Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Nevyžádaná připojení k herním serverům

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
kej.alin
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 pro 2013 11:31

Nevyžádaná připojení k herním serverům

#1 Příspěvek od kej.alin »

Dobrý den!
Každý den se PC opakovaně připojuje buď k ponorka.eu nebo youtube.com. Výpis z dnešní historie přikládám:



9:34
FOG.COM: Page Not Found (/en/tag/shooting-games/?utm_source=freeonlinegames.com&utm_medium=api-game&utm_campaign=AlienAssault-en)
www.freeonlinegames.com

9:33
Alien Assault - Free Games For Your Website
www.freegamesforyourwebsite.com

9:33
Majustuff
majustuff.tumblr.com

9:33
http://majustuff.tumblr.com/#_=_
majustuff.tumblr.com

9:33
EXOTWORKING • please rearrange your face
www.exotworking.com

9:32
Play The Visit Game Here - A Platform Game on FOG.COM
www.freeonlinegames.com

9:30
Play Xunmato Alpha Game Here - A Platform Game on FOG.COM
www.freeonlinegames.com

9:21
Play Mike Shadow Game Here - A Fighting Game on FOG.COM
www.freeonlinegames.com

9:20
THE AMAZING SPIDERMAN ONLINE MOVIE GAME - WWW.PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:19
3D GAMES 12 - WWW.PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:19
STUNT PILOT 2 SAN FRANCISCO - WWW.PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:17
Free Games For Your Website
www.freegamesforyourwebsite.com

9:17
Games - Free Online Games at FOG.COM
www.freeonlinegames.com

9:16
OFF ROADERS 2 - WWW.PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:16
PHINEAS AND FERB THE DIMENSION OF DOOOOM - WWW.PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:15
3D GAMES 11 - WWW.PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:06
TACTICAL FORCE - WWW.PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:06
FLUFY MINIGOLF - WWW.PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:05
3D GAMES 1 - WWW.PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:05
PONORKA.EU, flash hry online, hry zdarma, superhry, 1000her, webgames, webhry
ponorka.eu

9:05
STRATEGICKÉ 14 - PONORKA.EU - FLASH GAMES
ponorka.eu

9:00
RELIC OF WAR - PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

9:00
STRATEGICKÉ 13 - PONORKA.EU - FLASH GAMES
ponorka.eu

8:59
STRATEGICKÉ 12 - PONORKA.EU - FLASH GAMES
ponorka.eu

8:53
GUNROX HOLY GRENADE - PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

8:53
STRATEGICKÉ 11 - PONORKA.EU - FLASH GAMES
ponorka.eu

8:52
STRATEGICKÉ 10 - PONORKA.EU - FLASH GAMES
ponorka.eu

8:52
STRATEGICKÉ 9 - PONORKA.EU - FLASH GAMES
ponorka.eu

8:52
STRATEGICKÉ 8 - PONORKA.EU - FLASH GAMES
ponorka.eu

8:48
PLANTS VS ZOMBIE - PONORKA.EU - ONLINE FLASH GAMES
ponorka.eu

8:47
Minecraft Mod - Miner Paradise Mod - New Armor, Items, and Dimension - YouTube
www.youtube.com

8:46
[SFM] A TF Morning - YouTube
www.youtube.com

8:46
Be The Sentry Buster - YouTube
www.youtube.com

7:54
Zelda Adventure [3. Díl - Samá voda] | Český Let's Play - YouTube
www.youtube.com


URL adresu ponorka.eu a youtube.com jsem zakázal v Avastu i v nastavení routeru, bohužel marně. Díky za kontrolu!

Tady je LOG:




Logfile of random's system information tool 1.10 (written by random/random)
Run by Ali-mini at 2014-06-10 11:12:01
Microsoft Windows 8.1
System drive C: has 377 GB (86%) free of 436 GB
Total RAM: 2043 MB (37% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:12:17, on 10.6.2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17037)
Boot mode: Normal

Running processes:
C:\Program Files\StartW8\bin\StartW8Button.exe
C:\WINDOWS\system32\taskhostex.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\StartW8\bin\StartW8Menu.exe
C:\Windows\System32\skydrive.exe
C:\Windows\System32\SettingSyncHost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
C:\Windows\jmesoft\hotkey.exe
C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wwahost.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Ali-mini\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Users\Ali-mini\Downloads\RSIT (3).exe
C:\Program Files\trend micro\Ali-mini.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=ddrnw
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files\Funmoods\funmoods\1.5.11.16\bh\funmoods.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20130103172101.dll (file missing)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe /FORPCEE4
O4 - HKLM\..\Run: [Dolby Home Theater v4] "C:\Program Files\Dolby Home Theater v4\pcee4.exe" -autostart
O4 - HKLM\..\Run: [jmekey] C:\Windows\jmesoft\hotkey.exe
O4 - HKLM\..\Run: [jmesoft] C:\Windows\jmesoft\ServiceLoader.exe
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [Reader Application Helper] C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe
O4 - HKLM\..\Run: [SetDefaultSCR] C:\Program Files\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RunOdigo] C:\Program Files\Odigo\Bin\Odigo.exe
O4 - HKLM\..\Run: [StartW8Button] C:\Program Files\StartW8\bin\StartW8Button.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\WINDOWS\system32\atiesrxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: JME Keyboard Driver (JME Keyboard) - Unknown owner - C:\Windows\jmesoft\Service.exe
O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
O23 - Service: StartW8Service - SODATSW spol. s .r.o. - C:\Program Files\StartW8\bin\StartW8Service.exe

--
End of file - 6030 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core.job - C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA.job - C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}]
Funmoods Helper Object - C:\Program Files\Funmoods\funmoods\1.5.11.16\bh\funmoods.dll [2012-01-25 241888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20130103172101.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-05-16 436600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-03-21 4502400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2011-12-20 11487848]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [2011-11-15 1571432]
"Dolby Home Theater v4"=C:\Program Files\Dolby Home Theater v4\pcee4.exe [2011-06-01 506712]
"jmekey"=C:\Windows\jmesoft\hotkey.exe [2011-07-20 118784]
"jmesoft"=C:\Windows\jmesoft\ServiceLoader.exe [2011-03-15 28672]
"NUSB3MON"=C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2011-04-14 113288]
"Reader Application Helper"=C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [2012-11-08 898952]
"SetDefaultSCR"=C:\Program Files\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe [2009-12-30 102400]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2013-10-19 343168]
"RunOdigo"=C:\Program Files\Odigo\Bin\Odigo.exe [2001-01-18 1265664]
"StartW8Button"=C:\Program Files\StartW8\bin\StartW8Button.exe [2012-12-19 53736]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-09-23 926896]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-05-26 3888648]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2012-11-01 4763008]
"Google Update"=C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-09 116648]
"GoogleDriveSync"=C:\Program Files\Google\Drive\googledrivesync.exe [2013-12-06 20203904]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"vidc.cvid"=iccvid.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.VP60"=vp6vfw.dll
"VIDC.VP61"=vp6vfw.dll
"VIDC.VP62"=vp6vfw.dll
"VIDC.VP70"=vp7vfw.dll
"VIDC.X264"=vp7vfw.dll
"vidc.i263"=i263_32.drv
"VIDC.HFYU"=huffyuv.dll
"VIDC.YV12"=yv12vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.ac3filter"=ac3filter.acm
"msacm.divxa32"=divxa32.acm
"msacm.l3codecp"=l3codecp.acm
"msacm.lameacm"=lameACM.acm
"msacm.vorbis"=vorbis.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-06-07 08:31:30 ----D---- C:\Users\Ali-mini\AppData\Roaming\Mozilla
2014-05-16 08:54:11 ----A---- C:\WINDOWS\system32\drivers\aswHwid.sys
2014-05-16 08:54:05 ----A---- C:\WINDOWS\avastSS.scr
2014-05-14 14:58:49 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-05-14 14:58:48 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-05-14 14:58:46 ----A---- C:\WINDOWS\system32\wusa.exe
2014-05-14 14:58:34 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2014-05-14 14:58:32 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2014-05-14 14:58:31 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2014-05-14 14:58:23 ----A---- C:\WINDOWS\system32\shell32.dll
2014-05-14 14:58:20 ----A---- C:\WINDOWS\system32\mrt100.dll
2014-05-14 14:58:20 ----A---- C:\WINDOWS\system32\mrt_map.dll
2014-05-14 14:58:16 ----A---- C:\WINDOWS\system32\storewuauth.dll
2014-05-14 14:58:15 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-05-14 14:58:14 ----A---- C:\WINDOWS\system32\twinui.dll
2014-05-14 14:58:13 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-05-14 14:58:12 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-05-14 14:58:12 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-05-14 14:58:12 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-05-14 14:58:12 ----A---- C:\WINDOWS\system32\ubpm.dll
2014-05-14 14:58:11 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-05-14 14:58:11 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-14 14:58:11 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2014-05-14 14:58:11 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2014-05-14 14:58:10 ----A---- C:\WINDOWS\system32\wuwebv.dll
2014-05-14 14:58:10 ----A---- C:\WINDOWS\system32\wups.dll
2014-05-14 14:58:10 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-05-14 14:58:10 ----A---- C:\WINDOWS\system32\wuapp.exe
2014-05-14 14:58:09 ----A---- C:\WINDOWS\system32\WSReset.exe

======List of files/folders modified in the last 1 month======

2014-06-10 11:12:08 ----D---- C:\WINDOWS\Prefetch
2014-06-10 11:12:05 ----D---- C:\Program Files\trend micro
2014-06-10 11:02:02 ----D---- C:\WINDOWS\system32\sru
2014-06-10 10:15:42 ----D---- C:\WINDOWS\Temp
2014-06-10 10:13:09 ----D---- C:\WINDOWS\Microsoft.NET
2014-06-10 09:49:44 ----RD---- C:\WINDOWS\System32
2014-06-10 09:49:43 ----D---- C:\WINDOWS\inf
2014-06-10 09:49:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-06-09 13:15:04 ----SHD---- C:\System Volume Information
2014-06-09 11:19:32 ----D---- C:\WINDOWS\AppReadiness
2014-06-07 08:31:33 ----SHD---- C:\WINDOWS\Installer
2014-06-07 08:31:32 ----SHD---- C:\Config.Msi
2014-05-29 09:09:15 ----HD---- C:\Program Files\WindowsApps
2014-05-28 07:41:36 ----D---- C:\WINDOWS\system32\config
2014-05-27 16:04:45 ----D---- C:\Program Files\Java
2014-05-17 09:27:27 ----D---- C:\WINDOWS\system32\NDF
2014-05-16 09:47:32 ----D---- C:\WINDOWS\system32\Drivers
2014-05-16 08:54:44 ----D---- C:\WINDOWS\system32\DriverStore
2014-05-16 08:54:13 ----D---- C:\WINDOWS\system32\Tasks
2014-05-16 08:54:10 ----D---- C:\Windows
2014-05-16 08:54:05 ----A---- C:\WINDOWS\system32\aswBoot.exe
2014-05-15 09:32:16 ----D---- C:\WINDOWS\rescache
2014-05-15 08:49:15 ----D---- C:\WINDOWS\WinSxS
2014-05-15 08:42:31 ----RD---- C:\WINDOWS\assembly
2014-05-14 22:53:51 ----D---- C:\Program Files\Windows Defender
2014-05-14 22:53:50 ----RD---- C:\WINDOWS\ToastData
2014-05-14 22:53:50 ----D---- C:\WINDOWS\apppatch
2014-05-14 22:53:49 ----D---- C:\WINDOWS\WinStore
2014-05-14 22:53:49 ----D---- C:\WINDOWS\system32\cs-CZ
2014-05-14 15:15:39 ----D---- C:\WINDOWS\CbsTemp
2014-05-14 15:13:57 ----D---- C:\WINDOWS\system32\SecureBootUpdates
2014-05-14 15:13:52 ----D---- C:\WINDOWS\system32\MRT
2014-05-14 15:10:43 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-05-16 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-05-16 180632]
R0 Wof;Windows Overlay File System Filter Driver; C:\WINDOWS\system32\drivers\Wof.sys [2014-03-13 138584]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-05-16 81768]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-05-16 777488]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-05-16 411680]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2013-08-22 57344]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-05-16 24184]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-05-16 67824]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-05-16 68312]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2013-06-06 10908160]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2013-06-06 493568]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHDA.sys [2011-12-20 3922984]
R3 RTHDMIAzAudService;Service for HDMI; C:\WINDOWS\system32\drivers\RtHDMIV.sys [2011-12-02 199528]
R3 RTL8168;@netrt630x86.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x86.sys [2013-06-18 490496]
R3 RTWlanE;@netrtwlane.inf,%RTWlanE.DeviceDesc.DispName%;Realtek Wireless LAN 802.11n PCI-E – síťový adaptér; C:\WINDOWS\system32\DRIVERS\rtwlane.sys [2013-07-31 1659096]
R3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 88192]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2013-08-22 176768]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2013-08-22 29184]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2013-07-23 22016]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2013-07-23 61936]
S3 RSUSBVSTOR;@oem13.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [2011-09-14 232040]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 37888]
S3 WimFltr;WimFltr; C:\WINDOWS\system32\DRIVERS\wimfltr.sys [2008-08-06 128104]
S3 WinUsb;@wpdmtp.inf,%WinUsb.SvcDesc%;WinUsb; C:\WINDOWS\system32\DRIVERS\WinUsb.sys [2013-08-22 64000]
S3 wsvd;wsvd; C:\WINDOWS\system32\DRIVERS\wsvd.sys [2009-07-21 81704]
S3 WUDFSensorLP;@locationprovider.inf,%WudfLocationProviderDisplayName%;Služba Reflektor UMDF pro zprostředkovatele umístění (LocationProvider); C:\WINDOWS\System32\drivers\WUDFRd.sys [2013-08-22 187392]
S3 WUDFWpdFs;WUDFWpdFs; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [2013-08-22 187392]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2012-07-11 116608]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-09-23 65192]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2013-02-21 219136]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-05-16 50344]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-04-11 1390720]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-04-11 1764992]
R2 JME Keyboard;JME Keyboard Driver; C:\Windows\jmesoft\Service.exe [2011-03-15 32768]
R2 StartW8Service;StartW8Service; C:\Program Files\StartW8\bin\StartW8Service.exe [2012-12-19 48640]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-10 136120]
S3 Sony SCSI Helper Service;Sony SCSI Helper Service; C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [2012-10-23 73728]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-03 116648]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-03 116648]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nevyžádaná připojení k herním serverům

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kej.alin
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 pro 2013 11:31

Re: Nevyžádaná připojení k herním serverům

#3 Příspěvek od kej.alin »

# AdwCleaner v3.212 - Report created 10/06/2014 at 11:55:52
# Updated 05/06/2014 by Xplode
# Operating System : Windows 8.1 (32 bits)
# Username : Ali-mini - ALI-MINI-PC
# Running from : C:\Users\Ali-mini\Desktop\adwcleaner_3.212.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\Program Files\Funmoods
Folder Deleted : C:\Users\Ali-mini\AppData\LocalLow\Funmoods
Folder Deleted : C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgpdioedihjhncjafcpgbbjdpbbkikmi

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DDE62EB2-F367-41A7-8E4D-875811DC373D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.funmoodsESrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.funmoodsESrvc.1
Key Deleted : HKLM\SOFTWARE\Classes\f
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr
Key Deleted : HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr.1
Key Deleted : HKLM\SOFTWARE\Classes\funmoodsApp.appCore
Key Deleted : HKLM\SOFTWARE\Classes\funmoodsApp.appCore.1
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{75A4D144-506D-4BE5-81DB-EC7DA1E7F840}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A}
Key Deleted : HKCU\Software\Funmoods
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\Funmoods
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Funmoods

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17037

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v31.0.1650.63

[ File : C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://start.funmoods.com/results.php?f=4&a=ddrnw&q={searchTerms}
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://stesticko.inshop.cz/inshop/scripts/shop.aspx?action=dosearch&searchphrase={searchTerms}
Deleted [Extension] : dgpdioedihjhncjafcpgbbjdpbbkikmi
Deleted [Extension] : fdloijijlkoblmigdofommgnheckmaki

*************************

AdwCleaner[R0].txt - [5086 octets] - [10/06/2014 11:52:52]
AdwCleaner[S0].txt - [5374 octets] - [10/06/2014 11:55:52]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5434 octets] ##########







Zoek.exe v5.0.0.0 Updated 02-June-2014
Tool run by Ali-mini on Łt 10.06.2014 at 12:06:22,12.
Microsoft Windows 8.1 6.3.9600 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Ali-mini\Desktop\zoek.exe [Scan all users] [Quick Scan] [Auto Clean]

==== System Restore Info ======================

10.6.2014 12:10:21 Zoek.exe System Restore Point Created Succesfully.

==== Empty Folders Check ======================

C:\Program Files\DsNET Corp deleted successfully
C:\PROGRA~2\Oracle deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3615216187-194475068-2945929391-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CAD080A0-99F8-4EF5-BBD4-9E37E3A08A36} deleted successfully
HKEY_USERS\S-1-5-21-3615216187-194475068-2945929391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} deleted successfully
HKEY_USERS\S-1-5-21-3615216187-194475068-2945929391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Users\Ali-mini\Downloads\SoftonicDownloader_for_picasa.exe deleted
C:\user.js deleted

==== Files Recently Created / Modified ======================

====== C:\WINDOWS ====
2014-05-16 06:54:05 0B5A0005C0BDF4A05174576AF80DEA04 43152 ----a-w- C:\WINDOWS\avastSS.scr
====== C:\Users\Ali-mini\AppData\Local\Temp ====
====== Java Cache =====
====== C:\WINDOWS\system32 =====
2014-06-10 09:54:46 0DC5AF80D059DEC792B665ED598C6567 536576 ----a-w- C:\WINDOWS\System32\sqlite3.dll
====== C:\WINDOWS\system32\drivers =====
2014-05-16 06:54:11 4D6C6E0505A8E5A0656DCB223497D37C 24184 ----a-w- C:\WINDOWS\System32\drivers\aswHwid.sys
2014-05-14 12:58:34 BBD6DF3FC00CACBFA92A4C98CE5C0CCD 219992 ----a-w- C:\WINDOWS\System32\drivers\WdFilter.sys
2014-05-14 12:58:32 D7B8475F59FD0C9C395151E5BB5DCC2E 92504 ----a-w- C:\WINDOWS\System32\drivers\WdNisDrv.sys
2014-05-14 12:58:31 5B9AEA959D59C5F2DAEC2E6FD6DDFB0F 30224 ----a-w- C:\WINDOWS\System32\drivers\WdBoot.sys
====== C:\WINDOWS\Tasks ======
====== C:\WINDOWS\Temp ======
======= C:\Program Files =====
======= C: =====
====== C:\Users\Ali-mini\AppData\Roaming ======
2014-06-07 06:31:30 -------- d-----w- C:\Users\Ali-mini\AppData\Roaming\Mozilla
====== C:\Users\Ali-mini ======
2014-06-10 09:49:11 42F24559E8C472F6FF745BB7C5465FB2 1333465 ----a-w- C:\Users\Ali-mini\Desktop\adwcleaner_3.212.exe
2014-06-10 09:11:44 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\Ali-mini\Downloads\RSIT (3).exe
2014-06-10 09:11:07 B9B5E09AACBCCEC00D4C4452F7ABB8FB 781909 ----a-w- C:\Users\Ali-mini\Downloads\RSIT (2).exe
2014-06-10 09:09:14 B9B5E09AACBCCEC00D4C4452F7ABB8FB 781909 ----a-w- C:\Users\Ali-mini\Downloads\RSIT (1).exe

====== C: exe-files ==
2014-06-10 09:49:11 42F24559E8C472F6FF745BB7C5465FB2 1333465 ----a-w- C:\Users\Ali-mini\Desktop\adwcleaner_3.212.exe
2014-06-10 09:11:44 8685FAF50C04F9A9C2F56FF64B0B7ACB 1107968 ----a-w- C:\Users\Ali-mini\Downloads\RSIT (3).exe
2014-06-10 09:11:07 B9B5E09AACBCCEC00D4C4452F7ABB8FB 781909 ----a-w- C:\Users\Ali-mini\Downloads\RSIT (2).exe
2014-06-10 09:09:14 B9B5E09AACBCCEC00D4C4452F7ABB8FB 781909 ----a-w- C:\Users\Ali-mini\Downloads\RSIT (1).exe
2014-06-07 06:30:49 E8303EC0B00183D96D587986E866A8EF 2560 ----a-w- C:\Users\Ali-mini\AppData\Local\Google\Google Talk Plugin\redirect\googletalkplugin.exe
2014-06-06 09:27:16 4D4A404F08012AD3C2F5753D37F5AE21 64384 ----a-w- C:\Users\Ali-mini\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
=== C: other files ==

==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-21-3615216187-194475068-2945929391-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"Google Update"="C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"GoogleDriveSync"="C:\Program Files\Google\Drive\googledrivesync.exe /autostart"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s"
"RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe /FORPCEE4 "
"Dolby Home Theater v4"="C:\Program Files\Dolby Home Theater v4\pcee4.exe -autostart"
"jmekey"="C:\Windows\jmesoft\hotkey.exe"
"jmesoft"="C:\Windows\jmesoft\ServiceLoader.exe"
"NUSB3MON"="C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"Reader Application Helper"="C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe"
"SetDefaultSCR"="C:\Program Files\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe"
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun"
"RunOdigo"="C:\Program Files\Odigo\Bin\Odigo.exe"
"StartW8Button"="C:\Program Files\StartW8\bin\StartW8Button.exe"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
"Google Update"="C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe /c"
"GoogleDriveSync"="C:\Program Files\Google\Drive\googledrivesync.exe /autostart"

==== Task Scheduler Jobs ======================

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job --a-------- C:\Program Files\Google\Update\GoogleUpdate.exe [03.01.2013 12:48]
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job --a-------- C:\Program Files\Google\Update\GoogleUpdate.exe [03.01.2013 12:48]
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core.job --a-------- C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe [09.02.2013 22:00]
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA.job --a-------- C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe [09.02.2013 22:00]

==== Other Scheduled Tasks ======================

"C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\WINDOWS\system32\tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core" [C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\WINDOWS\system32\tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA" [C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{85565B91-571C-405B-8883-BF9006DA822F}" [C:\WINDOWS\system32\msfeedssync.exe]

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[16.05.2014 08:53]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[11.04.2014 19:46]

Google Docs - Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Speed Dial - Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgpdioedihjhncjafcpgbbjdpbbkikmi
AdBlock - Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Website Blocker Beta - Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclgegipaehbigmbhdpfapmjadbaldib
Skype Click to Call - Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Puzzle for Chrome - Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbalnpbcmecdckpghgacibglihkgamkl
Google Mail Checker - Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff
Google Wallet - Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
iReader - Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppelffpjgkifjfgnbaaldcehkpajlmbc

==== Chrome Fix ======================

C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_adblock_plus_firefox.en.softonic.com_0.localstorage deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_adblock_plus_firefox.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_answers.en.softonic.com_0.localstorage deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_answers.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.softonic.com_0.localstorage deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_picasa.en.softonic.com_0.localstorage deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_picasa.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_speed-dial.en.softonic.com_0.localstorage deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_speed-dial.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgpdioedihjhncjafcpgbbjdpbbkikmi deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dgpdioedihjhncjafcpgbbjdpbbkikmi_0.localstorage deleted successfully
C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dgpdioedihjhncjafcpgbbjdpbbkikmi_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Search_URL"="http://www.google.com/ie"
"Search Bar"="http://www.google.com/ie"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://www.google.com/ie"
"SearchAssistant"="http://www.google.com/ie"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{98AEBE7A-D40E-45C3-B5F6-33022CC0C333} Google Url="http://www.google.com/search?q={searchT ... f8&oe=utf8"

==== Empty IE Cache ======================

C:\Users\Ali-mini\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Ali-mini\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=138 folders=29 6986023 bytes)

==== Empty Temp Folders ======================

C:\Users\Ali-mini\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Ali-mini\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\Low" not deleted

==== EOF on Łt 10.06.2014 at 12:45:04,68 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nevyžádaná připojení k herním serverům

#4 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kej.alin
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 pro 2013 11:31

Re: Nevyžádaná připojení k herním serverům

#5 Příspěvek od kej.alin »

Sorry, musel jsem nutně odjet.


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:09-06-2014 03
Ran by Ali-mini (administrator) on ALI-MINI-PC on 10-06-2014 13:51:40
Running from C:\Users\Ali-mini\Desktop
Platform: Microsoft Windows 8.1 Update 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(SODATSW spol. s .r.o.) C:\Program Files\StartW8\bin\StartW8Service.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\Windows\jmesoft\Service.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(SODATSW spol. s r.o.) C:\Program Files\StartW8\bin\StartW8Button.exe
(SODATSW spol. s r. o.) C:\Program Files\StartW8\bin\StartW8Menu.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Lenovo) C:\Windows\jmesoft\hotkey.exe
(Renesas Electronics Corporation) C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
() C:\Windows\jmesoft\JME_LOAD.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google) C:\Users\Ali-mini\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Ali-mini\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [11487848 2011-12-20] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [1571432 2011-11-15] (Realtek Semiconductor)
HKLM\...\Run: [Dolby Home Theater v4] => C:\Program Files\Dolby Home Theater v4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM\...\Run: [jmekey] => C:\Windows\jmesoft\hotkey.exe [118784 2011-07-20] (Lenovo)
HKLM\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe [28672 2011-03-15] ()
HKLM\...\Run: [NUSB3MON] => C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-14] (Renesas Electronics Corporation)
HKLM\...\Run: [Reader Application Helper] => C:\Program Files\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe [898952 2012-11-08] (Sony Corporation)
HKLM\...\Run: [SetDefaultSCR] => C:\Program Files\Lenovo\Lenovo Screensaver\SetDefaultSCR.exe [102400 2009-12-30] (Lenovo)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2013-10-19] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RunOdigo] => C:\Program Files\Odigo\Bin\Odigo.exe [1265664 2001-01-18] (Odigo)
HKLM\...\Run: [StartW8Button] => C:\Program Files\StartW8\bin\StartW8Button.exe [53736 2012-12-19] (SODATSW spol. s r.o.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3890208 2014-06-05] (AVAST Software)
HKU\S-1-5-21-3615216187-194475068-2945929391-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [4763008 2012-11-01] (SUPERAntiSpyware.com)
HKU\S-1-5-21-3615216187-194475068-2945929391-1000\...\Run: [Google Update] => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-02-09] (Google Inc.)
HKU\S-1-5-21-3615216187-194475068-2945929391-1000\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [20203904 2013-12-06] (Google)

==================== Internet (Whitelisted) ====================

SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.20.53 10.0.20.10

FireFox:
========
FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @sony.com/ReaderDesktop - C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Ali-mini\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Ali-mini\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Ali-mini\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Ali-mini\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Ali-mini\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Ali-mini\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)

Chrome:
=======
CHR HomePage: https://www.google.com/ig
CHR RestoreOnStartup: "https://mail.google.com/mail/u/0/?tab=wm#inbox"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Google Talk Plugin) - C:\Users\Ali-mini\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Accelerator) - C:\Users\Ali-mini\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll No File
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Ali-mini\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (Picasa) - C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Reader Application Detector) - C:\Program Files\Sony\ReaderDesktop\npreaderdetectmoz.dll (Sony Corporation)
CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Extension: (Dokumenty Google) - C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-05-27]
CHR Extension: (AdBlock) - C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-04-04]
CHR Extension: (Website Blocker (Beta)) - C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\hclgegipaehbigmbhdpfapmjadbaldib [2013-12-29]
CHR Extension: (Skype Click to Call) - C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-05-27]
CHR Extension: (Puzzle for Chrome) - C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbalnpbcmecdckpghgacibglihkgamkl [2014-04-04]
CHR Extension: (Kontrola e-mailu Google) - C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2013-11-01]
CHR Extension: (Peněženka Google) - C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (iReader) - C:\Users\Ali-mini\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppelffpjgkifjfgnbaaldcehkpajlmbc [2014-04-04]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-05-16]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]

========================== Services (Whitelisted) =================

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [116608 2012-07-11] (SUPERAntiSpyware.com) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-16] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-15] () [File not signed]
S3 ScDeviceEnum; C:\WINDOWS\System32\ScDeviceEnum.dll [105472 2013-08-22] (Microsoft Corporation)
S3 Sony SCSI Helper Service; C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe [73728 2012-10-23] (Sony Corporation) [File not signed]
R2 StartW8Service; C:\Program Files\StartW8\bin\StartW8Service.exe [48640 2012-12-19] (SODATSW spol. s .r.o.) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [279784 2014-03-24] (Microsoft Corporation)
S3 WEPHOSTSVC; C:\WINDOWS\system32\wephostsvc.dll [20992 2013-08-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22224 2014-03-24] (Microsoft Corporation)
S3 workfolderssvc; C:\WINDOWS\system32\workfolderssvc.dll [1210368 2013-10-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24184 2014-05-16] ()
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [67824 2014-05-16] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [81768 2014-05-16] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2014-05-16] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [777488 2014-05-16] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [411680 2014-05-16] (AVAST Software)
S2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [68312 2014-05-16] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [180632 2014-05-16] ()
R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [25600 2014-02-22] (Microsoft Corporation)
S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpio.sys [22016 2013-07-23] (Intel Corporation)
S3 RSUSBVSTOR; C:\WINDOWS\System32\Drivers\RtsUVStor.sys [232040 2011-09-14] (Realtek Semiconductor Corp.)
R3 RTHDMIAzAudService; C:\WINDOWS\system32\drivers\RtHDMIV.sys [199528 2011-12-02] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\WINDOWS\system32\DRIVERS\rtwlane.sys [1659096 2013-07-31] (Realtek Semiconductor Corporation )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [92504 2014-03-24] (Microsoft Corporation)
R0 Wof; C:\WINDOWS\system32\Drivers\Wof.sys [138584 2014-03-13] (Microsoft Corporation)
S3 wsvd; C:\WINDOWS\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
S3 WUDFSensorLP; C:\WINDOWS\System32\drivers\WUDFRd.sys [187392 2013-08-22] (Microsoft Corporation)
S3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [187392 2013-08-22] (Microsoft Corporation)
U3 idsvc;

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-10 13:51 - 2014-06-10 13:52 - 00014675 _____ () C:\Users\Ali-mini\Desktop\FRST.txt
2014-06-10 13:50 - 2014-06-10 13:51 - 00000000 ____D () C:\FRST
2014-06-10 13:48 - 2014-06-10 13:48 - 00112640 _____ (forum.viry.cz) C:\Users\Ali-mini\Desktop\FRSTLauncher.exe
2014-06-10 13:44 - 2014-06-10 13:44 - 01177600 _____ (Farbar) C:\Users\Ali-mini\Desktop\FRST.exe
2014-06-10 13:27 - 2014-06-10 13:27 - 06794240 _____ () C:\Users\Ali-mini\Downloads\Vse_je_ze_dreva.pps
2014-06-10 12:42 - 2014-06-10 13:54 - 00000000 ____D () C:\Users\Ali-mini\AppData\Local\Temp
2014-06-10 12:42 - 2014-06-10 12:42 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp
2014-06-10 12:42 - 2014-06-10 12:42 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp
2014-06-10 12:42 - 2014-06-10 12:06 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-06-10 12:09 - 2014-06-10 12:45 - 00014640 _____ () C:\zoek-results.log
2014-06-10 12:06 - 2014-06-10 12:43 - 00000000 ____D () C:\zoek_backup
2014-06-10 12:05 - 2014-06-10 12:05 - 01285120 _____ () C:\Users\Ali-mini\Desktop\zoek.exe
2014-06-10 11:54 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll
2014-06-10 11:51 - 2014-06-10 11:56 - 00000000 ____D () C:\AdwCleaner
2014-06-10 11:49 - 2014-06-10 11:49 - 01333465 _____ () C:\Users\Ali-mini\Desktop\adwcleaner_3.212.exe
2014-06-10 11:37 - 2014-06-10 11:37 - 01686016 _____ () C:\Users\Ali-mini\Downloads\Skoro_neuveritelné_fotky.pps
2014-06-10 11:11 - 2014-06-10 11:11 - 01107968 _____ () C:\Users\Ali-mini\Downloads\RSIT (3).exe
2014-06-10 11:11 - 2014-06-10 11:11 - 00781909 _____ () C:\Users\Ali-mini\Downloads\RSIT (2).exe
2014-06-10 11:09 - 2014-06-10 11:09 - 00781909 _____ () C:\Users\Ali-mini\Downloads\RSIT (1).exe
2014-06-10 10:53 - 2014-06-10 10:53 - 09993216 _____ () C:\Users\Ali-mini\Downloads\Unavení... (1).pps
2014-06-10 10:44 - 2014-06-10 10:44 - 09993216 _____ () C:\Users\Ali-mini\Downloads\Unavení....pps
2014-06-09 22:41 - 2014-06-09 22:41 - 04012544 _____ () C:\Users\Ali-mini\Downloads\Bramboracka11.pps
2014-06-09 11:36 - 2014-06-09 11:36 - 09398510 _____ () C:\Users\Ali-mini\Downloads\Křižovatka v Etiopii - návratdoreality.cz[via torchbrowser.com] (2).mp4
2014-06-09 11:35 - 2014-06-09 11:36 - 09398510 _____ () C:\Users\Ali-mini\Downloads\Křižovatka v Etiopii - návratdoreality.cz[via torchbrowser.com] (1).mp4
2014-06-08 23:23 - 2014-06-08 23:23 - 00971718 _____ () C:\Users\Ali-mini\Downloads\why_women_have_handbags1.mp4
2014-06-08 11:41 - 2014-06-08 11:41 - 00005705 _____ () C:\Users\Ali-mini\Downloads\priloha (1).txt
2014-06-08 11:36 - 2014-06-08 11:37 - 14036185 _____ () C:\Users\Ali-mini\Downloads\Boeren_Power_2.ppsx
2014-06-07 13:25 - 2014-06-07 13:25 - 03034624 _____ () C:\Users\Ali-mini\Downloads\Pes_z_pohledu_muze.pps
2014-06-07 08:50 - 2014-06-07 08:50 - 05921261 _____ () C:\Users\Ali-mini\Downloads\1 zanger 2 gezichten.wmv
2014-06-07 08:31 - 2014-06-07 08:31 - 00000000 ____D () C:\Users\Ali-mini\AppData\Roaming\Mozilla
2014-06-06 20:10 - 2014-06-06 20:10 - 04412983 _____ () C:\Users\Ali-mini\Downloads\Pussy-lovers...Jeffy.ppsx
2014-06-06 20:10 - 2014-06-06 20:10 - 00000107 ____H () C:\Users\Ali-mini\Downloads\.~lock.Pussy-lovers...Jeffy.ppsx#
2014-06-06 17:51 - 2014-06-06 17:51 - 00942080 _____ () C:\Users\Ali-mini\Downloads\Tchyne, fotil Saudek.PPS
2014-06-06 13:23 - 2014-06-06 13:23 - 00417792 _____ () C:\Users\Ali-mini\Downloads\sestav_si_puzzle.pps
2014-06-06 12:53 - 2014-06-06 12:53 - 01041408 _____ () C:\Users\Ali-mini\Downloads\Návštěva hřbitova v Itálii (1).pps
2014-06-05 22:49 - 2014-06-05 22:50 - 10802688 _____ () C:\Users\Ali-mini\Downloads\nycstreetphotographermarkushartel.pps
2014-06-05 22:48 - 2014-06-05 22:48 - 04774400 _____ () C:\Users\Ali-mini\Downloads\Nuduri_artistice-Stan_Getz-Bahia_al.pps
2014-06-05 19:10 - 2014-06-05 19:10 - 00055296 _____ () C:\Users\Ali-mini\Downloads\Hadanka - kotatko.pps
2014-06-05 19:10 - 2014-06-05 19:10 - 00055296 _____ () C:\Users\Ali-mini\Downloads\Hadanka - kotatko (1).pps
2014-06-05 17:33 - 2014-06-05 17:33 - 00007806 _____ () C:\Users\Ali-mini\Downloads\Fwd_ Někdo z nás dělá blbce, ale KDO_!!.eml
2014-06-04 22:08 - 2014-06-04 22:08 - 12704256 _____ () C:\Users\Ali-mini\Downloads\60 pohledů z balkonu L H Po.pps
2014-06-04 10:49 - 2014-06-04 10:49 - 03175808 _____ () C:\Users\Ali-mini\Downloads\Praktickydoplnekdoauta.wmv
2014-06-04 10:33 - 2014-06-04 10:33 - 00012296 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ FW_ FW_ Rodina je víc než práce._. je to milé av krátké.eml
2014-06-03 21:44 - 2014-06-03 21:45 - 05774027 _____ () C:\Users\Ali-mini\Downloads\Knallerfrauen - Korken1.mp4
2014-06-03 14:22 - 2014-06-03 14:22 - 06357459 _____ () C:\Users\Ali-mini\Downloads\Ashampoo_Snap_2013.01.16_18h57m32s_002_.wmv
2014-06-03 11:30 - 2014-06-03 11:31 - 08557056 _____ () C:\Users\Ali-mini\Downloads\Nostalgie-Schoenes_aus_vergangenen_Zeiten.pps
2014-06-03 11:30 - 2014-06-03 11:31 - 08557056 _____ () C:\Users\Ali-mini\Downloads\Nostalgie-Schoenes_aus_vergangenen_Zeiten (1).pps
2014-06-03 10:12 - 2014-06-03 10:12 - 06104064 _____ () C:\Users\Ali-mini\Downloads\Epoustouflant1.pps
2014-06-02 15:57 - 2014-06-02 15:57 - 00073728 _____ () C:\Users\Ali-mini\Downloads\Schv. Rozpocet vyveska 2014[1] (2).xls
2014-06-02 15:54 - 2014-06-02 15:54 - 00073728 _____ () C:\Users\Ali-mini\Downloads\Schv. Rozpocet vyveska 2014[1].xls
2014-06-02 15:54 - 2014-06-02 15:54 - 00073728 _____ () C:\Users\Ali-mini\Downloads\Schv. Rozpocet vyveska 2014[1] (1).xls
2014-06-02 13:08 - 2014-06-02 13:08 - 01515520 _____ () C:\Users\Ali-mini\Downloads\Skleneny_chodnik_v_Cine.pps
2014-06-02 12:55 - 2014-06-02 12:56 - 04080640 _____ () C:\Users\Ali-mini\Downloads\Fotky2013.pps
2014-06-02 07:31 - 2014-06-02 07:31 - 11055616 _____ () C:\Users\Ali-mini\Downloads\B_fl_devastation-05-2014.pps
2014-06-01 22:23 - 2014-06-01 22:23 - 07481344 _____ () C:\Users\Ali-mini\Downloads\arkadi-ostritsky-1948-israelian-painter-adita.pps
2014-06-01 20:08 - 2014-06-01 20:09 - 06883840 _____ () C:\Users\Ali-mini\Downloads\Tanga.pps
2014-06-01 13:26 - 2014-06-01 13:26 - 02310144 _____ () C:\Users\Ali-mini\Downloads\Luxurie-planes-.pps
2014-06-01 13:23 - 2014-06-01 13:23 - 05496832 _____ () C:\Users\Ali-mini\Downloads\Les-plus-belles-photos-animali-res-de-l-ann-e-2009.pps
2014-06-01 13:21 - 2014-06-01 13:21 - 02830848 _____ () C:\Users\Ali-mini\Downloads\De-minikinis....pps
2014-05-31 22:22 - 2014-05-31 22:22 - 04789764 _____ () C:\Users\Ali-mini\Downloads\Dosekávka kukuřice - neskutečné! (1).mpeg
2014-05-31 22:21 - 2014-05-31 22:21 - 04789764 _____ () C:\Users\Ali-mini\Downloads\Dosekávka kukuřice - neskutečné!.mpeg
2014-05-31 22:17 - 2014-05-31 22:17 - 02841088 _____ () C:\Users\Ali-mini\Downloads\Google.pps
2014-05-30 11:41 - 2014-05-30 11:41 - 07110958 _____ () C:\Users\Ali-mini\Downloads\ProtiromskĂ˝ aktivista.wmv
2014-05-30 11:36 - 2014-05-30 11:37 - 09398510 _____ () C:\Users\Ali-mini\Downloads\Křižovatka v Etiopii - návratdoreality.cz[via torchbrowser.com].mp4
2014-05-30 07:53 - 2014-05-30 07:53 - 07491584 _____ () C:\Users\Ali-mini\Downloads\Ar zinojot kaip jie auga.pps
2014-05-29 21:22 - 2014-05-29 21:23 - 08308224 _____ () C:\Users\Ali-mini\Downloads\Fotky roku 2013 4.MM.pps
2014-05-29 21:16 - 2014-05-29 21:16 - 02267136 _____ () C:\Users\Ali-mini\Downloads\OdvazneMaminy.pps
2014-05-29 19:40 - 2014-05-29 19:40 - 07653376 _____ () C:\Users\Ali-mini\Downloads\De Virtule tuin.pps
2014-05-29 14:01 - 2014-05-29 14:01 - 00282112 _____ () C:\Users\Ali-mini\Downloads\super_hadanky (1).pps
2014-05-29 10:04 - 2014-05-29 10:04 - 00097474 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ UŽ MÁŠ POKLADNIČKU NA DUCHOD V EURECH __.eml
2014-05-28 21:18 - 2014-05-28 21:18 - 05318656 _____ () C:\Users\Ali-mini\Downloads\mode2013 (2).pps
2014-05-28 20:55 - 2014-05-28 20:55 - 03351040 _____ () C:\Users\Ali-mini\Downloads\No nepošli to! (1).pps
2014-05-28 19:52 - 2014-05-28 19:52 - 00794624 _____ () C:\Users\Ali-mini\Downloads\Reklamatina XX.pps
2014-05-28 19:47 - 2014-05-28 19:51 - 11286589 _____ () C:\Users\Ali-mini\Downloads\Misty_Miss.ppsx
2014-05-28 12:26 - 2014-05-28 12:26 - 01398784 _____ () C:\Users\Ali-mini\Downloads\Russia (1).pps
2014-05-28 09:53 - 2014-05-28 09:55 - 06927360 _____ () C:\Users\Ali-mini\Downloads\SAE - Abu Dhabi (1).pps
2014-05-27 21:18 - 2014-05-27 21:19 - 05956608 _____ () C:\Users\Ali-mini\Downloads\21 Special Hotel.pps
2014-05-27 19:39 - 2014-05-27 19:40 - 00684544 _____ () C:\Users\Ali-mini\Downloads\Mejte radi svou praci!.pps
2014-05-27 19:28 - 2014-05-27 19:29 - 00203264 _____ () C:\Users\Ali-mini\Downloads\opticky_klam_jencka.pps
2014-05-27 19:28 - 2014-05-27 19:28 - 00000257 _____ () C:\Users\Ali-mini\Downloads\_Certification_ (5).htm
2014-05-27 19:11 - 2014-05-27 19:12 - 03533312 _____ () C:\Users\Ali-mini\Downloads\Co v životě málo kdy spatříte (1).pps
2014-05-27 19:11 - 2014-05-27 19:11 - 03533312 _____ () C:\Users\Ali-mini\Downloads\Co v životě málo kdy spatříte.pps
2014-05-27 16:04 - 2014-05-27 16:04 - 00000000 _____ () C:\WINDOWS\system32\jupdate-1.7.0_55-b14.log
2014-05-27 14:44 - 2014-05-27 14:44 - 04511744 _____ () C:\Users\Ali-mini\Downloads\kava (1).pps
2014-05-27 13:17 - 2014-05-27 13:17 - 04048591 _____ () C:\Users\Ali-mini\Downloads\Zajimavé koupáni.mp4
2014-05-26 20:10 - 2014-05-26 20:11 - 09478144 _____ () C:\Users\Ali-mini\Downloads\50 neobvyklých věcí co o sobě nevíte (1).pps
2014-05-26 20:09 - 2014-05-26 20:11 - 09478144 _____ () C:\Users\Ali-mini\Downloads\50 neobvyklých věcí co o sobě nevíte.pps
2014-05-26 19:18 - 2014-05-26 19:18 - 01565696 _____ () C:\Users\Ali-mini\Downloads\293310_raphlebroc (2).pps
2014-05-26 14:27 - 2014-05-26 14:27 - 01285632 _____ () C:\Users\Ali-mini\Downloads\11_rad_proti_zblazneni_d.pps
2014-05-25 12:23 - 2014-05-25 12:23 - 04701675 _____ () C:\Users\Ali-mini\Downloads\Nemela provokovat.wmv.wmv
2014-05-24 21:13 - 2014-05-24 21:14 - 05708800 _____ () C:\Users\Ali-mini\Downloads\Úžasné.pps
2014-05-24 19:45 - 2014-05-24 19:46 - 12893844 _____ () C:\Users\Ali-mini\Downloads\Romantic_red.ppsx
2014-05-24 09:46 - 2014-05-24 09:46 - 02781721 _____ () C:\Users\Ali-mini\Downloads\beaute-de-jeunesse-madeleine.ppsx
2014-05-24 09:45 - 2014-05-24 09:45 - 06550528 _____ () C:\Users\Ali-mini\Downloads\amazing-3d-street-art-4-day.pps
2014-05-24 09:41 - 2014-05-24 09:41 - 00038912 _____ () C:\Users\Ali-mini\Downloads\Kratke_a_pekne.pps
2014-05-24 09:22 - 2014-05-24 09:22 - 02248192 _____ () C:\Users\Ali-mini\Downloads\katalog Bohda.pps
2014-05-24 08:53 - 2014-05-24 08:55 - 05795840 _____ () C:\Users\Ali-mini\Downloads\Heb_je_dat_gezien._._.pps
2014-05-23 19:07 - 2014-05-23 19:07 - 00160467 _____ () C:\Users\Ali-mini\Downloads\vy-32-inovace-15lm-veprove-maso.odp
2014-05-23 15:16 - 2014-05-23 15:16 - 00074493 _____ () C:\Users\Ali-mini\Downloads\Fwd_ Fw_ Klíšťata od Vás utečou! Jak na klíšťata a komáry_!ROZEŠLETE VŠEM ZNÁMÝM.eml
2014-05-22 21:18 - 2014-05-22 21:19 - 09610813 _____ () C:\Users\Ali-mini\Downloads\iveta_bartosova_lenka.ppsx
2014-05-22 08:34 - 2014-05-22 08:34 - 04597529 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ Třeste se Češi - Tomáš Klus - nemaž, - čti text, snad ho nezavřou.__.eml
2014-05-21 21:44 - 2014-05-21 21:44 - 06927360 _____ () C:\Users\Ali-mini\Downloads\SAE - Abu Dhabi .pps
2014-05-19 21:58 - 2014-05-19 21:58 - 06627328 _____ () C:\Users\Ali-mini\Downloads\AFGANIST_____N1.pps
2014-05-19 21:55 - 2014-05-19 21:56 - 14800093 _____ () C:\Users\Ali-mini\Downloads\Cowgirls (1).ppsx
2014-05-19 21:53 - 2014-05-19 21:55 - 14800093 _____ () C:\Users\Ali-mini\Downloads\Cowgirls.ppsx
2014-05-19 21:17 - 2014-05-19 21:17 - 02296832 _____ () C:\Users\Ali-mini\Downloads\pelmel_1403 (1).pps
2014-05-19 19:13 - 2014-05-19 19:14 - 06845440 _____ () C:\Users\Ali-mini\Downloads\Ita!lie_italia.pps
2014-05-19 12:47 - 2014-05-19 12:47 - 01371648 _____ () C:\Users\Ali-mini\Downloads\nebud egoista (1).pps
2014-05-18 22:16 - 2014-05-18 22:16 - 02974208 _____ () C:\Users\Ali-mini\Downloads\Klein_beginnt_es (1).pps
2014-05-18 22:15 - 2014-05-18 22:16 - 02974208 _____ () C:\Users\Ali-mini\Downloads\Klein_beginnt_es.pps
2014-05-18 22:02 - 2014-05-18 22:02 - 03545088 _____ () C:\Users\Ali-mini\Downloads\U PRAVOM TRENUTKU(bo) (1).pps
2014-05-18 18:37 - 2014-05-18 18:37 - 07506432 _____ () C:\Users\Ali-mini\Downloads\321308_Victoria2 vervolg1.pps
2014-05-18 17:40 - 2014-05-18 17:40 - 01321337 _____ () C:\Users\Ali-mini\Downloads\VID-20140326-WA0004 (2).mp4
2014-05-18 17:39 - 2014-05-18 17:40 - 01321337 _____ () C:\Users\Ali-mini\Downloads\VID-20140326-WA0004 (1).mp4
2014-05-18 17:38 - 2014-05-18 17:38 - 01321337 _____ () C:\Users\Ali-mini\Downloads\VID-20140326-WA0004.mp4
2014-05-18 16:23 - 2014-05-18 16:24 - 05772800 _____ () C:\Users\Ali-mini\Downloads\Endeavour's_last_flight_[by_MikeRT_scifi_2012[ (1).pps
2014-05-18 11:59 - 2014-05-18 11:59 - 00005319 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ Fwd_ Koupání seniorů v 2025, doufám,že se toho nedožiju._ (1).eml
2014-05-18 11:58 - 2014-05-18 11:58 - 00005319 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ Fwd_ Koupání seniorů v 2025, doufám,že se toho nedožiju._.eml
2014-05-17 17:26 - 2014-05-17 17:27 - 05938176 _____ () C:\Users\Ali-mini\Downloads\Krasavci a krasavice (1).pps
2014-05-17 17:25 - 2014-05-17 17:26 - 05938176 _____ () C:\Users\Ali-mini\Downloads\Krasavci a krasavice.pps
2014-05-17 14:23 - 2014-05-17 14:24 - 05962240 _____ () C:\Users\Ali-mini\Downloads\Park v Arabii-mik (1).pps
2014-05-16 21:41 - 2014-05-16 21:41 - 00037376 _____ () C:\Users\Ali-mini\Downloads\Fleming_a_penicilin (1).pps
2014-05-16 19:06 - 2014-05-16 19:06 - 03443437 _____ () C:\Users\Ali-mini\Downloads\Restaurace.wmv
2014-05-16 19:05 - 2014-05-16 19:05 - 00008107 _____ () C:\Users\Ali-mini\Downloads\attachment.txt
2014-05-16 19:02 - 2014-05-16 19:02 - 06788096 _____ () C:\Users\Ali-mini\Downloads\Poděkování mejlovým přátelům.pps
2014-05-16 08:54 - 2014-05-16 08:54 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-05-16 08:54 - 2014-05-16 08:54 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-05-16 08:04 - 2014-05-16 08:04 - 05561856 _____ () C:\Users\Ali-mini\Downloads\Napoleon palotája.pps
2014-05-15 19:38 - 2014-05-15 19:39 - 09857658 _____ () C:\Users\Ali-mini\Downloads\kocicky_lenka.ppsx
2014-05-15 13:44 - 2014-05-15 13:44 - 01226707 _____ () C:\Users\Ali-mini\Downloads\Klostopfer_....mp4
2014-05-15 08:35 - 2014-05-15 08:35 - 01875456 _____ () C:\Users\Ali-mini\Downloads\POZDRAV OD RADKA._.pps
2014-05-14 19:49 - 2014-05-14 19:49 - 13871616 _____ () C:\Users\Ali-mini\Downloads\MENSEN-IN-NEW-YORK.pps
2014-05-14 16:59 - 2014-05-14 17:00 - 11353600 _____ () C:\Users\Ali-mini\Downloads\ZIEMIA CUDO.PPS
2014-05-14 16:51 - 2014-05-14 16:51 - 08127030 _____ () C:\Users\Ali-mini\Downloads\s-o-s-une-maison-de-carmine.ppsx
2014-05-14 16:48 - 2014-05-14 16:48 - 06326784 _____ () C:\Users\Ali-mini\Downloads\131229[y] .pps
2014-05-14 14:58 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-05-14 14:58 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-05-14 14:58 - 2014-04-11 10:31 - 00049544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-05-14 14:58 - 2014-04-11 10:25 - 00419928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-05-14 14:58 - 2014-04-11 07:22 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-05-14 14:58 - 2014-04-11 07:13 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2014-05-14 14:58 - 2014-04-11 05:41 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2014-05-14 14:58 - 2014-04-11 05:36 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-05-14 14:58 - 2014-04-11 05:06 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-05-14 14:58 - 2014-04-11 05:05 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-14 14:58 - 2014-04-11 05:05 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-05-14 14:58 - 2014-04-11 05:02 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2014-05-14 14:58 - 2014-04-11 05:01 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-05-14 14:58 - 2014-04-11 05:00 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-05-14 14:58 - 2014-04-11 04:59 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-05-14 14:58 - 2014-04-11 04:54 - 02818048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-05-14 14:58 - 2014-04-11 04:47 - 01634304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-05-14 14:58 - 2014-04-11 04:36 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-05-14 14:58 - 2014-04-11 04:34 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-05-14 14:58 - 2014-04-08 20:54 - 00080032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt_map.dll
2014-05-14 14:58 - 2014-04-08 20:54 - 00026784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mrt100.dll
2014-05-14 14:58 - 2014-03-27 09:48 - 18679728 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-05-14 14:58 - 2014-03-24 03:34 - 00219992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-05-14 14:58 - 2014-03-24 03:34 - 00092504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-05-14 14:58 - 2014-03-24 03:33 - 00030224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-05-14 14:58 - 2014-03-13 08:51 - 00305152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wusa.exe
2014-05-14 10:31 - 2014-05-14 10:31 - 01352066 _____ () C:\Users\Ali-mini\Downloads\Az zjistís jak to delá dej vedet.wm
2014-05-14 10:31 - 2014-05-14 10:31 - 01352066 _____ () C:\Users\Ali-mini\Downloads\Az zjistís jak to delá dej vedet (1).wm
2014-05-13 20:02 - 2014-05-13 20:02 - 00209920 _____ () C:\Users\Ali-mini\Downloads\blondynka+kviz33.pps
2014-05-13 19:59 - 2014-05-13 19:59 - 00403968 _____ () C:\Users\Ali-mini\Downloads\sedm nejlepsich poloh.pps
2014-05-13 19:59 - 2014-05-13 19:59 - 00403968 _____ () C:\Users\Ali-mini\Downloads\sedm nejlepsich poloh (1).pps
2014-05-13 16:09 - 2014-05-13 16:09 - 05863467 _____ () C:\Users\Ali-mini\Downloads\Jak se vypíná Cikán v Marseille.wmv
2014-05-13 16:01 - 2014-05-13 16:02 - 05058048 _____ () C:\Users\Ali-mini\Downloads\vasalók.pps
2014-05-13 12:55 - 2014-05-13 12:55 - 02337065 _____ () C:\Users\Ali-mini\Downloads\veleprase (1).mp4
2014-05-13 09:52 - 2014-05-13 09:53 - 07994368 _____ () C:\Users\Ali-mini\Downloads\Reportaz_ze_Slovenska.pps
2014-05-12 21:48 - 2014-05-12 21:48 - 06977024 _____ () C:\Users\Ali-mini\Downloads\Leben_und_leben_lassen.pps
2014-05-12 21:16 - 2014-05-12 21:17 - 07623999 _____ () C:\Users\Ali-mini\Downloads\le-porte-bonheur-de-carmine.ppsx
2014-05-12 20:58 - 2014-05-12 20:58 - 04005399 _____ () C:\Users\Ali-mini\Downloads\l-enfant-et-le-chien-jackdidier.ppsx
2014-05-12 19:57 - 2014-05-12 19:57 - 02337065 _____ () C:\Users\Ali-mini\Downloads\veleprase.mp4
2014-05-12 19:55 - 2014-05-12 19:56 - 05437952 _____ () C:\Users\Ali-mini\Downloads\Realita-sucasnosti.pps
2014-05-12 19:48 - 2014-05-12 19:48 - 00290816 _____ () C:\Users\Ali-mini\Downloads\kalendar_wikipedie (1).xls
2014-05-12 19:46 - 2014-05-12 19:46 - 00290816 _____ () C:\Users\Ali-mini\Downloads\kalendar_wikipedie.xls
2014-05-12 11:42 - 2014-05-12 11:42 - 00823808 _____ () C:\Users\Ali-mini\Downloads\Chyba (1).pps
2014-05-12 10:49 - 2014-05-12 10:49 - 00524800 _____ () C:\Users\Ali-mini\Downloads\10_JÍDEL_SMRTI.pps
2014-05-12 10:29 - 2014-05-12 10:29 - 01762304 _____ () C:\Users\Ali-mini\Downloads\INDIA.pps
2014-05-11 19:56 - 2014-05-11 19:56 - 03957248 _____ () C:\Users\Ali-mini\Downloads\peintures-culinaires-de-hong-yi-une-oeuvre-poetique-et-gourmande.pps
2014-05-11 19:56 - 2014-05-11 19:56 - 03957248 _____ () C:\Users\Ali-mini\Downloads\peintures-culinaires-de-hong-yi-une-oeuvre-poetique-et-gourmande (1).pps
2014-05-11 19:54 - 2014-05-11 19:54 - 03985408 _____ () C:\Users\Ali-mini\Downloads\MAMA1-IT.pps
2014-05-11 19:54 - 2014-05-11 19:54 - 03985408 _____ () C:\Users\Ali-mini\Downloads\MAMA1-IT (1).pps

==================== One Month Modified Files and Folders =======

2014-06-10 13:54 - 2014-06-10 12:42 - 00000000 ____D () C:\Users\Ali-mini\AppData\Local\Temp
2014-06-10 13:52 - 2014-06-10 13:51 - 00014675 _____ () C:\Users\Ali-mini\Desktop\FRST.txt
2014-06-10 13:52 - 2013-10-19 12:34 - 01407017 _____ () C:\WINDOWS\WindowsUpdate.log
2014-06-10 13:51 - 2014-06-10 13:50 - 00000000 ____D () C:\FRST
2014-06-10 13:48 - 2014-06-10 13:48 - 00112640 _____ (forum.viry.cz) C:\Users\Ali-mini\Desktop\FRSTLauncher.exe
2014-06-10 13:44 - 2014-06-10 13:44 - 01177600 _____ (Farbar) C:\Users\Ali-mini\Desktop\FRST.exe
2014-06-10 13:40 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2014-06-10 13:30 - 2013-03-01 14:47 - 00000998 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA.job
2014-06-10 13:27 - 2014-06-10 13:27 - 06794240 _____ () C:\Users\Ali-mini\Downloads\Vse_je_ze_dreva.pps
2014-06-10 13:00 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-06-10 12:46 - 2013-11-20 09:58 - 00000000 __RDO () C:\Users\Ali-mini\SkyDrive
2014-06-10 12:45 - 2014-06-10 12:09 - 00014640 _____ () C:\zoek-results.log
2014-06-10 12:43 - 2014-06-10 12:06 - 00000000 ____D () C:\zoek_backup
2014-06-10 12:43 - 2013-09-29 23:28 - 00003230 _____ () C:\WINDOWS\PFRO.log
2014-06-10 12:43 - 2013-08-22 09:23 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-06-10 12:43 - 2013-08-22 08:13 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-06-10 12:42 - 2014-06-10 12:42 - 00000000 ____D () C:\Users\Default\AppData\Local\Temp
2014-06-10 12:42 - 2014-06-10 12:42 - 00000000 ____D () C:\Users\Default User\AppData\Local\Temp
2014-06-10 12:06 - 2014-06-10 12:42 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-06-10 12:05 - 2014-06-10 12:05 - 01285120 _____ () C:\Users\Ali-mini\Desktop\zoek.exe
2014-06-10 11:56 - 2014-06-10 11:51 - 00000000 ____D () C:\AdwCleaner
2014-06-10 11:49 - 2014-06-10 11:49 - 01333465 _____ () C:\Users\Ali-mini\Desktop\adwcleaner_3.212.exe
2014-06-10 11:37 - 2014-06-10 11:37 - 01686016 _____ () C:\Users\Ali-mini\Downloads\Skoro_neuveritelné_fotky.pps
2014-06-10 11:12 - 2013-12-29 12:35 - 00000000 ____D () C:\Program Files\trend micro
2014-06-10 11:11 - 2014-06-10 11:11 - 01107968 _____ () C:\Users\Ali-mini\Downloads\RSIT (3).exe
2014-06-10 11:11 - 2014-06-10 11:11 - 00781909 _____ () C:\Users\Ali-mini\Downloads\RSIT (2).exe
2014-06-10 11:09 - 2014-06-10 11:09 - 00781909 _____ () C:\Users\Ali-mini\Downloads\RSIT (1).exe
2014-06-10 10:53 - 2014-06-10 10:53 - 09993216 _____ () C:\Users\Ali-mini\Downloads\Unavení... (1).pps
2014-06-10 10:44 - 2014-06-10 10:44 - 09993216 _____ () C:\Users\Ali-mini\Downloads\Unavení....pps
2014-06-10 09:49 - 2013-10-19 12:33 - 01745984 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-06-09 22:41 - 2014-06-09 22:41 - 04012544 _____ () C:\Users\Ali-mini\Downloads\Bramboracka11.pps
2014-06-09 11:53 - 2013-07-09 11:19 - 02162176 ___SH () C:\Users\Ali-mini\Downloads\Thumbs.db
2014-06-09 11:36 - 2014-06-09 11:36 - 09398510 _____ () C:\Users\Ali-mini\Downloads\Křižovatka v Etiopii - návratdoreality.cz[via torchbrowser.com] (2).mp4
2014-06-09 11:36 - 2014-06-09 11:35 - 09398510 _____ () C:\Users\Ali-mini\Downloads\Křižovatka v Etiopii - návratdoreality.cz[via torchbrowser.com] (1).mp4
2014-06-09 11:19 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-06-08 23:23 - 2014-06-08 23:23 - 00971718 _____ () C:\Users\Ali-mini\Downloads\why_women_have_handbags1.mp4
2014-06-08 11:41 - 2014-06-08 11:41 - 00005705 _____ () C:\Users\Ali-mini\Downloads\priloha (1).txt
2014-06-08 11:37 - 2014-06-08 11:36 - 14036185 _____ () C:\Users\Ali-mini\Downloads\Boeren_Power_2.ppsx
2014-06-08 09:30 - 2013-03-01 14:47 - 00000946 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core.job
2014-06-07 13:25 - 2014-06-07 13:25 - 03034624 _____ () C:\Users\Ali-mini\Downloads\Pes_z_pohledu_muze.pps
2014-06-07 08:50 - 2014-06-07 08:50 - 05921261 _____ () C:\Users\Ali-mini\Downloads\1 zanger 2 gezichten.wmv
2014-06-07 08:31 - 2014-06-07 08:31 - 00000000 ____D () C:\Users\Ali-mini\AppData\Roaming\Mozilla
2014-06-06 20:10 - 2014-06-06 20:10 - 04412983 _____ () C:\Users\Ali-mini\Downloads\Pussy-lovers...Jeffy.ppsx
2014-06-06 20:10 - 2014-06-06 20:10 - 00000107 ____H () C:\Users\Ali-mini\Downloads\.~lock.Pussy-lovers...Jeffy.ppsx#
2014-06-06 17:51 - 2014-06-06 17:51 - 00942080 _____ () C:\Users\Ali-mini\Downloads\Tchyne, fotil Saudek.PPS
2014-06-06 13:23 - 2014-06-06 13:23 - 00417792 _____ () C:\Users\Ali-mini\Downloads\sestav_si_puzzle.pps
2014-06-06 12:53 - 2014-06-06 12:53 - 01041408 _____ () C:\Users\Ali-mini\Downloads\Návštěva hřbitova v Itálii (1).pps
2014-06-05 22:50 - 2014-06-05 22:49 - 10802688 _____ () C:\Users\Ali-mini\Downloads\nycstreetphotographermarkushartel.pps
2014-06-05 22:48 - 2014-06-05 22:48 - 04774400 _____ () C:\Users\Ali-mini\Downloads\Nuduri_artistice-Stan_Getz-Bahia_al.pps
2014-06-05 19:10 - 2014-06-05 19:10 - 00055296 _____ () C:\Users\Ali-mini\Downloads\Hadanka - kotatko.pps
2014-06-05 19:10 - 2014-06-05 19:10 - 00055296 _____ () C:\Users\Ali-mini\Downloads\Hadanka - kotatko (1).pps
2014-06-05 17:33 - 2014-06-05 17:33 - 00007806 _____ () C:\Users\Ali-mini\Downloads\Fwd_ Někdo z nás dělá blbce, ale KDO_!!.eml
2014-06-04 22:08 - 2014-06-04 22:08 - 12704256 _____ () C:\Users\Ali-mini\Downloads\60 pohledů z balkonu L H Po.pps
2014-06-04 10:49 - 2014-06-04 10:49 - 03175808 _____ () C:\Users\Ali-mini\Downloads\Praktickydoplnekdoauta.wmv
2014-06-04 10:33 - 2014-06-04 10:33 - 00012296 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ FW_ FW_ Rodina je víc než práce._. je to milé av krátké.eml
2014-06-03 22:37 - 2013-10-19 12:18 - 00000000 ____D () C:\Users\Ali-mini
2014-06-03 21:45 - 2014-06-03 21:44 - 05774027 _____ () C:\Users\Ali-mini\Downloads\Knallerfrauen - Korken1.mp4
2014-06-03 14:22 - 2014-06-03 14:22 - 06357459 _____ () C:\Users\Ali-mini\Downloads\Ashampoo_Snap_2013.01.16_18h57m32s_002_.wmv
2014-06-03 11:31 - 2014-06-03 11:30 - 08557056 _____ () C:\Users\Ali-mini\Downloads\Nostalgie-Schoenes_aus_vergangenen_Zeiten.pps
2014-06-03 11:31 - 2014-06-03 11:30 - 08557056 _____ () C:\Users\Ali-mini\Downloads\Nostalgie-Schoenes_aus_vergangenen_Zeiten (1).pps
2014-06-03 10:12 - 2014-06-03 10:12 - 06104064 _____ () C:\Users\Ali-mini\Downloads\Epoustouflant1.pps
2014-06-02 15:57 - 2014-06-02 15:57 - 00073728 _____ () C:\Users\Ali-mini\Downloads\Schv. Rozpocet vyveska 2014[1] (2).xls
2014-06-02 15:54 - 2014-06-02 15:54 - 00073728 _____ () C:\Users\Ali-mini\Downloads\Schv. Rozpocet vyveska 2014[1].xls
2014-06-02 15:54 - 2014-06-02 15:54 - 00073728 _____ () C:\Users\Ali-mini\Downloads\Schv. Rozpocet vyveska 2014[1] (1).xls
2014-06-02 13:08 - 2014-06-02 13:08 - 01515520 _____ () C:\Users\Ali-mini\Downloads\Skleneny_chodnik_v_Cine.pps
2014-06-02 12:56 - 2014-06-02 12:55 - 04080640 _____ () C:\Users\Ali-mini\Downloads\Fotky2013.pps
2014-06-02 07:31 - 2014-06-02 07:31 - 11055616 _____ () C:\Users\Ali-mini\Downloads\B_fl_devastation-05-2014.pps
2014-06-01 22:23 - 2014-06-01 22:23 - 07481344 _____ () C:\Users\Ali-mini\Downloads\arkadi-ostritsky-1948-israelian-painter-adita.pps
2014-06-01 20:09 - 2014-06-01 20:08 - 06883840 _____ () C:\Users\Ali-mini\Downloads\Tanga.pps
2014-06-01 13:26 - 2014-06-01 13:26 - 02310144 _____ () C:\Users\Ali-mini\Downloads\Luxurie-planes-.pps
2014-06-01 13:23 - 2014-06-01 13:23 - 05496832 _____ () C:\Users\Ali-mini\Downloads\Les-plus-belles-photos-animali-res-de-l-ann-e-2009.pps
2014-06-01 13:21 - 2014-06-01 13:21 - 02830848 _____ () C:\Users\Ali-mini\Downloads\De-minikinis....pps
2014-05-31 22:22 - 2014-05-31 22:22 - 04789764 _____ () C:\Users\Ali-mini\Downloads\Dosekávka kukuřice - neskutečné! (1).mpeg
2014-05-31 22:21 - 2014-05-31 22:21 - 04789764 _____ () C:\Users\Ali-mini\Downloads\Dosekávka kukuřice - neskutečné!.mpeg
2014-05-31 22:17 - 2014-05-31 22:17 - 02841088 _____ () C:\Users\Ali-mini\Downloads\Google.pps
2014-05-30 11:41 - 2014-05-30 11:41 - 07110958 _____ () C:\Users\Ali-mini\Downloads\ProtiromskĂ˝ aktivista.wmv
2014-05-30 11:37 - 2014-05-30 11:36 - 09398510 _____ () C:\Users\Ali-mini\Downloads\Křižovatka v Etiopii - návratdoreality.cz[via torchbrowser.com].mp4
2014-05-30 07:53 - 2014-05-30 07:53 - 07491584 _____ () C:\Users\Ali-mini\Downloads\Ar zinojot kaip jie auga.pps
2014-05-29 21:23 - 2014-05-29 21:22 - 08308224 _____ () C:\Users\Ali-mini\Downloads\Fotky roku 2013 4.MM.pps
2014-05-29 21:16 - 2014-05-29 21:16 - 02267136 _____ () C:\Users\Ali-mini\Downloads\OdvazneMaminy.pps
2014-05-29 19:40 - 2014-05-29 19:40 - 07653376 _____ () C:\Users\Ali-mini\Downloads\De Virtule tuin.pps
2014-05-29 16:50 - 2013-08-22 09:23 - 00290479 _____ () C:\WINDOWS\setupact.log
2014-05-29 14:01 - 2014-05-29 14:01 - 00282112 _____ () C:\Users\Ali-mini\Downloads\super_hadanky (1).pps
2014-05-29 10:04 - 2014-05-29 10:04 - 00097474 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ UŽ MÁŠ POKLADNIČKU NA DUCHOD V EURECH __.eml
2014-05-28 21:18 - 2014-05-28 21:18 - 05318656 _____ () C:\Users\Ali-mini\Downloads\mode2013 (2).pps
2014-05-28 20:55 - 2014-05-28 20:55 - 03351040 _____ () C:\Users\Ali-mini\Downloads\No nepošli to! (1).pps
2014-05-28 19:52 - 2014-05-28 19:52 - 00794624 _____ () C:\Users\Ali-mini\Downloads\Reklamatina XX.pps
2014-05-28 19:51 - 2014-05-28 19:47 - 11286589 _____ () C:\Users\Ali-mini\Downloads\Misty_Miss.ppsx
2014-05-28 12:26 - 2014-05-28 12:26 - 01398784 _____ () C:\Users\Ali-mini\Downloads\Russia (1).pps
2014-05-28 09:55 - 2014-05-28 09:53 - 06927360 _____ () C:\Users\Ali-mini\Downloads\SAE - Abu Dhabi (1).pps
2014-05-27 21:19 - 2014-05-27 21:18 - 05956608 _____ () C:\Users\Ali-mini\Downloads\21 Special Hotel.pps
2014-05-27 19:40 - 2014-05-27 19:39 - 00684544 _____ () C:\Users\Ali-mini\Downloads\Mejte radi svou praci!.pps
2014-05-27 19:29 - 2014-05-27 19:28 - 00203264 _____ () C:\Users\Ali-mini\Downloads\opticky_klam_jencka.pps
2014-05-27 19:28 - 2014-05-27 19:28 - 00000257 _____ () C:\Users\Ali-mini\Downloads\_Certification_ (5).htm
2014-05-27 19:12 - 2014-05-27 19:11 - 03533312 _____ () C:\Users\Ali-mini\Downloads\Co v životě málo kdy spatříte (1).pps
2014-05-27 19:11 - 2014-05-27 19:11 - 03533312 _____ () C:\Users\Ali-mini\Downloads\Co v životě málo kdy spatříte.pps
2014-05-27 16:04 - 2014-05-27 16:04 - 00000000 _____ () C:\WINDOWS\system32\jupdate-1.7.0_55-b14.log
2014-05-27 16:04 - 2013-07-02 08:50 - 00000000 ____D () C:\Program Files\Java
2014-05-27 14:44 - 2014-05-27 14:44 - 04511744 _____ () C:\Users\Ali-mini\Downloads\kava (1).pps
2014-05-27 13:17 - 2014-05-27 13:17 - 04048591 _____ () C:\Users\Ali-mini\Downloads\Zajimavé koupáni.mp4
2014-05-26 20:11 - 2014-05-26 20:10 - 09478144 _____ () C:\Users\Ali-mini\Downloads\50 neobvyklých věcí co o sobě nevíte (1).pps
2014-05-26 20:11 - 2014-05-26 20:09 - 09478144 _____ () C:\Users\Ali-mini\Downloads\50 neobvyklých věcí co o sobě nevíte.pps
2014-05-26 19:18 - 2014-05-26 19:18 - 01565696 _____ () C:\Users\Ali-mini\Downloads\293310_raphlebroc (2).pps
2014-05-26 14:27 - 2014-05-26 14:27 - 01285632 _____ () C:\Users\Ali-mini\Downloads\11_rad_proti_zblazneni_d.pps
2014-05-25 12:23 - 2014-05-25 12:23 - 04701675 _____ () C:\Users\Ali-mini\Downloads\Nemela provokovat.wmv.wmv
2014-05-24 21:14 - 2014-05-24 21:13 - 05708800 _____ () C:\Users\Ali-mini\Downloads\Úžasné.pps
2014-05-24 19:46 - 2014-05-24 19:45 - 12893844 _____ () C:\Users\Ali-mini\Downloads\Romantic_red.ppsx
2014-05-24 09:46 - 2014-05-24 09:46 - 02781721 _____ () C:\Users\Ali-mini\Downloads\beaute-de-jeunesse-madeleine.ppsx
2014-05-24 09:45 - 2014-05-24 09:45 - 06550528 _____ () C:\Users\Ali-mini\Downloads\amazing-3d-street-art-4-day.pps
2014-05-24 09:41 - 2014-05-24 09:41 - 00038912 _____ () C:\Users\Ali-mini\Downloads\Kratke_a_pekne.pps
2014-05-24 09:22 - 2014-05-24 09:22 - 02248192 _____ () C:\Users\Ali-mini\Downloads\katalog Bohda.pps
2014-05-24 08:55 - 2014-05-24 08:53 - 05795840 _____ () C:\Users\Ali-mini\Downloads\Heb_je_dat_gezien._._.pps
2014-05-23 19:07 - 2014-05-23 19:07 - 00160467 _____ () C:\Users\Ali-mini\Downloads\vy-32-inovace-15lm-veprove-maso.odp
2014-05-23 15:16 - 2014-05-23 15:16 - 00074493 _____ () C:\Users\Ali-mini\Downloads\Fwd_ Fw_ Klíšťata od Vás utečou! Jak na klíšťata a komáry_!ROZEŠLETE VŠEM ZNÁMÝM.eml
2014-05-22 21:19 - 2014-05-22 21:18 - 09610813 _____ () C:\Users\Ali-mini\Downloads\iveta_bartosova_lenka.ppsx
2014-05-22 08:34 - 2014-05-22 08:34 - 04597529 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ Třeste se Češi - Tomáš Klus - nemaž, - čti text, snad ho nezavřou.__.eml
2014-05-21 21:44 - 2014-05-21 21:44 - 06927360 _____ () C:\Users\Ali-mini\Downloads\SAE - Abu Dhabi .pps
2014-05-19 21:58 - 2014-05-19 21:58 - 06627328 _____ () C:\Users\Ali-mini\Downloads\AFGANIST_____N1.pps
2014-05-19 21:56 - 2014-05-19 21:55 - 14800093 _____ () C:\Users\Ali-mini\Downloads\Cowgirls (1).ppsx
2014-05-19 21:55 - 2014-05-19 21:53 - 14800093 _____ () C:\Users\Ali-mini\Downloads\Cowgirls.ppsx
2014-05-19 21:17 - 2014-05-19 21:17 - 02296832 _____ () C:\Users\Ali-mini\Downloads\pelmel_1403 (1).pps
2014-05-19 19:14 - 2014-05-19 19:13 - 06845440 _____ () C:\Users\Ali-mini\Downloads\Ita!lie_italia.pps
2014-05-19 12:47 - 2014-05-19 12:47 - 01371648 _____ () C:\Users\Ali-mini\Downloads\nebud egoista (1).pps
2014-05-18 22:16 - 2014-05-18 22:16 - 02974208 _____ () C:\Users\Ali-mini\Downloads\Klein_beginnt_es (1).pps
2014-05-18 22:16 - 2014-05-18 22:15 - 02974208 _____ () C:\Users\Ali-mini\Downloads\Klein_beginnt_es.pps
2014-05-18 22:02 - 2014-05-18 22:02 - 03545088 _____ () C:\Users\Ali-mini\Downloads\U PRAVOM TRENUTKU(bo) (1).pps
2014-05-18 18:37 - 2014-05-18 18:37 - 07506432 _____ () C:\Users\Ali-mini\Downloads\321308_Victoria2 vervolg1.pps
2014-05-18 17:40 - 2014-05-18 17:40 - 01321337 _____ () C:\Users\Ali-mini\Downloads\VID-20140326-WA0004 (2).mp4
2014-05-18 17:40 - 2014-05-18 17:39 - 01321337 _____ () C:\Users\Ali-mini\Downloads\VID-20140326-WA0004 (1).mp4
2014-05-18 17:38 - 2014-05-18 17:38 - 01321337 _____ () C:\Users\Ali-mini\Downloads\VID-20140326-WA0004.mp4
2014-05-18 16:24 - 2014-05-18 16:23 - 05772800 _____ () C:\Users\Ali-mini\Downloads\Endeavour's_last_flight_[by_MikeRT_scifi_2012[ (1).pps
2014-05-18 11:59 - 2014-05-18 11:59 - 00005319 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ Fwd_ Koupání seniorů v 2025, doufám,že se toho nedožiju._ (1).eml
2014-05-18 11:58 - 2014-05-18 11:58 - 00005319 _____ () C:\Users\Ali-mini\Downloads\Fwd_ FW_ Fwd_ Koupání seniorů v 2025, doufám,že se toho nedožiju._.eml
2014-05-17 17:27 - 2014-05-17 17:26 - 05938176 _____ () C:\Users\Ali-mini\Downloads\Krasavci a krasavice (1).pps
2014-05-17 17:26 - 2014-05-17 17:25 - 05938176 _____ () C:\Users\Ali-mini\Downloads\Krasavci a krasavice.pps
2014-05-17 14:24 - 2014-05-17 14:23 - 05962240 _____ () C:\Users\Ali-mini\Downloads\Park v Arabii-mik (1).pps
2014-05-17 09:27 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-05-16 21:41 - 2014-05-16 21:41 - 00037376 _____ () C:\Users\Ali-mini\Downloads\Fleming_a_penicilin (1).pps
2014-05-16 19:06 - 2014-05-16 19:06 - 03443437 _____ () C:\Users\Ali-mini\Downloads\Restaurace.wmv
2014-05-16 19:05 - 2014-05-16 19:05 - 00008107 _____ () C:\Users\Ali-mini\Downloads\attachment.txt
2014-05-16 19:02 - 2014-05-16 19:02 - 06788096 _____ () C:\Users\Ali-mini\Downloads\Poděkování mejlovým přátelům.pps
2014-05-16 09:03 - 2013-08-22 08:13 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-05-16 08:55 - 2013-12-29 13:02 - 00002063 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-05-16 08:54 - 2014-05-16 08:54 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2014-05-16 08:54 - 2014-05-16 08:54 - 00024184 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2014-05-16 08:54 - 2013-12-29 13:01 - 00777488 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2014-05-16 08:54 - 2013-12-29 13:01 - 00411680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys
2014-05-16 08:54 - 2013-12-29 13:01 - 00271264 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2014-05-16 08:54 - 2013-12-29 13:01 - 00180632 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2014-05-16 08:54 - 2013-12-29 13:01 - 00081768 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2014-05-16 08:54 - 2013-12-29 13:01 - 00068312 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswstm.sys
2014-05-16 08:54 - 2013-12-29 13:01 - 00067824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2014-05-16 08:54 - 2013-12-29 13:01 - 00049944 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2014-05-16 08:04 - 2014-05-16 08:04 - 05561856 _____ () C:\Users\Ali-mini\Downloads\Napoleon palotája.pps
2014-05-15 19:39 - 2014-05-15 19:38 - 09857658 _____ () C:\Users\Ali-mini\Downloads\kocicky_lenka.ppsx
2014-05-15 13:44 - 2014-05-15 13:44 - 01226707 _____ () C:\Users\Ali-mini\Downloads\Klostopfer_....mp4
2014-05-15 09:32 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\rescache
2014-05-15 08:35 - 2014-05-15 08:35 - 01875456 _____ () C:\Users\Ali-mini\Downloads\POZDRAV OD RADKA._.pps
2014-05-14 22:53 - 2013-08-22 10:17 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-05-14 22:53 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-14 22:53 - 2013-08-22 10:17 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-14 22:53 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\WinStore
2014-05-14 22:53 - 2013-08-22 10:17 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-14 19:49 - 2014-05-14 19:49 - 13871616 _____ () C:\Users\Ali-mini\Downloads\MENSEN-IN-NEW-YORK.pps
2014-05-14 17:00 - 2014-05-14 16:59 - 11353600 _____ () C:\Users\Ali-mini\Downloads\ZIEMIA CUDO.PPS
2014-05-14 16:51 - 2014-05-14 16:51 - 08127030 _____ () C:\Users\Ali-mini\Downloads\s-o-s-une-maison-de-carmine.ppsx
2014-05-14 16:48 - 2014-05-14 16:48 - 06326784 _____ () C:\Users\Ali-mini\Downloads\131229[y] .pps
2014-05-14 15:15 - 2012-07-26 08:43 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-05-14 15:13 - 2013-08-22 10:17 - 00000000 ____D () C:\WINDOWS\system32\SecureBootUpdates
2014-05-14 15:13 - 2013-08-18 11:53 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-05-14 15:10 - 2013-01-16 14:39 - 90547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-05-14 10:31 - 2014-05-14 10:31 - 01352066 _____ () C:\Users\Ali-mini\Downloads\Az zjistís jak to delá dej vedet.wm
2014-05-14 10:31 - 2014-05-14 10:31 - 01352066 _____ () C:\Users\Ali-mini\Downloads\Az zjistís jak to delá dej vedet (1).wm
2014-05-13 20:02 - 2014-05-13 20:02 - 00209920 _____ () C:\Users\Ali-mini\Downloads\blondynka+kviz33.pps
2014-05-13 19:59 - 2014-05-13 19:59 - 00403968 _____ () C:\Users\Ali-mini\Downloads\sedm nejlepsich poloh.pps
2014-05-13 19:59 - 2014-05-13 19:59 - 00403968 _____ () C:\Users\Ali-mini\Downloads\sedm nejlepsich poloh (1).pps
2014-05-13 16:09 - 2014-05-13 16:09 - 05863467 _____ () C:\Users\Ali-mini\Downloads\Jak se vypíná Cikán v Marseille.wmv
2014-05-13 16:02 - 2014-05-13 16:01 - 05058048 _____ () C:\Users\Ali-mini\Downloads\vasalók.pps
2014-05-13 12:55 - 2014-05-13 12:55 - 02337065 _____ () C:\Users\Ali-mini\Downloads\veleprase (1).mp4
2014-05-13 09:53 - 2014-05-13 09:52 - 07994368 _____ () C:\Users\Ali-mini\Downloads\Reportaz_ze_Slovenska.pps
2014-05-12 21:48 - 2014-05-12 21:48 - 06977024 _____ () C:\Users\Ali-mini\Downloads\Leben_und_leben_lassen.pps
2014-05-12 21:17 - 2014-05-12 21:16 - 07623999 _____ () C:\Users\Ali-mini\Downloads\le-porte-bonheur-de-carmine.ppsx
2014-05-12 20:58 - 2014-05-12 20:58 - 04005399 _____ () C:\Users\Ali-mini\Downloads\l-enfant-et-le-chien-jackdidier.ppsx
2014-05-12 19:57 - 2014-05-12 19:57 - 02337065 _____ () C:\Users\Ali-mini\Downloads\veleprase.mp4
2014-05-12 19:56 - 2014-05-12 19:55 - 05437952 _____ () C:\Users\Ali-mini\Downloads\Realita-sucasnosti.pps
2014-05-12 19:48 - 2014-05-12 19:48 - 00290816 _____ () C:\Users\Ali-mini\Downloads\kalendar_wikipedie (1).xls
2014-05-12 19:46 - 2014-05-12 19:46 - 00290816 _____ () C:\Users\Ali-mini\Downloads\kalendar_wikipedie.xls
2014-05-12 11:42 - 2014-05-12 11:42 - 00823808 _____ () C:\Users\Ali-mini\Downloads\Chyba (1).pps
2014-05-12 10:49 - 2014-05-12 10:49 - 00524800 _____ () C:\Users\Ali-mini\Downloads\10_JÍDEL_SMRTI.pps
2014-05-12 10:29 - 2014-05-12 10:29 - 01762304 _____ () C:\Users\Ali-mini\Downloads\INDIA.pps
2014-05-11 19:56 - 2014-05-11 19:56 - 03957248 _____ () C:\Users\Ali-mini\Downloads\peintures-culinaires-de-hong-yi-une-oeuvre-poetique-et-gourmande.pps
2014-05-11 19:56 - 2014-05-11 19:56 - 03957248 _____ () C:\Users\Ali-mini\Downloads\peintures-culinaires-de-hong-yi-une-oeuvre-poetique-et-gourmande (1).pps
2014-05-11 19:54 - 2014-05-11 19:54 - 03985408 _____ () C:\Users\Ali-mini\Downloads\MAMA1-IT.pps
2014-05-11 19:54 - 2014-05-11 19:54 - 03985408 _____ () C:\Users\Ali-mini\Downloads\MAMA1-IT (1).pps

==================== Bamital & volsnap Check =================

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core.job => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA.job => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Ali-mini\Desktop" je 3 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================


Additional scan result of Farbar Recovery Scan Tool (x86) Version:09-06-2014 03
Ran by Ali-mini at 2014-06-10 13:54:53
Running from C:\Users\Ali-mini\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

Adobe Reader XI - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
AMD APP SDK Runtime (Version: 10.0.851.4 - Advanced Micro Devices Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{9308874E-4CC0-AF26-E0EF-1D675CF96C1B}) (Version: 3.0.859.0 - Advanced Micro Devices, Inc.)
AMD Media Foundation Decoders (Version: 1.0.70207.2312 - Advanced Micro Devices, Inc.) Hidden
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2018 - Avast Software)
calibre (HKLM\...\{AB259D81-DE6B-4554-B4A8-DB13D321FBF2}) (Version: 0.9.18 - Kovid Goyal)
Catalyst Control Center (Version: 2012.0207.2312.41523 - Název společnosti:) Hidden
Catalyst Control Center Graphics Previews Common (Version: 2012.0207.2312.41523 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (Version: 2012.0207.2312.41523 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (Version: 2012.0207.2312.41523 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Profiles Mobile (Version: 2012.0207.2312.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (Version: 2012.0207.2311.41523 - Advanced Micro Devices, Inc.) Hidden
ccc-utility (Version: 2012.0207.2312.41523 - Advanced Micro Devices, Inc.) Hidden
Cisco EAP-FAST Module (HKLM\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
CS Codec Solution 1.10 (HKLM\...\CS Codec Solution_is1) (Version: 1.10 - CS Software)
Dolby Home Theater v4 (HKLM\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.7000.7 - Dolby Laboratories Inc)
FBReader for Windows (HKLM\...\FBReader for Windows) (Version: - )
Google Drive (HKLM\...\{56D4499E-AC3E-4B8D-91C9-C700C148C44B}) (Version: 1.13.5782.599 - Google, Inc.)
Google Chrome (HKLM\...\Google Chrome) (Version: 31.0.1650.63 - Google Inc.)
Google Talk Plugin (HKLM\...\{C1E3DFE7-4EAD-3E9E-A826-E06055BA5921}) (Version: 5.4.2.18903 - Google)
Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden
Instalace ovladačů a aplikací Lenovo (HKLM\...\{45970CD1-D599-47D4-938F-3E9800D54ED1}) (Version: 5.10.1809 - Lenovo)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.37 - Irfan Skiljan)
Java 7 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.450 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
JDownloader 0.9 (HKLM\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Lenovo Blacksilk USB Keyboard Driver (HKLM\...\{B266E062-D6C5-485B-B426-51B152B041A6}) (Version: V1.5.11.0720 - Lenovo)
Lenovo Rescue System (HKLM\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 3.0.1029 - CyberLink Corp.)
Lenovo Rescue System (Version: 3.0.1029 - CyberLink Corp.) Hidden
Lenovo Screensaver (HKLM\...\{803E6DED-5050-4E3D-B26A-5915397362CD}) (Version: 1.0.5.110908 - Lenovo)
LibreOffice 3.6 Help Pack (Czech) (HKLM\...\{A80E9DE9-1D1C-479A-B782-777B7450E0FF}) (Version: 3.6.4.3 - The Document Foundation)
LibreOffice 4.0.1.2 (HKLM\...\{604B2A5C-B1CE-45B2-ADCC-6B7C721AC3AC}) (Version: 4.0.1.2 - The Document Foundation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Odigo (HKLM\...\Odigo) (Version: - )
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.208.0 - Tracker Software Products Ltd)
Picasa 3 (HKLM\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Reader for PC (HKLM\...\{BAE1CCA6-AB32-4D27-AE69-203436D54EC8}) (Version: 2.0.01.11080 - Sony Corporation)
Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.43.321.2011 - Realtek)
Realtek HDMI Audio Driver for ATI (HKLM\...\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6519 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6531 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Reader Driver (HKLM\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7601.39014 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM\...\{9D3D8C60-A55F-4123-B2B9-173F09590E16}) (Version: 1.00.0180 - )
Renesas Electronics USB 3.0 Host Controller Driver (HKLM\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.16.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.1.16.0 - Renesas Electronics Corporation) Hidden
Riot - Radical Image Optimization Tool (HKLM\...\Riot) (Version: - )
Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
Skype Click to Call (HKLM\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation)
StartW8 1.1.34.0 (HKLM\...\{B6ADD537-BDC9-4D2B-B135-01C261D675BC}) (Version: 1.1.34.0 - SODATSW spol. s r. o.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.6.1014 - SUPERAntiSpyware.com)
VLC media player 2.0.5 (HKLM\...\VLC media player) (Version: 2.0.5 - VideoLAN)

==================== Restore Points =========================

25-05-2014 09:02:20 Naplánovaný kontrolní bod
27-05-2014 14:02:54 Installed Java 7 Update 55
03-06-2014 18:49:35 Naplánovaný kontrolní bod
10-06-2014 10:09:15 zoek.exe restore point

==================== Hosts content: ==========================

2013-08-22 08:13 - 2013-08-22 08:13 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {00BC77BF-3352-4FE8-9617-4F1B27BEC19A} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {06408001-3B9D-4D46-ADA1-618188FE2AF9} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {08663139-C721-4846-969F-20AF6BEAE388} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {0ECFA1C3-6CE0-4B58-9424-3354E2A4292C} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-05-16] (AVAST Software)
Task: {1213FCCC-FA35-4AE6-A8ED-4CAB77CC6033} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {17233BE9-87E9-40B0-B003-AE9D2B92CBBE} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {1C0B51C8-622E-4752-AE57-138B5558D91C} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {1EDE60D4-55B3-4E0B-8735-77B31DE02BD7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {247BD142-0549-4E91-84B0-172C25563718} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {2BE65564-89D1-4396-A5CC-D7D9283FC4A1} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {2E027C67-1C00-401E-82D9-31C7EC00880E} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {3922A463-9A2C-4BAA-AFD2-E850170D14E9} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {392EB017-207C-42BF-A061-F3BE721F456C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {477AB3B0-29B9-4867-90FD-F91CF2D75BF6} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4B7EF56A-8A42-4BD2-BB5C-7C389AC54A37} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {5700ACE8-D0AF-4BA7-98B6-1033521A877A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {604AA5C7-C5ED-40F2-87CC-52959CBE2DB3} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6776E4E1-34BD-4606-876C-88F974CD1B83} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {6A08D2F1-77D1-49C0-AB0C-84A6277E5EF1} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {6E84A59B-1863-4B21-8BD8-C9B20FD15484} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {6EC1A983-A401-4381-AE69-F31F9D85ECBF} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {7A887405-409F-4FCB-83DF-5C545DA8D3F4} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7C7CF1DA-F461-4850-96B2-ADCA8A67E59C} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {87CCADA1-CEFB-4AEF-AE08-F59999D52648} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8B3E2506-3B38-44E5-A6F0-B918792B4F6E} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {8B5819AE-7B44-478B-A3D3-8846AF160A8F} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {929D81DB-A2FB-4900-9C99-6ACCC6C23CB9} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {92ED6570-4654-4BFA-9A6C-1084C6939C16} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {9705CABD-61C6-44C8-A6E1-1DFE26832116} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {997C8BBD-710B-4E66-B5BC-CC09575A58D2} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {9FF9E17A-2AA3-40B4-BA09-006AF80F488C} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {A5D45ED3-F524-4574-8F39-527F3729D1E2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\WINDOWS\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {B0AD10AF-D6F5-4FA2-8357-2A1D7E1690B5} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B5127B4A-EE28-4167-A81A-2D5A640DDC06} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: {B7FB5B44-03BC-4BA2-8C2D-60C2C5C334C1} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BC201864-8029-4DE9-9655-12B4224A5623} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-3615216187-194475068-2945929391-1000
Task: {BCFB4913-83ED-417E-AF7D-24B130D71540} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-05-14] (Microsoft Corporation)
Task: {C0D0F7C4-419F-41B3-90A2-FE79270B828A} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {C964F9C1-91FE-425C-9360-43082CF3EA7E} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {CA3A7FFE-9F0C-4CE0-A596-8456C08D72FB} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CF5A1DDC-D14D-4D59-AD49-A19A645B087B} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {D458491D-3D19-49CC-912C-A2701BC75E4D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D6741BA7-0000-4BD0-A083-AF9879AC6C04} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-09] (Google Inc.)
Task: {D7B59B6E-A34B-43C9-AF7A-1E7BA1F3B513} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DCF55BED-B1DF-4ABF-8D85-6542C7007799} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {DF944C7C-7DFF-4156-8CDB-89DE6D83246B} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\WINDOWS\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation)
Task: {E16E7D2E-4E63-4C46-8523-5161FC0BCBB3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-03] (Google Inc.)
Task: {E4C8774A-2818-45A4-8A6D-11DDF6348886} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {ED5D9495-6CB7-4101-B2D6-E4B090161338} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F2180FA3-A409-401D-AD32-F7761A4D5DD6} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe [2013-02-09] (Google Inc.)
Task: {F3D9D704-5BBE-483F-938A-3FB524AE790C} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {FAB49829-3EE7-4234-BE84-277862F2A57C} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {FC508233-E230-47D3-8989-A1EE0ED2F28E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-03] (Google Inc.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core.job => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA.job => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2014-06-10 11:59 - 2014-06-10 11:59 - 02775040 _____ () C:\Program Files\AVAST Software\Avast\defs\14061001\algo.dll
2013-01-03 11:48 - 2011-03-15 21:47 - 00032768 _____ () C:\Windows\jmesoft\Service.exe
2013-01-03 11:48 - 2011-05-17 14:54 - 00024576 _____ () C:\Windows\jmesoft\JME_LOAD.exe
2013-01-03 11:48 - 2011-05-17 14:27 - 00028672 _____ () C:\Windows\jmesoft\hidhook.dll
2013-12-29 13:01 - 2013-12-29 13:01 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-02-05 14:48 - 2007-08-09 14:27 - 00380928 _____ () C:\WINDOWS\SYSTEM32\ac3filter.acm
2013-12-05 09:36 - 2013-12-04 04:47 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libglesv2.dll
2013-12-05 09:36 - 2013-12-04 04:47 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\libegl.dll
2013-12-05 09:36 - 2013-12-04 04:48 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll
2013-12-05 09:36 - 2013-12-04 04:48 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
2013-12-05 09:36 - 2013-12-04 04:47 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Ali-mini\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\Ali-mini\SkyDrive.old:ms-properties
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fwd_ Fwd_ Fwd_ Fwd_ Jeden stobodový vtip pro rodáky z Bechyně !!!.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fwd_ FW_ Fwd_ Fwd_ Fw_ FW_ Klikni na sklenici s utopenci a pak klikej dál_ (1).eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fwd_ FW_ Fwd_ Fwd_ Fw_ FW_ Klikni na sklenici s utopenci a pak klikej dál_.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ Ahoj, prosím nepřekaž to, teď to zrovna moc potřebuju. Myslím, že ty taky_.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ Aspikové vajíčko - Vhodné jako Velikonoční pochoutka_.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ Fwd_ Fw_ Fwd_ humorný horoskop - moc hezke !.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fw_ Fwd_ FW_ FW_ Paříž - takto ji neuvidíš s žádnou cestovní kanceláří.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ Fwd_ Koupání seniorů v 2025, doufám,že se toho nedožiju._ (1).eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ Fwd_ Koupání seniorů v 2025, doufám,že se toho nedožiju._.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fw_ Fwd_ Letecký průkaz - zasílám, aby Ti toho 30.dubna nescházel (1).eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fw_ Fwd_ Letecký průkaz - zasílám, aby Ti toho 30.dubna nescházel.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fw_ Fw[3]_ Absolutně nejlepší, vtip to ale není. ._._._.to budeme jednou utlačovaní.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ FW_ FW_ Rodina je víc než práce._. je to milé av krátké.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fw_ Klíšťata od Vás utečou! Jak na klíšťata a komáry_!ROZEŠLETE VŠEM ZNÁMÝM.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fw_ novinky ve fotkách.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fw_ Přání.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ Recepty - Athénská kuchařka.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ Třeste se Češi - Tomáš Klus - nemaž, - čti text, snad ho nezavřou.__.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ UŽ MÁŠ POKLADNIČKU NA DUCHOD V EURECH __.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Fw_ VELKÁ KUCHAŘKA Ládi Hrušky_ Tady jsou všechny jeho levné recepty - tn.cz.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ FW_ _ Čištění ledvin - jak snadné.__.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Ke kafíčku - mým stárnoucím kamarádům, přátelům a známým .__.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Někdo z nás dělá blbce, ale KDO_!!.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ přání.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Rozdíl mezi kamarádem a přítelem._._._Tak z toho mě úplně mrazí - to nemá chybičku.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Venca jede do Španělska ._.To nemohu neposlat !!! (1).eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Fwd_ Venca jede do Španělska ._.To nemohu neposlat !!!.eml:OECustomProperty
AlternateDataStreams: C:\Users\Ali-mini\Downloads\Pohlednice ze serveru hanulka.cz.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================


==================== EXE Association (whitelisted) =============


==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/10/2014 00:03:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: avastui.exe, verze: 9.0.2018.401, časové razítko: 0x538dfb5f
Název chybujícího modulu: ntdll.dll, verze: 6.3.9600.17031, časové razítko: 0x53088928
Kód výjimky: 0xc0000005
Posun chyby: 0x0004cd34
ID chybujícího procesu: 0x1100
Čas spuštění chybující aplikace: 0xavastui.exe0
Cesta k chybující aplikaci: avastui.exe1
Cesta k chybujícímu modulu: avastui.exe2
ID zprávy: avastui.exe3
Úplný název chybujícího balíčku: avastui.exe4
ID aplikace související s chybujícím balíčkem: avastui.exe5

Error: (06/10/2014 11:08:33 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program LiveComm.exe verze 17.5.9600.20498 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: bec

Čas spuštění: 01cf848a7e143f16

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe

ID hlášení: cac5920b-f07e-11e3-b1a5-50af731f7adf

Úplný název chybujícího balíčku: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe

ID aplikace související s chybujícím balíčkem: ppleae38af2e007f4358a809ac99a64a67c1

Error: (06/10/2014 10:02:24 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program LiveComm.exe verze 17.5.9600.20498 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 5fc

Čas spuštění: 01cf848137710f56

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe

ID hlášení: 84d2a107-f075-11e3-b1a5-50af731f7adf

Úplný název chybujícího balíčku: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe

ID aplikace související s chybujícím balíčkem: ppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 10:12:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program LiveComm.exe verze 17.5.9600.20498 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 600

Čas spuštění: 01cf841e1a6f248b

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe

ID hlášení: 671d697c-f012-11e3-b1a5-50af731f7adf

Úplný název chybujícího balíčku: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe

ID aplikace související s chybujícím balíčkem: ppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 09:12:10 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program LiveComm.exe verze 17.5.9600.20498 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: dcc

Čas spuštění: 01cf8415a68e1d40

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe

ID hlášení: f3699743-f009-11e3-b1a5-50af731f7adf

Úplný název chybujícího balíčku: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe

ID aplikace související s chybujícím balíčkem: ppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 08:45:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program LiveComm.exe verze 17.5.9600.20498 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 17c0

Čas spuštění: 01cf8411eae9aabd

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe

ID hlášení: 37a0a424-f006-11e3-b1a5-50af731f7adf

Úplný název chybujícího balíčku: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe

ID aplikace související s chybujícím balíčkem: ppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 08:04:35 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program LiveComm.exe verze 17.5.9600.20498 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: 9c4

Čas spuštění: 01cf840c3db908c0

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe

ID hlášení: 8292c406-f000-11e3-b1a5-50af731f7adf

Úplný název chybujícího balíčku: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe

ID aplikace související s chybujícím balíčkem: ppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 08:04:31 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program wwahost.exe verze 6.3.9600.17031 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: f00

Čas spuštění: 01cf840d1649e460

Čas ukončení: 4294967295

Cesta k aplikaci: C:\WINDOWS\system32\wwahost.exe

ID hlášení: 7f9eed75-f000-11e3-b1a5-50af731f7adf

Úplný název chybujícího balíčku: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe

ID aplikace související s chybujícím balíčkem: Microsoft.WindowsLive.People

Error: (06/09/2014 08:04:28 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: ALI-MINI-PC)
Description: Balíček microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe+ppleae38af2e007f4358a809ac99a64a67c1 se ukončil, protože jeho pozastavování trvalo moc dlouho.

Error: (06/09/2014 08:04:28 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: ALI-MINI-PC)
Description: Balíček microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe+Microsoft.WindowsLive.People se ukončil, protože jeho pozastavování trvalo moc dlouho.


System errors:
=============
Error: (06/10/2014 00:32:42 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/10/2014 00:32:42 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/10/2014 00:32:41 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/10/2014 00:32:41 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/10/2014 00:32:40 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (06/09/2014 11:09:31 PM) (Source: DCOM) (EventID: 10010) (User: ALI-MINI-PC)
Description: {D63B10C5-BB46-4990-A94F-E40B9D520160}

Error: (06/03/2014 08:13:52 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (17:49:40, ‎3. ‎6. ‎2014) bylo neočekávané.

Error: (06/03/2014 08:48:31 AM) (Source: bowser) (EventID: 8003) (User: )
Description: Hlavní prohledávač přijal oznámení serveru od počítače BJES_DES-PC,
který se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{83292FEF-0F6E-449B-B250-D16494.
Hlavní prohledávač bude ukončen nebo bude vyvolána volba.

Error: (06/01/2014 11:25:13 PM) (Source: DCOM) (EventID: 10010) (User: ALI-MINI-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}

Error: (06/01/2014 11:25:13 PM) (Source: DCOM) (EventID: 10010) (User: ALI-MINI-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}


Microsoft Office Sessions:
=========================
Error: (06/10/2014 00:03:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: avastui.exe9.0.2018.401538dfb5fntdll.dll6.3.9600.1703153088928c00000050004cd34110001cf8493087b4c55C:\Program Files\AVAST Software\Avast\avastui.exeC:\WINDOWS\SYSTEM32\ntdll.dll77358882-f086-11e3-b1a6-50af731f7adf

Error: (06/10/2014 11:08:33 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.20498bec01cf848a7e143f164294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.execac5920b-f07e-11e3-b1a5-50af731f7adfmicrosoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (06/10/2014 10:02:24 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.204985fc01cf848137710f564294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe84d2a107-f075-11e3-b1a5-50af731f7adfmicrosoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 10:12:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.2049860001cf841e1a6f248b4294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe671d697c-f012-11e3-b1a5-50af731f7adfmicrosoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 09:12:10 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.20498dcc01cf8415a68e1d404294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exef3699743-f009-11e3-b1a5-50af731f7adfmicrosoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 08:45:26 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.2049817c001cf8411eae9aabd4294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe37a0a424-f006-11e3-b1a5-50af731f7adfmicrosoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 08:04:35 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.204989c401cf840c3db908c04294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe\LiveComm.exe8292c406-f000-11e3-b1a5-50af731f7adfmicrosoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 08:04:31 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.17031f0001cf840d1649e4604294967295C:\WINDOWS\system32\wwahost.exe7f9eed75-f000-11e3-b1a5-50af731f7adfmicrosoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbweMicrosoft.WindowsLive.People

Error: (06/09/2014 08:04:28 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: ALI-MINI-PC)
Description: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe+ppleae38af2e007f4358a809ac99a64a67c1

Error: (06/09/2014 08:04:28 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: ALI-MINI-PC)
Description: microsoft.windowscommunicationsapps_17.5.9600.20498_x86__8wekyb3d8bbwe+Microsoft.WindowsLive.People


CodeIntegrity Errors:
===================================
Date: 2013-10-19 12:34:56.994
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Definition Updates\{CF8EB320-9C63-46D7-8994-4C4E988AD974}\mpengine.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2013-10-19 12:34:55.806
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Definition Updates\{FB7F764A-08DE-4BE1-BF69-AAB61A3D3C8B}\mpengine.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Percentage of memory in use: 54%
Total physical RAM: 2043.08 MB
Available physical RAM: 936.15 MB
Total Pagefile: 4091.08 MB
Available Pagefile: 2538.42 MB
Total Virtual: 2047.88 MB
Available Virtual: 1865.91 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:426.04 GB) (Free:368.78 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: C3FFC3FF)
Partition 1: (Active) - (Size=15 GB) - (Type=0C)
Partition 2: (Not Active) - (Size=426 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=25 GB) - (Type=12)

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nevyžádaná připojení k herním serverům

#6 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
    HKU\S-1-5-21-3615216187-194475068-2945929391-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [4763008 2012-11-01] (SUPERAntiSpyware.com)
    HKU\S-1-5-21-3615216187-194475068-2945929391-1000\...\Run: [Google Update] => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-02-09] (Google Inc.)
    
    SearchScopes: HKLM - DefaultScope value is missing.
    
    CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
    
    DisableService: c2cautoupdatesvc
    DisableService: c2cpnrsvc
    
    2014-06-10 13:48 - 2014-06-10 13:48 - 00112640 _____ (forum.viry.cz) C:\Users\Ali-mini\Desktop\FRSTLauncher.exe
    2014-06-10 12:42 - 2014-06-10 12:06 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
    2014-06-10 12:09 - 2014-06-10 12:45 - 00014640 _____ () C:\zoek-results.log
    2014-06-10 12:06 - 2014-06-10 12:43 - 00000000 ____D () C:\zoek_backup
    2014-06-10 12:05 - 2014-06-10 12:05 - 01285120 _____ () C:\Users\Ali-mini\Desktop\zoek.exe
    2014-06-10 11:54 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll
    2014-06-10 11:51 - 2014-06-10 11:56 - 00000000 ____D () C:\AdwCleaner
    2014-06-10 11:49 - 2014-06-10 11:49 - 01333465 _____ () C:\Users\Ali-mini\Desktop\adwcleaner_3.212.exe
    
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core.job => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA.job => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe
    
    Hosts:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kej.alin
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 pro 2013 11:31

Re: Nevyžádaná připojení k herním serverům

#7 Příspěvek od kej.alin »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:09-06-2014 03
Ran by Ali-mini at 2014-06-10 20:52:41 Run:1
Running from C:\Users\Ali-mini\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-3615216187-194475068-2945929391-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [4763008 2012-11-01] (SUPERAntiSpyware.com)
HKU\S-1-5-21-3615216187-194475068-2945929391-1000\...\Run: [Google Update] => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-02-09] (Google Inc.)

SearchScopes: HKLM - DefaultScope value is missing.

CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]

DisableService: c2cautoupdatesvc
DisableService: c2cpnrsvc

2014-06-10 13:48 - 2014-06-10 13:48 - 00112640 _____ (forum.viry.cz) C:\Users\Ali-mini\Desktop\FRSTLauncher.exe
2014-06-10 12:42 - 2014-06-10 12:06 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-06-10 12:09 - 2014-06-10 12:45 - 00014640 _____ () C:\zoek-results.log
2014-06-10 12:06 - 2014-06-10 12:43 - 00000000 ____D () C:\zoek_backup
2014-06-10 12:05 - 2014-06-10 12:05 - 01285120 _____ () C:\Users\Ali-mini\Desktop\zoek.exe
2014-06-10 11:54 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\system32\sqlite3.dll
2014-06-10 11:51 - 2014-06-10 11:56 - 00000000 ____D () C:\AdwCleaner
2014-06-10 11:49 - 2014-06-10 11:49 - 01333465 _____ () C:\Users\Ali-mini\Desktop\adwcleaner_3.212.exe

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core.job => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA.job => C:\Users\Ali-mini\AppData\Local\Google\Update\GoogleUpdate.exe

Hosts:
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKU\S-1-5-21-3615216187-194475068-2945929391-1000\Software\Microsoft\Windows\CurrentVersion\Run\\SUPERAntiSpyware => value deleted successfully.
HKU\S-1-5-21-3615216187-194475068-2945929391-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
'HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl' => Key deleted successfully.
C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx => Moved successfully.
c2cautoupdatesvc service was disabled
c2cpnrsvc service was disabled
C:\Users\Ali-mini\Desktop\FRSTLauncher.exe => Moved successfully.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Ali-mini\Desktop\zoek.exe => Moved successfully.
C:\WINDOWS\system32\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Ali-mini\Desktop\adwcleaner_3.212.exe => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000Core.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3615216187-194475068-2945929391-1000UA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nevyžádaná připojení k herním serverům

#8 Příspěvek od vyosek »

Jak se chova PC???
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kej.alin
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 pro 2013 11:31

Re: Nevyžádaná připojení k herním serverům

#9 Příspěvek od kej.alin »

Žádné problémy, celkem svižně. Je možné, že to souvisí s PC, se kterým je zapojen v síti? Ten jde přes kabel a tento, ze kterého píšu, jde přes wi-fi.
Pro upřesnění. Ta připojení, která jsem zkopíroval na začátku vlákna, se mi ukazují na PC, připojeném přímo na net. Ale u každého připojení se objeví roletka, která po rozevření ukazuje na PC, ze kterého jsem odesílal logy.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nevyžádaná připojení k herním serverům

#10 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Pokud bude problem na PC, tak na nej zalozte nove tema a do predmetu dejte "pro vyosek"
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

kej.alin
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 pro 2013 11:31

Re: Nevyžádaná připojení k herním serverům

#11 Příspěvek od kej.alin »

Hotovo, díky, v případě opakování závady se ozvu z druhého PC. Hezký večer!

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nevyžádaná připojení k herním serverům

#12 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek

A na zaklade Pravidla o zamykani temat :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno