viry.cz) C:\Users\Kateřina\Desktop\FRSTLauncher.exe
2014-05-14 20:21 - 2014-05-14 20:21 - 02066944 _____ (Farbar) C:\Users\Kateřina\Desktop\FRST64.exe
2014-05-14 11:08 - 2014-05-14 11:08 - 00010678 _____ () C:\Users\Kateřina\Desktop\1_Call Script FIRST MINUTE OFFER 1.odt
2014-05-12 10:31 - 2014-05-12 10:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-30 13:27 - 2014-04-30 13:28 - 00000790 _____ () C:\Windows\setupact.log
2014-04-30 13:27 - 2014-04-30 13:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-28 08:03 - 2014-04-28 08:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
2014-04-28 08:03 - 2012-11-01 15:35 - 00093600 _____ (PC Tools) C:\Windows\system32\Drivers\pctplsg64.sys
2014-04-28 08:03 - 2012-11-01 15:35 - 00087968 _____ (PC Tools) C:\Windows\system32\Drivers\pctplsm64.sys
2014-04-28 08:03 - 2012-11-01 15:35 - 00016392 _____ (PC Tools) C:\Windows\system32\Drivers\pctBTFix64.sys
2014-04-28 08:03 - 2012-10-31 14:21 - 00347016 _____ (PC Tools) C:\Windows\system32\Drivers\pctgntdi64.sys
2014-04-28 08:03 - 2012-10-31 14:21 - 00258424 _____ (PC Tools) C:\Windows\system32\Drivers\pctwfpfilter64.sys
2014-04-28 08:00 - 2012-10-22 16:38 - 00413448 _____ (PC Tools) C:\Windows\system32\Drivers\PCTCore64.sys
2014-04-28 08:00 - 2012-02-28 11:43 - 01096176 _____ (PC Tools) C:\Windows\system32\Drivers\pctEFA64.sys
2014-04-28 08:00 - 2012-02-28 11:43 - 00453896 _____ (PC Tools) C:\Windows\system32\Drivers\pctDS64.sys
2014-04-27 21:41 - 2014-05-14 20:29 - 00000000 ____D () C:\Users\Kateřina\Desktop\antiviry
2014-04-27 21:18 - 2014-04-27 21:18 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-27 21:18 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-27 21:17 - 2014-04-27 21:17 - 00004764 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-27 21:17 - 2014-04-27 21:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-27 21:17 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-27 21:17 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-27 21:17 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-27 21:04 - 2014-04-27 21:04 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\Lavasoft
2014-04-27 20:29 - 2014-05-14 17:26 - 00015678 _____ () C:\Windows\PFRO.log
2014-04-27 19:57 - 2014-04-27 19:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
2014-04-27 19:56 - 2014-04-27 19:56 - 00000000 ____D () C:\Program Files\Lavasoft
2014-04-27 19:55 - 2014-05-14 17:31 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection
2014-04-27 19:55 - 2014-04-27 21:06 - 00000000 ____D () C:\Users\Kateřina\AppData\Local\adawarebp
2014-04-27 19:55 - 2014-04-27 19:55 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\SecureSearch
2014-04-27 19:55 - 2014-04-27 19:55 - 00000000 ____D () C:\ProgramData\Search Protection
2014-04-27 19:55 - 2014-04-27 19:55 - 00000000 ____D () C:\Program Files (x86)\Toolbar Cleaner
2014-04-27 19:55 - 2014-04-27 19:55 - 00000000 ____D () C:\Program Files (x86)\Lavasoft
2014-04-27 19:47 - 2014-04-27 19:47 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-04-27 19:46 - 2014-04-27 19:52 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-04-27 19:46 - 2014-04-27 19:47 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-04-27 19:46 - 2014-04-27 19:46 - 00001399 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-04-27 19:46 - 2014-04-27 19:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-04-27 19:46 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean64.exe
2014-04-27 19:45 - 2014-04-28 14:07 - 00138758 _____ () C:\Windows\WindowsUpdate.log
2014-04-27 19:41 - 2014-04-27 19:42 - 00097844 _____ () C:\Users\Kateřina\Documents\záloha registrů ccleaner.reg
2014-04-27 19:31 - 2014-04-27 19:31 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\LavasoftStatistics
2014-04-27 19:27 - 2014-04-27 19:27 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-04-27 19:27 - 2014-04-27 19:27 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-27 19:06 - 2014-04-27 19:06 - 01727624 _____ () C:\Users\Kateřina\Downloads\Adaware_Installer.exe
2014-04-27 19:06 - 2014-04-27 19:06 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-04-27 19:06 - 2014-04-27 19:06 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-04-27 18:22 - 2014-04-27 18:22 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\AVAST Software
2014-04-27 18:21 - 2012-10-23 17:40 - 02280568 _____ (Threat Expert Ltd.) C:\Windows\PCTBDCore.dll0405.old
2014-04-27 18:21 - 2012-10-23 17:40 - 02280568 _____ (Threat Expert Ltd.) C:\Windows\PCTBDCore.dll
2014-04-27 18:21 - 2012-10-23 17:40 - 01690744 _____ (Threat Expert Ltd.) C:\Windows\PCTBDRes.dll
2014-04-27 18:21 - 2012-10-23 17:40 - 00769144 _____ () C:\Windows\BDTSupport.dll0405.old
2014-04-27 18:21 - 2012-10-23 17:40 - 00769144 _____ () C:\Windows\BDTSupport.dll
2014-04-27 18:21 - 2012-10-23 17:40 - 00150648 _____ (PC Tools) C:\Windows\SGDetectionTool.dll0405.old
2014-04-27 18:21 - 2012-10-23 17:40 - 00150648 _____ (PC Tools) C:\Windows\SGDetectionTool.dll
2014-04-27 18:21 - 2012-10-23 17:40 - 00077144 _____ (PC Tools) C:\Windows\system32\Drivers\PCTBD64.sys
2014-04-27 18:21 - 2012-10-23 16:30 - 00003488 _____ () C:\Windows\UDB.zip
2014-04-27 18:21 - 2012-10-23 16:30 - 00000882 _____ () C:\Windows\RegSDImport.xml
2014-04-27 18:21 - 2012-10-23 16:30 - 00000879 _____ () C:\Windows\RegISSImport.xml
2014-04-27 18:21 - 2012-10-23 16:30 - 00000131 _____ () C:\Windows\IDB.zip
2014-04-27 18:19 - 2014-04-28 08:02 - 00000000 ____D () C:\Program Files (x86)\PC Tools
2014-04-27 18:17 - 2014-04-27 18:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-04-27 18:16 - 2014-05-14 17:29 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-04-27 18:15 - 2014-04-28 08:00 - 03522941 _____ () C:\Windows\system32\Drivers\Cat.DB
2014-04-27 18:15 - 2014-04-27 18:15 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-27 18:15 - 2014-04-27 18:15 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-27 18:15 - 2014-04-27 18:15 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-27 18:15 - 2014-04-27 18:14 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-04-27 18:15 - 2012-11-01 15:35 - 00253256 _____ (PC Tools) C:\Windows\system32\Drivers\PCTSD64.sys
2014-04-27 18:14 - 2014-04-27 18:14 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-04-27 18:13 - 2014-04-28 08:03 - 00000000 ____D () C:\ProgramData\PC Tools
2014-04-27 18:13 - 2014-04-27 18:13 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\TestApp
2014-04-27 18:12 - 2014-04-27 18:12 - 04165592 _____ (PC Tools) C:\Users\Kateřina\Downloads\sdsetup.exe
2014-04-27 18:12 - 2014-04-27 18:12 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-27 18:09 - 2014-04-27 18:09 - 04768536 _____ (AVAST Software) C:\Users\Kateřina\Downloads\avast_premier_antivirus_setup_online.exe
2014-04-27 18:09 - 2014-04-27 18:09 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-24 16:46 - 2014-04-24 16:46 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-24 16:46 - 2014-04-24 16:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-24 16:45 - 2014-04-24 16:46 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-24 16:45 - 2014-04-24 16:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-24 16:45 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-24 16:45 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-24 16:45 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-24 16:44 - 2014-04-24 16:44 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Kateřina\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-24 16:39 - 2014-04-24 16:43 - 00000000 ____D () C:\Programy
2014-04-24 16:37 - 2014-04-24 16:37 - 28001672 _____ (Wireshark development team) C:\Users\Kateřina\Downloads\Wireshark-win64-1.10.7.exe
2014-04-22 13:26 - 2014-04-22 13:36 - 00060459 _____ () C:\Users\Kateřina\Downloads\Koleje osudu (2013) titulky.srt
2014-04-22 13:26 - 2014-04-22 13:26 - 00060459 _____ () C:\Users\Kateřina\Downloads\sk.srt
2014-04-22 13:19 - 2014-04-22 13:24 - 731945434 _____ () C:\Users\Kateřina\Downloads\Koleje osudu (2013) titulky.avi
2014-04-17 15:19 - 2014-04-18 08:49 - 00000000 ____D () C:\Users\Kateřina\Desktop\MUŽI NA STROMECH 2 SÉRIE
2014-04-17 14:59 - 2014-04-17 15:17 - 00000000 ____D () C:\Users\Kateřina\Desktop\MUŽI NA STROMECH 1 SÉRIE
2014-04-15 10:01 - 2014-04-15 11:42 - 00000000 ____D () C:\Users\Kateřina\Desktop\NOVÉ CALL SCRIPTY
2014-04-15 08:06 - 2014-05-07 16:42 - 00035840 _____ () C:\Users\Kateřina\Desktop\Kopie - registrace duben.xls

==================== One Month Modified Files and Folders =======

2014-05-14 20:29 - 2014-04-27 21:41 - 00000000 ____D () C:\Users\Kateřina\Desktop\antiviry
2014-05-14 20:28 - 2014-05-14 20:28 - 00024376 _____ () C:\Users\Kateřina\Desktop\FRST.txt
2014-05-14 20:28 - 2014-05-14 20:27 - 00000000 ____D () C:\FRST
2014-05-14 20:28 - 2013-06-25 11:42 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\Skype
2014-05-14 20:26 - 2014-05-14 20:26 - 00112640 _____ (forum.viry.cz) C:\Users\Kateřina\Desktop\FRSTLauncher.exe
2014-05-14 20:21 - 2014-05-14 20:21 - 02066944 _____ (Farbar) C:\Users\Kateřina\Desktop\FRST64.exe
2014-05-14 20:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-05-14 19:42 - 2013-09-02 17:05 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-14 19:08 - 2013-06-23 21:49 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2280900641-3005277421-3576168842-1001
2014-05-14 19:03 - 2013-06-24 12:51 - 00000000 ____D () C:\Users\Kateřina\AppData\Local\Deployment
2014-05-14 18:57 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\tracing
2014-05-14 17:34 - 2013-07-01 13:22 - 00000000 ____D () C:\Users\Kateřina\AppData\Local\CrashDumps
2014-05-14 17:31 - 2014-04-27 19:55 - 00000000 ____D () C:\ProgramData\Ad-Aware Browsing Protection
2014-05-14 17:29 - 2014-04-27 18:16 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-05-14 17:26 - 2014-04-27 20:29 - 00015678 _____ () C:\Windows\PFRO.log
2014-05-14 17:26 - 2013-08-16 10:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-14 17:26 - 2013-07-01 13:19 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-05-14 17:26 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-14 11:43 - 2013-09-02 17:05 - 00003802 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-14 11:08 - 2014-05-14 11:08 - 00010678 _____ () C:\Users\Kateřina\Desktop\1_Call Script FIRST MINUTE OFFER 1.odt
2014-05-14 10:58 - 2014-03-17 21:42 - 00000000 ____D () C:\Users\Kateřina\Desktop\ANDREJ CHODÍ
2014-05-13 11:54 - 2013-06-23 22:55 - 00000000 ___RD () C:\Users\Kateřina\Desktop\Práce
2014-05-12 10:32 - 2014-05-12 10:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-09 15:08 - 2013-07-02 09:24 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\vlc
2014-05-09 14:12 - 2013-06-24 16:32 - 00000000 ___RD () C:\Users\Kateřina\Desktop\freerapid
2014-05-08 16:32 - 2013-03-25 06:13 - 00727488 _____ () C:\Windows\system32\perfh005.dat
2014-05-08 16:32 - 2013-03-25 06:13 - 00148006 _____ () C:\Windows\system32\perfc005.dat
2014-05-08 16:32 - 2012-07-26 09:28 - 01714430 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-08 09:12 - 2014-01-24 21:34 - 00005305 _____ () C:\Users\Kateřina\AppData\Roaming\froggy_scorebox
2014-05-08 09:12 - 2014-01-24 21:34 - 00001601 _____ () C:\Users\Kateřina\AppData\Roaming\pl_accounts.pl_acc
2014-05-08 09:12 - 2014-01-24 21:34 - 00000556 _____ () C:\Users\Kateřina\AppData\Roaming\Troll.options
2014-05-07 16:42 - 2014-04-15 08:06 - 00035840 _____ () C:\Users\Kateřina\Desktop\Kopie - registrace duben.xls
2014-05-07 10:05 - 2013-07-30 19:41 - 01513472 ___SH () C:\Users\Kateřina\Desktop\Thumbs.db
2014-04-30 13:28 - 2014-04-30 13:27 - 00000790 _____ () C:\Windows\setupact.log
2014-04-30 13:27 - 2014-04-30 13:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-29 14:50 - 2013-06-23 21:37 - 00000000 ____D () C:\Users\Kateřina
2014-04-28 14:07 - 2014-04-27 19:45 - 00138758 _____ () C:\Windows\WindowsUpdate.log
2014-04-28 08:03 - 2014-04-28 08:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
2014-04-28 08:03 - 2014-04-27 18:13 - 00000000 ____D () C:\ProgramData\PC Tools
2014-04-28 08:02 - 2014-04-27 18:19 - 00000000 ____D () C:\Program Files (x86)\PC Tools
2014-04-28 08:00 - 2014-04-27 18:15 - 03522941 _____ () C:\Windows\system32\Drivers\Cat.DB
2014-04-27 21:18 - 2014-04-27 21:18 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-27 21:17 - 2014-04-27 21:17 - 00004764 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
2014-04-27 21:17 - 2014-04-27 21:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-04-27 21:17 - 2013-06-24 16:34 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-27 21:12 - 2012-11-22 14:02 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-27 21:06 - 2014-04-27 19:55 - 00000000 ____D () C:\Users\Kateřina\AppData\Local\adawarebp
2014-04-27 21:04 - 2014-04-27 21:04 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\Lavasoft
2014-04-27 20:30 - 2012-11-22 14:00 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-04-27 20:30 - 2012-11-22 13:59 - 00000000 ____D () C:\ProgramData\McAfee
2014-04-27 20:29 - 2013-03-25 07:00 - 00000000 ____D () C:\ProgramData\Norton
2014-04-27 20:29 - 2012-11-22 14:00 - 00000000 ____D () C:\Program Files\mcafee
2014-04-27 20:29 - 2012-11-22 14:00 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-04-27 20:28 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-04-27 19:57 - 2014-04-27 19:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
2014-04-27 19:56 - 2014-04-27 19:56 - 00000000 ____D () C:\Program Files\Lavasoft
2014-04-27 19:55 - 2014-04-27 19:55 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\SecureSearch
2014-04-27 19:55 - 2014-04-27 19:55 - 00000000 ____D () C:\ProgramData\Search Protection
2014-04-27 19:55 - 2014-04-27 19:55 - 00000000 ____D () C:\Program Files (x86)\Toolbar Cleaner
2014-04-27 19:55 - 2014-04-27 19:55 - 00000000 ____D () C:\Program Files (x86)\Lavasoft
2014-04-27 19:52 - 2014-04-27 19:46 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-04-27 19:47 - 2014-04-27 19:47 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-04-27 19:47 - 2014-04-27 19:46 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-04-27 19:47 - 2013-07-04 15:44 - 00101376 ___SH () C:\Users\Kateřina\Downloads\Thumbs.db
2014-04-27 19:46 - 2014-04-27 19:46 - 00001399 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2014-04-27 19:46 - 2014-04-27 19:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2014-04-27 19:42 - 2014-04-27 19:41 - 00097844 _____ () C:\Users\Kateřina\Documents\záloha registrů ccleaner.reg
2014-04-27 19:38 - 2013-06-24 17:27 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\DAEMON Tools Lite
2014-04-27 19:37 - 2014-01-10 09:51 - 00000000 ____D () C:\Windows\Minidump
2014-04-27 19:37 - 2012-11-22 13:28 - 00000000 ____D () C:\Windows\Panther
2014-04-27 19:31 - 2014-04-27 19:31 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\LavasoftStatistics
2014-04-27 19:27 - 2014-04-27 19:27 - 00002778 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-04-27 19:27 - 2014-04-27 19:27 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-27 19:06 - 2014-04-27 19:06 - 01727624 _____ () C:\Users\Kateřina\Downloads\Adaware_Installer.exe
2014-04-27 19:06 - 2014-04-27 19:06 - 00000000 ____D () C:\ProgramData\Lavasoft
2014-04-27 19:06 - 2014-04-27 19:06 - 00000000 ____D () C:\Program Files\Common Files\Lavasoft
2014-04-27 18:22 - 2014-04-27 18:22 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\AVAST Software
2014-04-27 18:17 - 2014-04-27 18:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-04-27 18:15 - 2014-04-27 18:15 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-04-27 18:15 - 2014-04-27 18:15 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-04-27 18:15 - 2014-04-27 18:15 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-04-27 18:15 - 2014-04-27 18:15 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-04-27 18:14 - 2014-04-27 18:15 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-04-27 18:14 - 2014-04-27 18:14 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-04-27 18:13 - 2014-04-27 18:13 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\TestApp
2014-04-27 18:12 - 2014-04-27 18:12 - 04165592 _____ (PC Tools) C:\Users\Kateřina\Downloads\sdsetup.exe
2014-04-27 18:12 - 2014-04-27 18:12 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-27 18:12 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-04-27 18:10 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-04-27 18:09 - 2014-04-27 18:09 - 04768536 _____ (AVAST Software) C:\Users\Kateřina\Downloads\avast_premier_antivirus_setup_online.exe
2014-04-27 18:09 - 2014-04-27 18:09 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-24 18:32 - 2013-06-23 22:28 - 00000000 ____D () C:\Users\Kateřina\AppData\Roaming\TeamViewer
2014-04-24 16:46 - 2014-04-24 16:46 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-24 16:46 - 2014-04-24 16:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-24 16:46 - 2014-04-24 16:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-24 16:45 - 2014-04-24 16:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-24 16:44 - 2014-04-24 16:44 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Kateřina\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-24 16:43 - 2014-04-24 16:39 - 00000000 ____D () C:\Programy
2014-04-24 16:37 - 2014-04-24 16:37 - 28001672 _____ (Wireshark development team) C:\Users\Kateřina\Downloads\Wireshark-win64-1.10.7.exe
2014-04-22 13:36 - 2014-04-22 13:26 - 00060459 _____ () C:\Users\Kateřina\Downloads\Koleje osudu (2013) titulky.srt
2014-04-22 13:26 - 2014-04-22 13:26 - 00060459 _____ () C:\Users\Kateřina\Downloads\sk.srt
2014-04-22 13:24 - 2014-04-22 13:19 - 731945434 _____ () C:\Users\Kateřina\Downloads\Koleje osudu (2013) titulky.avi
2014-04-18 13:51 - 2013-06-25 11:42 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-04-18 08:49 - 2014-04-17 15:19 - 00000000 ____D () C:\Users\Kateřina\Desktop\MUŽI NA STROMECH 2 SÉRIE
2014-04-17 15:17 - 2014-04-17 14:59 - 00000000 ____D () C:\Users\Kateřina\Desktop\MUŽI NA STROMECH 1 SÉRIE
2014-04-15 11:42 - 2014-04-15 10:01 - 00000000 ____D () C:\Users\Kateřina\Desktop\NOVÉ CALL SCRIPTY
2014-04-15 08:25 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-04-15 08:01 - 2013-06-23 21:42 - 00000000 ___RD () C:\Users\Kateřina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-15 08:01 - 2013-06-23 21:42 - 00000000 ___RD () C:\Users\Kateřina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-15 07:56 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-04-15 07:56 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-04-14 20:13 - 2014-04-27 21:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2014-04-27 21:18 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-14 20:05 - 2014-04-27 21:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-14 20:04 - 2014-04-27 21:17 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-14 17:16 - 2014-03-28 21:45 - 00101376 _____ () C:\Users\Kateřina\Desktop\nove rogostrace operatorky.xls
2014-04-14 10:26 - 2014-02-12 18:22 - 00024976 ____H () C:\Users\Kateřina\Desktop\~WRL4087.tmp

Some content of TEMP:
====================
C:\Users\Kateřina\AppData\Local\Temp\08d37da1-30d7-4e1a-ae7d-ffc113b91c87.exe
C:\Users\Kateřina\AppData\Local\Temp\6b031ded-ab62-418e-afde-824d53db9038.exe
C:\Users\Kateřina\AppData\Local\Temp\885aae3d-e4d4-479f-a20b-28694c9f15e4.exe
C:\Users\Kateřina\AppData\Local\Temp\GC_PCTOOLS.exe
C:\Users\Kateřina\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: PC Tools Spyware Doctor with AntiVirus (Disabled - Up to date) {2F668A56-D5E0-2DF1-A0AE-CB1284F42AB2}
AV: Ad-Aware Antivirus (Disabled - Out of date) {D87B6541-12A1-DAEA-0033-9B8057AAB996}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Ad-Aware Antivirus (Disabled - Out of date) {631A84A5-349B-D564-3A83-A0F22C2DF32B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: PC Tools Spyware Doctor (Disabled - Up to date) {94076BB2-F3DA-227F-9A1E-F060FF73600F}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: Ad-Aware Firewall (Disabled) {E040E464-58CE-DBB2-2B6C-32B5A979FEED}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Kate�ina\Desktop" je 52060 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"="C:\\Program Files (x86)\\Spybot - Search & Destroy 2\\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119537
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST prosím o kontrolu.

#2 Příspěvek od Rudy »

Zdravím!
Zkusíme to vyčistit. Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [Search Protection] => C:\ProgramData\Search Protection\SearchProtection.exe [949512 2014-02-17] (Lavasoft)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {1e8e8bc4-dca3-11e2-be71-20898468bef8} - "F:\SETUP.EXE"
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {483f461a-e0c0-11e2-be7a-20898468bef8} - "E:\Autorun.exe"
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {483f4647-e0c0-11e2-be7a-20898468bef8} - "E:\Autorun.exe"
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {483f46b6-e0c0-11e2-be7a-20898468bef8} - "E:\Autorun.exe"
SearchScopes: HKLM - DefaultScope {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM - {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - DefaultScope {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKCU - {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL =
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://securedsearch2.lavasoft.com/resu ... &ent=ch&q={searchTerms}
BHO: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx64.dll ()
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
C:\Program Files (x86)\Skype\Toolbars
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
C:\Users\Kateřina\AppData\Local\Temp
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Ještě bych odinstaloval AdAware a PCTools security. Mohou být v konfliktu s antispywarem Avastu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST prosím o kontrolu.

#3 Příspěvek od Cizap »

Tak Ad-aware mi na konci odinstalace hodilo nějakou uninstall error a řeklo mi to ať to zkusim odinstalovat později a pak už to šlo v pořádku, tak snad dobrý. PC tools jsem také odinstaloval, jen se chci zeptat jestli Avast má antispyware i při free verzi je tam teď trial na 30 dní (13 zbývá), tak jestli pak budu muset nějakej antispyware doinstalovat až to vyprší nebo ne :?:

a tady je ten log z fixu:



Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-05-2014
Ran by Kateřina at 2014-05-15 07:32:33 Run:1
Running from C:\Users\Kateřina\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [] => [X]
HKLM-x32\...\Run: [Search Protection] => C:\ProgramData\Search Protection\SearchProtection.exe [949512 2014-02-17] (Lavasoft)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {1e8e8bc4-dca3-11e2-be71-20898468bef8} - "F:\SETUP.EXE"
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {483f461a-e0c0-11e2-be7a-20898468bef8} - "E:\Autorun.exe"
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {483f4647-e0c0-11e2-be7a-20898468bef8} - "E:\Autorun.exe"
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\...\MountPoints2: {483f46b6-e0c0-11e2-be7a-20898468bef8} - "E:\Autorun.exe"
SearchScopes: HKLM - DefaultScope {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM - {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - DefaultScope {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKCU - {0FEAAC8E-DA88-4997-9224-D4C60E938CD2} URL =
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://securedsearch2.lavasoft.com/resu ... &ent=ch&q={searchTerms}
BHO: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx64.dll ()
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
C:\Program Files (x86)\Skype\Toolbars
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
C:\Users\Kateřina\AppData\Local\Temp
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Search Protection => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1e8e8bc4-dca3-11e2-be71-20898468bef8} => Key deleted successfully.
HKCR\CLSID\{1e8e8bc4-dca3-11e2-be71-20898468bef8} => Key not found.
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{483f461a-e0c0-11e2-be7a-20898468bef8} => Key deleted successfully.
HKCR\CLSID\{483f461a-e0c0-11e2-be7a-20898468bef8} => Key not found.
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{483f4647-e0c0-11e2-be7a-20898468bef8} => Key deleted successfully.
HKCR\CLSID\{483f4647-e0c0-11e2-be7a-20898468bef8} => Key not found.
HKU\S-1-5-21-2280900641-3005277421-3576168842-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{483f46b6-e0c0-11e2-be7a-20898468bef8} => Key deleted successfully.
HKCR\CLSID\{483f46b6-e0c0-11e2-be7a-20898468bef8} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0FEAAC8E-DA88-4997-9224-D4C60E938CD2} => Key deleted successfully.
HKCR\CLSID\{0FEAAC8E-DA88-4997-9224-D4C60E938CD2} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0FEAAC8E-DA88-4997-9224-D4C60E938CD2} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{0FEAAC8E-DA88-4997-9224-D4C60E938CD2} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0FEAAC8E-DA88-4997-9224-D4C60E938CD2} => Key deleted successfully.
HKCR\CLSID\{0FEAAC8E-DA88-4997-9224-D4C60E938CD2} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => Key deleted successfully.
HKCR\CLSID\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c} => Key deleted successfully.
HKCR\CLSID\{6c97a91e-4524-4019-86af-2aa2d567bf5c} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} => Key deleted successfully.
HKCR\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} => Key deleted successfully.

"C:\Program Files (x86)\Skype\Toolbars" directory move:

C:\Program Files (x86)\Skype\Toolbars\Shared x64\SkypeBrowserOptions.dll => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Shared x64\SkypePnr.dll => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Shared\root.pem => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Shared\SkypeBrowserOptions.dll => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Shared\SkypePnr.dll => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\icon.ico => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\icon.ico => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\FirefoxAddOn\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi => Moved successfully.
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe => Moved successfully.
Could not move "C:\Program Files (x86)\Skype\Toolbars" directory. => Scheduled to move on reboot.

HKCR\PROTOCOLS\Handler\skype-ie-addon-data => Key deleted successfully.
HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => Key deleted successfully.
c2cautoupdatesvc => Unable to stop service
c2cautoupdatesvc => Service deleted successfully.
c2cpnrsvc => Unable to stop service
c2cpnrsvc => Service deleted successfully.

"C:\Users\Kateřina\AppData\Local\Temp" directory move:

C:\Users\Kateřina\AppData\Local\Temp\08d37da1-30d7-4e1a-ae7d-ffc113b91c87.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\0SLpGFkg.htm.part => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\6b031ded-ab62-418e-afde-824d53db9038.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\885aae3d-e4d4-479f-a20b-28694c9f15e4.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\adaware-manifest.xml => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\adaware-toolbar.xml => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\adawaretb_Install_Log.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\au-descriptor-1.7.0_55-b14.xml => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\AUCHECK_PARSER.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR1046.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR143C.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR204F.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR3B84.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR3D97.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR505A.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR5730.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR713A.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR71C4.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR732A.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR8144.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR83AB.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR8947.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR8FEB.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR92D7.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR98B2.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVR98ED.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRA1C0.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRA7A9.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRA935.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRC5D4.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRC918.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRD357.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRD3C.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRDC63.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRDF51.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRE29.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRF841.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRFA66.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRFB1E.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\CVRFD17.tmp.cvr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\dd_vcredistMSI46DD.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\dd_vcredistMSI50D6.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\dd_vcredistUI46DD.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\dd_vcredistUI46DE.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\dd_vcredistUI50D6.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\dd_vcredistUI50D7.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_0VAC5830vtdX2D8 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_1lkwyK7RjyIMtVm => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_1SVP3AeazNx9KV6 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_28APuKxuPbp2Cfy => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_4fIT5Re3v00oyud => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_4l9xDpv50dKWUWU => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_5SaFwbbjvbDFc4B => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_6hcFmn9phex0B3m => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_8utgi669fqoyHqg => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_ALgPhb6IbCyV110 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_ayB5vCQYpUKkd3y => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_BcPsCzxFYx1iOJH => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_bP0zJxKiDSi6dwa => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_bv4GZ2mdTG8DxVV => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_Ca8A3CrhTr17LL5 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_DfPuHfRIGZlQ7V8 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_DNwGj4VVdLnZ8j9 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_f4QQy1UXy1OEUA1 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_fBuubxxdOyW0m5u => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_FCCZ3RaWGmh4cu4 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_FfH2UrChMyxFhdL => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_gojztybqGZJSEGp => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_gRpdMw2MbCTEJw6 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_HbwkegabhzzM3Zb => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_hxeiGnoInQvech9 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_IFEKkeRVEtHSb6L => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_it8lbL6xp3scauI => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_Ite3MYyFHvH0Qpx => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_J80sd2jQNJIgeiu => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_k8IhjVw1mNq5h5u => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_kszIKfydc8trcO0 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_lVPJG2MGtsWSJym => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_LyJox2aXMF4KNod => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_m7wK8Sjn0ePbhxs => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_nld7JAlibeh0xu8 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_NoJOqOrC861qxPn => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_NT0IV3JMPAfYezF => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_NwOVP0czv49tjbY => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_OeyHV5NiC3QrVye => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_OM8nIFsdXtDDNg6 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_OmOhMomFjHtafmF => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_OPSOURfR3ykwU8d => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_PCOnbXVzIm5zulH => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_RvaIxIgrEoyT0Tr => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_SI4OqJw6n9BvcCd => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_Tvr4DNPvEtdgPel => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_UQnxo5Ws6KogEVp => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_uyUbVxcLeMjx9CM => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_V0uUBQlYghp6YVh => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_xovGMWtOysupvje => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_yQv6H2nqYlarLjJ => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_ywzq6LeqLbfm9pc => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_ZqXAbtLj6UVsxb6 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\etilqs_zrpPEJ36fDhA4FP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\faktura 0382014-1.pdf => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\faktura 0382014.pdf => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\GC_PCTOOLS.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\GenericTdiDll.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\JAUReg.log => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\JavaDeployReg.log => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\java_install_reg.log => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\java_install_sp.log => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\jinstall.cfg => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\jusched.log => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Manuál k dohledání kontaktu v Dialcomu.doc => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Mazal Miroslav DiS. Ukázka postupu výroby pažby.pdf => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\MMDUtl.ini => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\modules00 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\modules11 => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PCTSBL_sdsetup.exe_DebugLog_2014-04-27_0.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PCTSBL_sdsetup.exe_DebugLog_2014-04-28_0.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\přihlášení v Dialcomu.doc => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\RDDC8F.tmp => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\RDF8B6.tmp => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-27 #001.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-27 #002.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-27 #003.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-27 #004.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-27 #005.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-27 #006.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-27 #007.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-27 #008.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-28 #001.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-28 #002.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-28 #003.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-28 #004.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-28 #005.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-28 #006.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-28 #007.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Setup Log 2014-04-28 #008.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\SetupProtect20140427181327842_b7bf12e.log => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\SetupProtect20140428075837384_27742c8.log => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Uninstall Log 2014-04-27 #001.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Uninstall Log 2014-04-27 #002.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Uninstall Log 2014-04-27 #003.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Uninstall Log 2014-04-27 #004.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Uninstall Log 2014-04-28 #001.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\VYKAZ ODPRACOVANYCH HODIN.doc => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\VZP_prispevek_cerpani-1.docx => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\VZP_prispevek_cerpani-1.pdf => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\VZP_prispevek_cerpani.docx => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\VZP_prispevek_cerpani.pdf => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\winstore.log => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\_iu14D2N.tmp => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~$ihlášení v Dialcomu.doc => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~2543.bat => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~2543.tmp => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DF3E04381A4E8B61DA.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DF4123FB27DF8F3BE3.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DF79061AD72E42A823.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DF815CEBFE0288ABD1.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DF81C3DD6E1E639028.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DFC5AEA164ADBA00E6.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DFCD8875D30836A3E4.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DFE3C2F29B63472129.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DFF65F6875BDB7AC93.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\~DFFF2982E565A91A01.TMP => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\{6c97a91e-4524-4019-86af-2aa2d567bf5c}\geodata.xml => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\Connections_incoming.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer7_Exit.hta => Moved successfully.
Could not move "C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer7_Logfile.log" => Scheduled to move on reboot.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Desktop.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Resource_cs.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Service.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Service_2014-04-27-21-03-57.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Service_2014-04-29-19-53-44.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Service_2014-05-13-10-36-35.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_Service_2014-05-14-18-50-47.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_StaticRes.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\tvinfo.ini => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\tv_w32.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\tv_w32.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\tv_x64.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\tv_x64.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\x86\tvmonitor.cat => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\x86\TVMonitor.inf => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\x86\TVMonitor.sys => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\x64\tvmonitor.cat => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\x64\TVMonitor.inf => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\x64\TVMonitor.sys => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TCDC3FF.tmp\CleanGradient.thmx => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TCD38DE.tmp\CleanGradient.thmx => Moved successfully.
Could not move "C:\Users\Kateřina\AppData\Local\Temp\Skype\DbTemp\temp-8HlSzJA1Q8Q5cftUy3hEVJca" => Scheduled to move on reboot.
Could not move "C:\Users\Kateřina\AppData\Local\Temp\Skype\DbTemp\temp-aS346gpSKz5yFD2LxY8SRH1M" => Scheduled to move on reboot.
Could not move "C:\Users\Kateřina\AppData\Local\Temp\Skype\DbTemp\temp-eczGBaTDkTskMXZkXJOlXasL" => Scheduled to move on reboot.
Could not move "C:\Users\Kateřina\AppData\Local\Temp\Skype\DbTemp\temp-eNNZdH2bjjnWQZAKztVDVyL2" => Scheduled to move on reboot.
C:\Users\Kateřina\AppData\Local\Temp\PCTInstaller\sd_url.txt => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\cmd.ini => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\DownloadManagerAPI.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\DownloadManagerWrapper.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\gcapi.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\gtapi.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\htmlayout.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\InnoHelpers.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\InnoSelfProtect.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\InstallWrapper.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\pctcc.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\PCTUI.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\tiscript.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\PC Tools Download Manager\lang\English.dll => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\nssA194.tmp\ccsetup.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\msohtmlclip1\01\clip_colorschememapping.xml => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\msohtmlclip1\01\clip_themedata.thmx => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\MozUpdater\bgupdate\updater.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Low\JavaDeployReg.log => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\is-DGJD2.tmp\InnoMonitor2.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\is-2MGDJ.tmp\InnoMonitor2.exe => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\avastBCLTMP\firefox\{cb84136f-9c44-433a-9048-c5cd9df1dc16}\bdtoolbar.jar.unp\skin\icon.png => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\avastBCLTMP\firefox\{82af8dca-6de9-405d-bd5e-43525bdad38a}\icon.png => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\.jpf-shadow\euroshare.eu@1.0.2.frp => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\.jpf-shadow\uloz.to@1.1.5.frp => Moved successfully.
Could not move "C:\Users\Kateřina\AppData\Local\Temp" directory. => Scheduled to move on reboot.


=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-05-15 07:37:37)<=

C:\Program Files (x86)\Skype\Toolbars => Moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\TeamViewer\Version7\TeamViewer7_Logfile.log => Is moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Skype\DbTemp\temp-8HlSzJA1Q8Q5cftUy3hEVJca => Is moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Skype\DbTemp\temp-aS346gpSKz5yFD2LxY8SRH1M => Is moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Skype\DbTemp\temp-eczGBaTDkTskMXZkXJOlXasL => Is moved successfully.
C:\Users\Kateřina\AppData\Local\Temp\Skype\DbTemp\temp-eNNZdH2bjjnWQZAKztVDVyL2 => Is moved successfully.
C:\Users\Kateřina\AppData\Local\Temp => Moved successfully.

==== End of Fixlog ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119537
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST prosím o kontrolu.

#4 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST prosím o kontrolu.

#5 Příspěvek od Cizap »

Jo je to znát :) stránky už se nezasekávaj beží to celkem plynule volat taky jde normálně akorát nevim, to bude asi problem mozilly, když chci poslat email v outlook web app dám kopírovat tak občas musím třeba 3x kliknout do okna "komu" než je tlačítko vložit aktivní a druhá věc při přihlášení do tý služby na volání se obrazovka sekne a zůstane tam loading a musí se to přihlašovat na dvakrát tak teď se jen chci zeptat jestli mozillu přeinstalovat nebo nějak vyčistit nebo nevim (v exploreru to přihlášení jde hned) :) každopádně zatim moc děkuji :thumbsup:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119537
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST prosím o kontrolu.

#6 Příspěvek od Rudy »

FF přeinstalujte. Před tím profil zazálohujte pomocí MozBackup: http://www.stahuj.centrum.cz/utility_a_ ... mozbackup/ . Nainstalujte nový FF a ze zálohy zpět nakopírujte pouze záložky. Zatím není zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Cizap
Návštěvník
Návštěvník
Příspěvky: 81
Registrován: 07 dub 2014 11:56

Re: FRST prosím o kontrolu.

#7 Příspěvek od Cizap »

Tak přeinstalováno ještě to segra vyzkouší na volání zítra jak to bude chodit protože dneska tomu moc nedala a volala když volalo málo lidí a ještě bych se ozval jestli ok nebo ne. Vřele díky hezký večer :worship:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119537
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST prosím o kontrolu.

#8 Příspěvek od Rudy »

Hezký večer i vám a nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět