Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

zelene pismenka - odkazy

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Laba
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 25 čer 2014 18:16

zelene pismenka - odkazy

#1 Příspěvek od Laba »

Dobry den, par dni mam problem, ze sa mi v prehlaidacoch zobrazuju casti slov alebo cele slova v zelenej farbe, podciarknute a ked na nich podrzim mys sprava sa to ako odkaz. Preinastaloval som prehliadace (IE aj Operu) a precistil CCleanerom..... neviem ako pokracovat dalej.
Dakujem za odpoved.

pripajam aj obrazok

LOG:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Laba at 2014-06-25 19:11:57
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 213 GB (45%) free of 475 GB
Total RAM: 3894 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:12:02, on 25. 6. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17126)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera_crashreporter.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe
C:\Program Files\trend micro\Laba.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securedsearch2.lavasoft.com/inde ... 53AAF6EA5F
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Amazon 1Button App for IE - {26B19FA4-E8A1-4A1B-A163-1A1E46F830DD} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Search Protection] C:\ProgramData\Search Protection\SearchProtection.exe
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [icq] C:\Users\Laba\AppData\Roaming\ICQM\icq.exe -CU
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Download with Mipony - file://C:\Users\Laba\Desktop\MiPony\Browser\IEContext.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Laba\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Laba\AppData\Roaming\ICQM\icq.exe (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: ArcGIS License Manager - Acresso Software Inc. - C:\Program Files (x86)\ArcGIS\License10.0\bin\lmgrd.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - Hewlett-Packard Company - C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Network HTTP Support Service (NetHttpService) - Unknown owner - C:\Windows\SysWOW64\nethtsrv.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - The OpenVPN Project - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Network Support Service Updater (ServiceUpdater) - Unknown owner - C:\Windows\SysWOW64\netupdsrv.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10129 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10742 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\vcsFPService.exe
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\system32\WLANExt.exe 27438496
\??\C:\Windows\system32\conhost.exe "-19165015731580267290-529007912-432292775-1719453431505961284-371262077860580359
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\ArcGIS\License10.0\bin\lmgrd.exe"
\??\C:\Windows\system32\conhost.exe "4785889374139097341472494687-1126326350-789025216623414689-1535912632924432814
"c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\ArcGIS\License10.0\bin\lmgrd.exe" -c "C:\Program Files (x86)\ArcGIS\License10.0\bin\service.txt" -l "C:\Program Files (x86)\ArcGIS\License10.0\bin\lmgrd9.log" -z -local
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe"
ARCGIS.exe -T Mantel-PC 11.6 -1 -c "C:\Program Files (x86)\ArcGIS\License10.0\bin\service.txt" -lmgrd_port 6978 --lmgrd_start 53aafabe -l "C:\Program Files (x86)\ArcGIS\License10.0\bin\lmgrd9.log"
C:\Windows\SysWOW64\nethtsrv.exe
C:\Windows\SysWOW64\netupdsrv.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\IDT\WDM\sttray64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"c:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --ran-launcher /crash-reporter-parent-id=860
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --type=gpu-process --channel="860.0.374122682\1330541548" --crash-reporter-pid=3008 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,15 --gpu-vendor-id=0x1002 --gpu-device-id=0x68c1 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.771.1.0 --crash-reporter-pid=3008 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=sk --extension-process --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3008 --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="860.2.1064550662\1266612488" /prefetch:673131151
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=sk --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3008 --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="860.4.1180199378\1993737371" /prefetch:673131151
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=sk --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3008 --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="860.5.769087229\1947484131" /prefetch:673131151
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=sk --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3008 --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="860.6.1290927186\874036485" /prefetch:673131151
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=sk --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3008 --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="860.7.2053257652\74826093" /prefetch:673131151
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe" /hidden
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll" --lang=sk --channel="860.17.106880784\692594229" --crash-reporter-pid=3008 /prefetch:-390060480
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe" "<hpNotification><Toast><Title>HP Wireless Assistant</Title><Text>Bluetooth®: On
WLAN: On</Text><IconPath>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WA_tray_32_on.ico</IconPath><ID>2071920792</ID><Path>C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe</Path><Parameters></Parameters></Toast></hpNotification>"
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -critical
"C:\Program Files (x86)\Opera\22.0.1471.70_0\opera.exe" --type=renderer --disable-direct-npapi-requests --lang=sk --disable-client-side-phishing-detection --with-feature:enhanced-autofill --crash-reporter-pid=3008 --enable-threaded-compositing --enable-delegated-renderer --enable-software-compositing --channel="860.52.2111387375\812037888" /prefetch:673131151

"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\Laba\Downloads\RSITx64.exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\AmiUpdXp.job - C:\Users\Laba\AppData\Local\SwvUpdater\Updater.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-10-29 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-10-29 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray64.exe [2010-07-22 487424]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-09-13 2281256]
"HPWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe [2010-04-23 8192]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-07-27 161304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-07-27 386584]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-07-27 415256]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
"icq"=C:\Users\Laba\AppData\Roaming\ICQM\icq.exe [2013-09-18 28698984]
""= []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-05-11 958576]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-04-13 284696]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"Search Protection"=C:\ProgramData\Search Protection\SearchProtection.exe []
"StartCCC"=c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-09-09 98304]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-07-28 271360]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-06-25 19:11:58 ----D---- C:\Program Files\trend micro
2014-06-25 19:11:57 ----D---- C:\rsit
2014-06-25 18:42:24 ----A---- C:\awh12B5.tmp
2014-06-25 18:34:51 ----SHD---- C:\Config.Msi
2014-06-25 18:27:16 ----D---- C:\Users\Laba\AppData\Roaming\Lavasoft
2014-06-25 18:21:21 ----A---- C:\prefs.js
2014-06-25 18:16:04 ----A---- C:\awh1100.tmp
2014-06-25 15:10:19 ----A---- C:\awh27DA.tmp
2014-06-25 06:55:47 ----A---- C:\awh1E49.tmp
2014-06-24 22:14:26 ----A---- C:\awh1959.tmp
2014-06-24 14:40:17 ----A---- C:\awh315C.tmp
2014-06-23 15:47:27 ----A---- C:\awh1A91.tmp
2014-06-23 06:13:44 ----A---- C:\awh2F59.tmp
2014-06-22 20:13:19 ----A---- C:\awh4F47.tmp
2014-06-20 08:11:44 ----A---- C:\Windows\system32\drivers\nethfdrv.sys
2014-06-20 08:11:28 ----A---- C:\Windows\SYSWOW64\netupdsrv.exe
2014-06-20 08:11:18 ----A---- C:\Windows\SYSWOW64\installd.exe
2014-06-20 08:11:08 ----A---- C:\Windows\SYSWOW64\nethtsrv.exe
2014-06-20 08:10:58 ----A---- C:\Windows\SYSWOW64\hfnapi.dll
2014-06-20 08:10:48 ----A---- C:\Windows\SYSWOW64\hfpapi.dll
2014-06-18 18:26:31 ----D---- C:\ProgramData\KONAMI
2014-06-17 10:40:09 ----D---- C:\ProgramData\Origin
2014-06-17 10:39:28 ----A---- C:\Windows\system32\d3dx10_40.dll
2014-06-15 17:48:24 ----N---- C:\Windows\SYSWOW64\iyvu9_32.dll
2014-06-15 17:48:24 ----N---- C:\Windows\SYSWOW64\iacenc.dll
2014-06-12 11:16:11 ----A---- C:\Windows\SYSWOW64\usp10.dll
2014-06-12 11:16:11 ----A---- C:\Windows\system32\usp10.dll
2014-06-12 11:16:11 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-06-12 11:16:10 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2014-06-12 11:16:10 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2014-06-12 11:16:10 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2014-06-12 11:16:10 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2014-06-12 11:16:10 ----A---- C:\Windows\system32\msxml6r.dll
2014-06-12 11:16:10 ----A---- C:\Windows\system32\msxml6.dll
2014-06-12 11:16:10 ----A---- C:\Windows\system32\msxml3r.dll
2014-06-12 11:16:10 ----A---- C:\Windows\system32\msxml3.dll
2014-06-12 11:16:10 ----A---- C:\Windows\system32\drivers\netio.sys
2014-06-12 11:16:10 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-06-12 11:16:09 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-06-12 11:16:09 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-06-12 11:16:09 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-06-12 11:16:08 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-06-12 11:16:08 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-06-12 11:16:08 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-06-12 11:16:08 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-06-12 11:16:08 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-06-12 11:16:08 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 11:16:08 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-06-12 11:16:06 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-06-12 11:16:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-06-12 11:16:06 ----A---- C:\Windows\system32\urlmon.dll
2014-06-12 11:16:05 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-06-12 11:16:05 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-06-12 11:16:05 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-06-12 11:16:05 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-06-12 11:16:05 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-06-12 11:16:05 ----A---- C:\Windows\system32\msfeeds.dll
2014-06-12 11:16:05 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 11:16:05 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-06-12 11:16:05 ----A---- C:\Windows\system32\dxtmsft.dll
2014-06-12 11:16:03 ----A---- C:\Windows\system32\iesetup.dll
2014-06-12 11:16:03 ----A---- C:\Windows\system32\ie4uinit.exe
2014-06-12 11:16:02 ----A---- C:\Windows\system32\iertutil.dll
2014-06-12 11:16:01 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-06-12 11:16:01 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-06-12 11:16:01 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-06-12 11:16:01 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-06-12 11:16:01 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-06-12 11:16:01 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-06-12 11:16:00 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-06-12 11:16:00 ----A---- C:\Windows\system32\jsproxy.dll
2014-06-12 11:16:00 ----A---- C:\Windows\system32\ieui.dll
2014-06-12 11:16:00 ----A---- C:\Windows\system32\iernonce.dll
2014-06-12 11:16:00 ----A---- C:\Windows\system32\dxtrans.dll
2014-06-12 11:15:59 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-06-12 11:15:59 ----A---- C:\Windows\system32\mshtmled.dll
2014-06-12 11:15:59 ----A---- C:\Windows\system32\ieframe.dll
2014-06-12 11:15:58 ----A---- C:\Windows\system32\vbscript.dll
2014-06-12 11:15:58 ----A---- C:\Windows\system32\jscript9diag.dll
2014-06-12 11:15:58 ----A---- C:\Windows\system32\jscript9.dll
2014-06-12 11:15:58 ----A---- C:\Windows\system32\ieUnatt.exe
2014-06-12 11:15:57 ----A---- C:\Windows\system32\wininet.dll
2014-06-12 11:15:57 ----A---- C:\Windows\system32\ieapfltr.dll
2014-06-12 11:15:56 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 11:15:56 ----A---- C:\Windows\system32\msrating.dll
2014-06-12 11:15:55 ----A---- C:\Windows\system32\mshtml.dll
2014-06-12 11:14:30 ----A---- C:\Windows\system32\aepdu.dll
2014-06-12 11:14:29 ----A---- C:\Windows\system32\aeinv.dll
2014-05-29 18:06:59 ----D---- C:\ProgramData\ATI
2014-05-29 18:02:14 ----A---- C:\Windows\SYSWOW64\atipblup.dat
2014-05-29 18:02:14 ----A---- C:\Windows\system32\atipblup.dat
2014-05-29 17:49:05 ----D---- C:\Program Files\Common Files\Intel
2014-05-29 16:35:49 ----D---- C:\Program Files (x86)\AMD APP
2014-05-29 16:05:50 ----N---- C:\Windows\SYSWOW64\ir41_32.dll

======List of files/folders modified in the last 1 month======

2014-06-25 19:12:00 ----D---- C:\Windows\Temp
2014-06-25 19:11:58 ----RD---- C:\Program Files
2014-06-25 18:42:58 ----D---- C:\Windows\System32
2014-06-25 18:42:58 ----D---- C:\Windows\inf
2014-06-25 18:42:58 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-06-25 18:41:01 ----D---- C:\Windows\system32\config
2014-06-25 18:39:32 ----A---- C:\Windows\SYSWOW64\log.txt
2014-06-25 18:36:58 ----HD---- C:\ProgramData
2014-06-25 18:36:02 ----SHD---- C:\Windows\Installer
2014-06-25 18:35:18 ----D---- C:\Program Files\Common Files
2014-06-25 18:34:55 ----D---- C:\Windows\system32\drivers
2014-06-25 18:34:32 ----SHD---- C:\System Volume Information
2014-06-25 18:28:10 ----RD---- C:\Program Files (x86)
2014-06-25 18:28:10 ----D---- C:\Program Files (x86)\Lavasoft
2014-06-25 18:22:37 ----D---- C:\Windows\system32\DriverStore
2014-06-25 18:10:53 ----D---- C:\Windows
2014-06-25 18:10:40 ----D---- C:\Program Files (x86)\MediaViewV1
2014-06-25 16:17:39 ----D---- C:\Windows\system32\Tasks
2014-06-25 16:15:27 ----D---- C:\Users\Laba\AppData\Roaming\DAEMON Tools Lite
2014-06-25 16:15:26 ----D---- C:\Users\Laba\AppData\Roaming\uTorrent
2014-06-25 16:15:23 ----D---- C:\Windows\Panther
2014-06-25 16:15:22 ----D---- C:\Windows\Minidump
2014-06-25 16:15:22 ----D---- C:\Windows\Logs
2014-06-25 16:15:22 ----D---- C:\Windows\debug
2014-06-25 16:12:54 ----D---- C:\Windows\Tasks
2014-06-25 16:12:52 ----D---- C:\Program Files (x86)\Google
2014-06-25 16:05:08 ----D---- C:\Users\Laba\AppData\Roaming\Opera Software
2014-06-25 16:05:02 ----D---- C:\Program Files (x86)\Opera
2014-06-24 15:18:41 ----D---- C:\Users\Laba\AppData\Roaming\Skype
2014-06-23 20:43:57 ----D---- C:\Users\Laba\AppData\Roaming\vlc
2014-06-22 20:08:06 ----D---- C:\Windows\SysWOW64
2014-06-22 20:08:06 ----D---- C:\Program Files (x86)\Common Files
2014-06-19 10:31:27 ----D---- C:\Windows\system32\catroot2
2014-06-18 18:26:31 ----D---- C:\HRY
2014-06-17 10:39:05 ----RSD---- C:\Windows\assembly
2014-06-15 21:27:12 ----D---- C:\Windows\LiveKernelReports
2014-06-15 17:39:21 ----D---- C:\Windows\Prefetch
2014-06-15 09:56:35 ----D---- C:\Windows\rescache
2014-06-12 20:28:23 ----D---- C:\ProgramData\Skype
2014-06-12 20:14:05 ----D---- C:\Windows\winsxs
2014-06-12 20:12:16 ----D---- C:\Windows\SYSWOW64\en-US
2014-06-12 20:12:16 ----D---- C:\Program Files\Internet Explorer
2014-06-12 20:12:15 ----D---- C:\Windows\system32\en-US
2014-06-12 20:12:14 ----D---- C:\Program Files (x86)\Internet Explorer
2014-06-12 16:12:44 ----D---- C:\Windows\system32\MRT
2014-06-12 16:11:29 ----A---- C:\Windows\system32\MRT.exe
2014-06-12 16:10:06 ----SD---- C:\Windows\system32\CompatTel
2014-06-12 11:14:23 ----D---- C:\Windows\system32\catroot
2014-05-29 18:04:18 ----D---- C:\Program Files\ATI Technologies
2014-05-29 18:03:54 ----D---- C:\Program Files (x86)\ATI Technologies
2014-05-29 18:03:27 ----D---- C:\Windows\Microsoft.NET
2014-05-29 18:00:40 ----D---- C:\Program Files\ATI
2014-05-29 17:49:01 ----D---- C:\Program Files (x86)\Intel
2014-05-29 17:44:20 ----D---- C:\Intel
2014-05-29 17:42:36 ----D---- C:\swsetup
2014-05-29 17:18:14 ----D---- C:\Program Files (x86)\Hewlett-Packard
2014-05-29 17:18:13 ----D---- C:\Program Files (x86)\HP
2014-05-29 16:10:37 ----RSD---- C:\Windows\Fonts
2014-05-28 18:26:19 ----RD---- C:\Program Files (x86)\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 hpdskflt;HP Filter; C:\Windows\system32\DRIVERS\hpdskflt.sys [2011-05-13 30008]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-04-13 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2012-04-22 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-06-09 283200]
R1 nethfdrv;nethfdrv; \??\C:\Windows\system32\drivers\nethfdrv.sys [2014-06-20 46160]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2012-04-22 60416]
R3 Accelerometer;HP Mobile Data Protection Sensor; C:\Windows\system32\DRIVERS\Accelerometer.sys [2011-05-13 43320]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-09-08 7767552]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-09-08 279040]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2011-02-22 2736640]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2012-05-14 96896]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2012-04-22 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2012-04-22 80384]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-01-07 98344]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-01-07 132648]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-01-07 35104]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-01-07 21160]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys [2010-02-26 158976]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [2010-07-27 10610400]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 STHDA;@%SystemRoot%\system32\stlang64.dll,-10329; C:\Windows\system32\DRIVERS\stwrt64.sys [2010-07-22 515584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-09-13 1390640]
R3 tap0901;TAP-Windows Adapter V9; C:\Windows\system32\DRIVERS\tap0901.sys [2013-02-08 36736]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2012-04-22 18432]
R3 WinUSB;WinUSB Service; C:\Windows\system32\DRIVERS\WinUSB.sys [2010-11-21 41984]
S3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-05 125456]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-07-28 10610400]
S3 iscFlash;iscFlash; \??\c:\SwSetup\SP55299\iscflashx64.sys []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2010-01-11 232992]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-24 344680]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-05-11 65640]
R2 AESTFilters;Andrea ST Filters Service; C:\Program Files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-09-08 203264]
R2 ArcGIS License Manager;ArcGIS License Manager; C:\Program Files (x86)\ArcGIS\License10.0\bin\lmgrd.exe [2008-11-06 1500424]
R2 btwdins;Bluetooth Service; c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-12-29 873248]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-04-23 103992]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-05-21 103992]
R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [2011-05-13 30520]
R2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [2014-05-21 49464]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-05-01 325656]
R2 NetHttpService;Network HTTP Support Service; C:\Windows\SysWOW64\nethtsrv.exe [2014-06-20 180736]
R2 ServiceUpdater;Network Support Service Updater; C:\Windows\SysWOW64\netupdsrv.exe [2014-06-20 162304]
R2 STacSV;@%SystemRoot%\system32\stlang64.dll,-10129; C:\Program Files\IDT\WDM\STacSV64.exe [2010-07-22 263168]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-05-01 2533400]
R2 vcsFPService;Validity VCS Fingerprint Service; C:\Windows\system32\vcsFPService.exe [2010-02-23 2192176]
R3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2013-10-15 867080]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-05-21 818232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-13 257712]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-05-30 111616]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2013-03-07 34528]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-05-20 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------
Přílohy
obrazok
obrazok
Bez názvu.png (103.77 KiB) Zobrazeno 1271 x

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zelene pismenka - odkazy

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji

Vas log se studuje Obrázek a pracuje se na nem Obrázek.
Prosim o strpeni!Obrázek
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zelene pismenka - odkazy

#3 Příspěvek od vyosek »

:arrow: Je to klasicky otravny reklamni SW, zrejme se nainstaloval s nejakym dalsim SW :?:

:arrow: Ale neni tak tezke se toho zbavit :idea:

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Laba
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 25 čer 2014 18:16

Re: zelene pismenka - odkazy

#4 Příspěvek od Laba »

Dakujem za skoru odpoved tak tu je JRT zatial :)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Laba on st 25. 06. 2014 at 19:42:18,29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\search protection
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\distromatic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\systweak
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updater.amiupd.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{99c91fc5-db5b-4aa0-bb70-5d89c5a4df96}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}



~~~ Files

Successfully deleted: [File] C:\Windows\Tasks\amiupdxp.job



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Laba\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\Laba\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Program Files (x86)\regclean pro"
Successfully deleted: [Folder] "C:\Program Files (x86)\videoplayerv3"
Successfully deleted: [Folder] "C:\Program Files (x86)\webexpenhancedv1"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 25. 06. 2014 at 19:51:50,60
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zelene pismenka - odkazy

#5 Příspěvek od vyosek »

OuKej, pokracujte AdwCleanerem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Laba
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 25 čer 2014 18:16

Re: zelene pismenka - odkazy

#6 Příspěvek od Laba »

a tu ADW...


# AdwCleaner v3.213 - Report created 25/06/2014 at 19:55:38
# Updated 23/06/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Laba - MANTEL-PC
# Running from : C:\Users\Laba\Desktop\adwcleaner_3.213.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\FileCure
Folder Deleted : C:\Program Files (x86)\MediaPlayerV1
Folder Deleted : C:\Program Files (x86)\MediaViewerV1
Folder Deleted : C:\Program Files (x86)\MediaViewV1
Folder Deleted : C:\Program Files (x86)\MediaWatchV1
Folder Deleted : C:\Program Files (x86)\RichMediaViewV1
Folder Deleted : C:\Program Files (x86)\Systweak Support Dock
Folder Deleted : C:\Users\Laba\AppData\Local\PackageAware
Folder Deleted : C:\Users\Laba\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Laba\AppData\Roaming\SecureSearch
File Deleted : C:\Windows\System32\roboot64.exe

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [12x3q@3244516.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [ext@bettersurfplus.com]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [xz123@ya456.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dedmngkbaffkenlfdcbganndoghblmap
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\poheodfamflhhhdcmjfeggbgigeefaco
Key Deleted : HKCU\Software\Classes\pokki
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
Key Deleted : HKCU\Software\ParetoLogic
Key Deleted : HKLM\Software\BetterSurf
Key Deleted : HKLM\Software\ParetoLogic
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17126


*************************

AdwCleaner[R0].txt - [2585 octets] - [25/06/2014 19:54:20]
AdwCleaner[S0].txt - [2503 octets] - [25/06/2014 19:55:38]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2563 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zelene pismenka - odkazy

#7 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Laba
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 25 čer 2014 18:16

Re: zelene pismenka - odkazy

#8 Příspěvek od Laba »

Zoek.exe v5.0.0.0 Updated 22-06-2014
Tool run by Laba on st 25. 06. 2014 at 20:48:08,32.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Laba\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

25. 6. 2014 20:49:47 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{45e2eeba-528e-452c-a38f-df5e44b795e4} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{45e2eeba-528e-452c-a38f-df5e44b795e4} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4c4bece7-4ce9-48d0-9d52-da9aae4e870a} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4c4bece7-4ce9-48d0-9d52-da9aae4e870a} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2cd63d91-fa25-43ac-8e48-7cb50c49f45a} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2cd63d91-fa25-43ac-8e48-7cb50c49f45a} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{71fce611-e9fc-4ff4-9b09-414b0051e494} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{71fce611-e9fc-4ff4-9b09-414b0051e494} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9e4969e3-bd03-40ff-bd48-e21d826fc26a} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9e4969e3-bd03-40ff-bd48-e21d826fc26a} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{b6136ec7-c900-4b6c-a0a0-3e0697dd385e} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{b6136ec7-c900-4b6c-a0a0-3e0697dd385e} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{c3eff263-bd08-480a-a79e-72f0c5173498} deleted successfully
HKEY_USERS\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{c3eff263-bd08-480a-a79e-72f0c5173498} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\MediaBuzzV1 deleted
C:\extensions.sqlite deleted
C:\extensions.ini deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Laba\Searches deleted
C:\prefs.js deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
"C:\Users\Laba\AppData\Local\LumaEmu" deleted

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
mmifolfpllfdhilecpdpmemhelmanajl - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx[]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE11SR"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"
{80D0F900-77A8-45CD-92F7-59BA08B02602} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_16194"

==== Reset Google Chrome ======================

Nothing found to reset

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mmifolfpllfdhilecpdpmemhelmanajl deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Laba\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Laba\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=21 folders=18 14063584 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Laba\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Laba\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on st 25. 06. 2014 at 21:02:08,03 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zelene pismenka - odkazy

#9 Příspěvek od vyosek »

:arrow: Parada, uz to vypada docela ciste

:arrow: Poprosim o FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100 at docistime zbytky
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Laba
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 25 čer 2014 18:16

Re: zelene pismenka - odkazy

#10 Příspěvek od Laba »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-06-2014
Ran by Laba (administrator) on MANTEL-PC on 25-06-2014 21:13:05
Running from C:\Users\Laba\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Acresso Software Inc.) C:\Program Files (x86)\ArcGIS\License10.0\bin\lmgrd.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Acresso Software Inc.) C:\Program Files (x86)\ArcGIS\License10.0\bin\lmgrd.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe
() C:\Windows\SysWOW64\nethtsrv.exe
() C:\Windows\SysWOW64\netupdsrv.exe
(ESRI) C:\Program Files (x86)\ArcGIS\License10.0\bin\ARCGIS.exe
(Acresso Software Inc.) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(forum.viry.cz) C:\Users\Laba\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-07-22] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2281256 2010-09-13] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] => C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-23] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-09-09] (Advanced Micro Devices, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\Run: [icq] => C:\Users\Laba\AppData\Roaming\ICQM\icq.exe [28698984 2013-09-18] (ICQ)
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\Run: [] => [X]
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\MountPoints2: {42afd595-d0d4-11e2-9463-c80aa9f08d7a} - F:\autorun.exe
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\MountPoints2: {b2a8f6df-6ee3-11e3-8af1-70f39559660e} - G:\HTC_Sync_Manager_PC.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7E3C4A247954CE01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {80D0F900-77A8-45CD-92F7-59BA08B02602} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @soe.sony.com/installer,version=1.0.3 - C:\Users\Laba\AppData\LocalLow\Sony Online Entertainment\npsoe.dll No File
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Laba\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

==================== Services (Whitelisted) =================

R2 ArcGIS License Manager; C:\Program Files (x86)\ArcGIS\License10.0\bin\lmgrd.exe [1500424 2008-11-06] (Acresso Software Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [49464 2014-05-21] (Hewlett-Packard Company)
R2 NetHttpService; C:\Windows\SysWOW64\nethtsrv.exe [180736 2014-06-20] () [File not signed]
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [34528 2013-03-07] (The OpenVPN Project)
R2 ServiceUpdater; C:\Windows\SysWOW64\netupdsrv.exe [162304 2014-06-20] () [File not signed]

==================== Drivers (Whitelisted) ====================

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-06-09] (DT Soft Ltd)
R1 nethfdrv; C:\Windows\system32\drivers\nethfdrv.sys [46160 2014-06-20] (nethfdrv)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 iscFlash; \??\c:\SwSetup\SP55299\iscflashx64.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-06-25 21:13 - 2014-06-25 21:13 - 00009979 _____ () C:\Users\Laba\Desktop\FRST.txt
2014-06-25 21:11 - 2014-06-25 21:13 - 00000000 ____D () C:\FRST
2014-06-25 21:10 - 2014-06-25 21:10 - 00112640 _____ (forum.viry.cz) C:\Users\Laba\Desktop\FRSTLauncher.exe
2014-06-25 21:09 - 2014-06-25 21:09 - 02082816 _____ (Farbar) C:\Users\Laba\Desktop\FRST64.exe
2014-06-25 21:07 - 2014-06-25 21:07 - 00000687 _____ () C:\awh33AC.tmp
2014-06-25 21:00 - 2014-06-25 20:48 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-25 20:49 - 2014-06-25 21:02 - 00008500 _____ () C:\zoek-results.log
2014-06-25 20:48 - 2014-06-25 20:59 - 00000000 ____D () C:\zoek_backup
2014-06-25 20:45 - 2014-06-25 20:46 - 01285120 _____ () C:\Users\Laba\Desktop\zoek.exe
2014-06-25 20:43 - 2014-06-25 20:43 - 00000687 _____ () C:\awh401C.tmp
2014-06-25 19:54 - 2014-06-25 19:55 - 00000000 ____D () C:\AdwCleaner
2014-06-25 19:51 - 2014-06-25 19:51 - 00003223 _____ () C:\Users\Laba\Desktop\JRT.txt
2014-06-25 19:42 - 2014-06-25 19:42 - 00000000 ____D () C:\Windows\ERUNT
2014-06-25 19:40 - 2014-06-25 19:40 - 01342659 _____ () C:\Users\Laba\Desktop\adwcleaner_3.213.exe
2014-06-25 19:40 - 2014-06-25 19:40 - 01016261 _____ (Thisisu) C:\Users\Laba\Desktop\JRT.exe
2014-06-25 19:11 - 2014-06-25 19:12 - 00000000 ____D () C:\Users\Laba\Desktop\rsit
2014-06-25 19:11 - 2014-06-25 19:12 - 00000000 ____D () C:\Program Files\trend micro
2014-06-25 18:42 - 2014-06-25 18:42 - 00000687 _____ () C:\awh12B5.tmp
2014-06-25 18:27 - 2014-06-25 18:35 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\Lavasoft
2014-06-25 18:16 - 2014-06-25 18:16 - 00000687 _____ () C:\awh1100.tmp
2014-06-25 18:10 - 2014-06-25 21:01 - 00007116 _____ () C:\Windows\PFRO.log
2014-06-25 18:10 - 2014-06-25 21:01 - 00000280 _____ () C:\Windows\setupact.log
2014-06-25 18:10 - 2014-06-25 18:10 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-25 16:05 - 2014-06-25 16:05 - 00003830 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1403705101
2014-06-25 16:05 - 2014-06-25 16:05 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-25 15:10 - 2014-06-25 15:10 - 00000687 _____ () C:\awh27DA.tmp
2014-06-25 06:55 - 2014-06-25 06:55 - 00000687 _____ () C:\awh1E49.tmp
2014-06-24 22:14 - 2014-06-24 22:14 - 00000687 _____ () C:\awh1959.tmp
2014-06-24 14:40 - 2014-06-24 14:40 - 00000687 _____ () C:\awh315C.tmp
2014-06-23 15:47 - 2014-06-23 15:47 - 00000687 _____ () C:\awh1A91.tmp
2014-06-23 06:13 - 2014-06-23 06:13 - 00000687 _____ () C:\awh2F59.tmp
2014-06-22 20:13 - 2014-06-22 20:13 - 00000687 _____ () C:\awh4F47.tmp
2014-06-20 08:11 - 2014-06-20 08:11 - 00180736 _____ () C:\Windows\SysWOW64\nethtsrv.exe
2014-06-20 08:11 - 2014-06-20 08:11 - 00162304 _____ () C:\Windows\SysWOW64\netupdsrv.exe
2014-06-20 08:11 - 2014-06-20 08:11 - 00111104 _____ () C:\Windows\SysWOW64\installd.exe
2014-06-20 08:11 - 2014-06-20 08:11 - 00046160 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
2014-06-20 08:10 - 2014-06-20 08:10 - 00246784 _____ () C:\Windows\SysWOW64\hfpapi.dll
2014-06-20 08:10 - 2014-06-20 08:10 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-06-19 16:54 - 2014-06-19 17:37 - 00000000 ____D () C:\Users\Laba\Desktop\promocna karta
2014-06-18 18:35 - 2014-06-18 18:35 - 00000000 ____D () C:\Users\Laba\Documents\KONAMI
2014-06-18 18:26 - 2014-06-18 18:26 - 00000000 ____D () C:\ProgramData\KONAMI
2014-06-18 17:41 - 2014-06-18 17:59 - 00000000 ____D () C:\Users\Laba\Desktop\Pro.Evolution.Soccer.2014-RELOADED
2014-06-17 10:40 - 2014-06-18 17:48 - 00000000 ____D () C:\Users\Laba\Documents\FIFA 14
2014-06-17 10:40 - 2014-06-17 10:40 - 00000000 ____D () C:\ProgramData\Origin
2014-06-17 10:39 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2014-06-15 17:49 - 2014-06-15 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOE & AOK Campaign Manager
2014-06-15 17:48 - 2014-06-15 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2014-06-15 17:48 - 2014-06-15 17:48 - 00001491 _____ () C:\Users\Public\Desktop\Age of Empires Expansion.lnk
2014-06-15 17:48 - 2014-06-15 17:48 - 00001484 _____ () C:\Users\Public\Desktop\Age of Empires.lnk
2014-06-15 17:48 - 1998-05-07 19:57 - 00143872 ____N (Intel Corporation) C:\Windows\SysWOW64\iacenc.dll
2014-06-15 17:48 - 1997-06-13 17:56 - 00056832 ____N () C:\Windows\SysWOW64\iyvu9_32.dll
2014-06-12 11:16 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 11:16 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 11:16 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 11:16 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 11:16 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-12 11:16 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 11:16 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 11:16 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-12 11:16 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-12 11:16 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-12 11:16 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 11:16 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-12 11:16 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 11:16 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-12 11:16 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 11:16 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-12 11:16 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-12 11:16 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-12 11:16 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 11:16 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-12 11:16 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-12 11:16 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-12 11:16 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 11:16 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-12 11:16 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-12 11:16 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 11:16 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-12 11:16 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-12 11:16 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-12 11:16 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-12 11:16 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-12 11:16 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-12 11:16 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-12 11:16 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-12 11:16 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-12 11:16 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-12 11:16 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 11:16 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-12 11:16 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-12 11:16 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-12 11:16 - 2014-04-25 04:27 - 00801792 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 11:16 - 2014-04-25 03:58 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 11:16 - 2014-04-05 04:37 - 01897408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 11:16 - 2014-04-05 04:37 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-06-12 11:16 - 2014-04-05 04:37 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 11:16 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 11:16 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 11:16 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 11:16 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-12 11:16 - 2014-03-26 04:39 - 01881088 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 11:16 - 2014-03-26 04:36 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 11:16 - 2014-03-26 04:13 - 01236992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-12 11:16 - 2014-03-26 04:10 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-12 11:15 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 11:15 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-12 11:15 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-12 11:15 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-12 11:15 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 11:15 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 11:15 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 11:15 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 11:15 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-12 11:15 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 11:15 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 11:15 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-12 11:14 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-12 11:14 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-11 08:36 - 2014-06-11 09:10 - 2837354496 ____R () C:\Users\Laba\Desktop\Hobit - Šmakova dračí poušť (2013) CZ.avi
2014-06-10 19:31 - 2014-06-10 20:03 - 205010002 ____R () C:\Users\Laba\Desktop\AOE.isz
2014-06-10 18:31 - 2014-06-10 19:04 - 2601699328 ____R () C:\Users\Laba\Desktop\The.Hobbit.An.Unexpected.Journey.2012.BRRip.XviD.AC3.CZ.avi
2014-05-30 15:36 - 2014-05-30 15:40 - 00000000 ____D () C:\Users\Laba\Desktop\BAKALARKA
2014-05-29 18:06 - 2014-05-29 18:06 - 00000000 ____D () C:\ProgramData\ATI
2014-05-29 18:04 - 2014-05-29 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
2014-05-29 18:03 - 2014-05-29 18:03 - 00060328 _____ () C:\Windows\SysWOW64\CCCInstall_201405291803190272.log
2014-05-29 18:02 - 2010-06-14 16:32 - 00002857 _____ () C:\Windows\SysWOW64\atipblup.dat
2014-05-29 18:02 - 2010-06-14 16:32 - 00002857 _____ () C:\Windows\system32\atipblup.dat
2014-05-29 17:57 - 2014-05-29 17:57 - 00015906 _____ () C:\Windows\system32\results.xml
2014-05-29 17:49 - 2014-05-29 17:49 - 00000000 ____D () C:\Program Files\Common Files\Intel
2014-05-29 16:35 - 2014-05-29 16:35 - 00000000 ____D () C:\Program Files (x86)\AMD APP
2014-05-29 16:05 - 1997-07-06 20:22 - 00756736 ____N (Intel Corporation) C:\Windows\SysWOW64\ir41_32.dll
2014-05-29 15:46 - 2014-05-29 15:48 - 170769181 ____R () C:\Users\Laba\Desktop\Age-of-Empires1-.rar

==================== One Month Modified Files and Folders =======

2014-06-25 21:13 - 2014-06-25 21:13 - 00009979 _____ () C:\Users\Laba\Desktop\FRST.txt
2014-06-25 21:13 - 2014-06-25 21:11 - 00000000 ____D () C:\FRST
2014-06-25 21:10 - 2014-06-25 21:10 - 00112640 _____ (forum.viry.cz) C:\Users\Laba\Desktop\FRSTLauncher.exe
2014-06-25 21:09 - 2014-06-25 21:09 - 02082816 _____ (Farbar) C:\Users\Laba\Desktop\FRST64.exe
2014-06-25 21:09 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-25 21:09 - 2009-07-14 06:45 - 00021888 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-25 21:07 - 2014-06-25 21:07 - 00000687 _____ () C:\awh33AC.tmp
2014-06-25 21:06 - 2013-05-19 11:07 - 01575740 _____ () C:\Windows\WindowsUpdate.log
2014-06-25 21:06 - 2009-07-14 07:13 - 00006406 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-25 21:04 - 2013-05-19 11:13 - 00000000 ____D () C:\Users\Laba
2014-06-25 21:02 - 2014-06-25 20:49 - 00008500 _____ () C:\zoek-results.log
2014-06-25 21:01 - 2014-06-25 18:10 - 00007116 _____ () C:\Windows\PFRO.log
2014-06-25 21:01 - 2014-06-25 18:10 - 00000280 _____ () C:\Windows\setupact.log
2014-06-25 21:01 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-25 20:59 - 2014-06-25 20:48 - 00000000 ____D () C:\zoek_backup
2014-06-25 20:48 - 2014-06-25 21:00 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-25 20:46 - 2014-06-25 20:45 - 01285120 _____ () C:\Users\Laba\Desktop\zoek.exe
2014-06-25 20:43 - 2014-06-25 20:43 - 00000687 _____ () C:\awh401C.tmp
2014-06-25 19:55 - 2014-06-25 19:54 - 00000000 ____D () C:\AdwCleaner
2014-06-25 19:51 - 2014-06-25 19:51 - 00003223 _____ () C:\Users\Laba\Desktop\JRT.txt
2014-06-25 19:42 - 2014-06-25 19:42 - 00000000 ____D () C:\Windows\ERUNT
2014-06-25 19:40 - 2014-06-25 19:40 - 01342659 _____ () C:\Users\Laba\Desktop\adwcleaner_3.213.exe
2014-06-25 19:40 - 2014-06-25 19:40 - 01016261 _____ (Thisisu) C:\Users\Laba\Desktop\JRT.exe
2014-06-25 19:33 - 2013-08-28 20:30 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-25 19:32 - 2014-03-04 23:01 - 00000000 ____D () C:\Users\Laba\AppData\Local\Paint.NET
2014-06-25 19:12 - 2014-06-25 19:11 - 00000000 ____D () C:\Users\Laba\Desktop\rsit
2014-06-25 19:12 - 2014-06-25 19:11 - 00000000 ____D () C:\Program Files\trend micro
2014-06-25 18:42 - 2014-06-25 18:42 - 00000687 _____ () C:\awh12B5.tmp
2014-06-25 18:35 - 2014-06-25 18:27 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\Lavasoft
2014-06-25 18:28 - 2014-02-23 00:23 - 00000000 ____D () C:\Program Files (x86)\Lavasoft
2014-06-25 18:16 - 2014-06-25 18:16 - 00000687 _____ () C:\awh1100.tmp
2014-06-25 18:10 - 2014-06-25 18:10 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-25 16:27 - 2014-01-30 16:31 - 00000290 __RSH () C:\ProgramData\ntuser.pol
2014-06-25 16:15 - 2014-03-10 14:34 - 00000000 ____D () C:\Windows\Minidump
2014-06-25 16:15 - 2013-06-09 15:24 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\DAEMON Tools Lite
2014-06-25 16:15 - 2013-06-04 21:13 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\uTorrent
2014-06-25 16:15 - 2013-05-19 12:04 - 00000000 ____D () C:\Windows\Panther
2014-06-25 16:12 - 2013-05-19 12:16 - 00000000 ____D () C:\Users\Laba\AppData\Local\Google
2014-06-25 16:12 - 2013-05-19 12:16 - 00000000 ____D () C:\Program Files (x86)\Google
2014-06-25 16:05 - 2014-06-25 16:05 - 00003830 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1403705101
2014-06-25 16:05 - 2014-06-25 16:05 - 00001133 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-06-25 16:05 - 2013-10-11 19:00 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\Opera Software
2014-06-25 16:05 - 2013-10-11 19:00 - 00000000 ____D () C:\Users\Laba\AppData\Local\Opera Software
2014-06-25 16:05 - 2013-10-11 19:00 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-25 16:01 - 2013-05-19 11:26 - 00001417 _____ () C:\Users\Laba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-06-25 15:10 - 2014-06-25 15:10 - 00000687 _____ () C:\awh27DA.tmp
2014-06-25 06:55 - 2014-06-25 06:55 - 00000687 _____ () C:\awh1E49.tmp
2014-06-24 22:14 - 2014-06-24 22:14 - 00000687 _____ () C:\awh1959.tmp
2014-06-24 15:18 - 2013-05-22 19:04 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\Skype
2014-06-24 14:40 - 2014-06-24 14:40 - 00000687 _____ () C:\awh315C.tmp
2014-06-23 20:43 - 2013-06-17 15:19 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\vlc
2014-06-23 15:47 - 2014-06-23 15:47 - 00000687 _____ () C:\awh1A91.tmp
2014-06-23 06:13 - 2014-06-23 06:13 - 00000687 _____ () C:\awh2F59.tmp
2014-06-22 20:13 - 2014-06-22 20:13 - 00000687 _____ () C:\awh4F47.tmp
2014-06-20 08:11 - 2014-06-20 08:11 - 00180736 _____ () C:\Windows\SysWOW64\nethtsrv.exe
2014-06-20 08:11 - 2014-06-20 08:11 - 00162304 _____ () C:\Windows\SysWOW64\netupdsrv.exe
2014-06-20 08:11 - 2014-06-20 08:11 - 00111104 _____ () C:\Windows\SysWOW64\installd.exe
2014-06-20 08:11 - 2014-06-20 08:11 - 00046160 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
2014-06-20 08:10 - 2014-06-20 08:10 - 00246784 _____ () C:\Windows\SysWOW64\hfpapi.dll
2014-06-20 08:10 - 2014-06-20 08:10 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-06-19 17:37 - 2014-06-19 16:54 - 00000000 ____D () C:\Users\Laba\Desktop\promocna karta
2014-06-18 18:35 - 2014-06-18 18:35 - 00000000 ____D () C:\Users\Laba\Documents\KONAMI
2014-06-18 18:26 - 2014-06-18 18:26 - 00000000 ____D () C:\ProgramData\KONAMI
2014-06-18 18:26 - 2013-06-09 15:28 - 00000000 ____D () C:\HRY
2014-06-18 18:01 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-06-18 17:59 - 2014-06-18 17:41 - 00000000 ____D () C:\Users\Laba\Desktop\Pro.Evolution.Soccer.2014-RELOADED
2014-06-18 17:48 - 2014-06-17 10:40 - 00000000 ____D () C:\Users\Laba\Documents\FIFA 14
2014-06-17 10:40 - 2014-06-17 10:40 - 00000000 ____D () C:\ProgramData\Origin
2014-06-15 21:29 - 2013-05-19 11:14 - 00094152 _____ () C:\Users\Laba\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-15 21:29 - 2009-07-14 06:45 - 00359856 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-15 21:27 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-06-15 17:49 - 2014-06-15 17:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOE & AOK Campaign Manager
2014-06-15 17:49 - 2014-06-15 17:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2014-06-15 17:48 - 2014-06-15 17:48 - 00001491 _____ () C:\Users\Public\Desktop\Age of Empires Expansion.lnk
2014-06-15 17:48 - 2014-06-15 17:48 - 00001484 _____ () C:\Users\Public\Desktop\Age of Empires.lnk
2014-06-15 09:56 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-12 20:28 - 2013-05-22 19:04 - 00000000 ____D () C:\ProgramData\Skype
2014-06-12 16:12 - 2013-08-14 23:31 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 16:11 - 2013-08-11 19:48 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 16:10 - 2014-04-30 08:32 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-12 08:55 - 2013-10-22 14:11 - 00000000 ____D () C:\Users\Laba\Documents\NHL09
2014-06-11 12:05 - 2014-05-09 11:10 - 00000000 ____D () C:\Users\Laba\Desktop\Škola
2014-06-11 09:10 - 2014-06-11 08:36 - 2837354496 ____R () C:\Users\Laba\Desktop\Hobit - Šmakova dračí poušť (2013) CZ.avi
2014-06-10 20:03 - 2014-06-10 19:31 - 205010002 ____R () C:\Users\Laba\Desktop\AOE.isz
2014-06-10 19:04 - 2014-06-10 18:31 - 2601699328 ____R () C:\Users\Laba\Desktop\The.Hobbit.An.Unexpected.Journey.2012.BRRip.XviD.AC3.CZ.avi
2014-06-08 11:13 - 2014-06-12 11:14 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 11:14 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-03 10:59 - 2014-05-07 14:16 - 00000000 ____D () C:\Users\Laba\Desktop\štátnice
2014-05-30 15:40 - 2014-05-30 15:36 - 00000000 ____D () C:\Users\Laba\Desktop\BAKALARKA
2014-05-30 12:21 - 2014-06-12 11:15 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-12 11:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-12 11:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-12 11:16 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-12 11:16 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 11:39 - 2014-06-12 11:15 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 11:38 - 2014-06-12 11:16 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-12 11:16 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-12 11:16 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-12 11:16 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-12 11:16 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 11:21 - 2014-06-12 11:15 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 11:20 - 2014-06-12 11:15 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-12 11:16 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-12 11:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-12 11:15 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-12 11:16 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-12 11:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-12 11:16 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-12 11:15 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:47 - 2009-07-14 07:08 - 00032556 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-05-30 10:46 - 2014-06-12 11:15 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-12 11:16 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-12 11:16 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-12 11:16 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-12 11:16 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 11:16 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-12 11:16 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-12 11:16 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 11:16 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-12 11:16 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-12 11:16 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-12 11:16 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-12 11:16 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-12 11:15 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-12 11:16 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-12 11:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 11:16 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 11:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-12 11:16 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 11:16 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-12 11:16 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-12 11:15 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-12 11:16 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 11:16 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 11:16 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-12 11:15 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-12 11:16 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-12 11:16 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-12 11:16 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-12 11:16 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-12 11:16 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-30 09:13 - 2014-06-12 11:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-29 18:06 - 2014-05-29 18:06 - 00000000 ____D () C:\ProgramData\ATI
2014-05-29 18:04 - 2014-05-29 18:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
2014-05-29 18:04 - 2013-10-01 09:03 - 00000000 ____D () C:\Program Files\ATI Technologies
2014-05-29 18:03 - 2014-05-29 18:03 - 00060328 _____ () C:\Windows\SysWOW64\CCCInstall_201405291803190272.log
2014-05-29 18:03 - 2013-09-17 11:56 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2014-05-29 18:00 - 2013-10-01 09:03 - 00000000 ____D () C:\Program Files\ATI
2014-05-29 17:57 - 2014-05-29 17:57 - 00015906 _____ () C:\Windows\system32\results.xml
2014-05-29 17:49 - 2014-05-29 17:49 - 00000000 ____D () C:\Program Files\Common Files\Intel
2014-05-29 17:49 - 2013-05-19 12:14 - 00000000 ____D () C:\Program Files (x86)\Intel
2014-05-29 17:44 - 2013-05-19 12:14 - 00000000 ____D () C:\Intel
2014-05-29 17:42 - 2013-05-21 21:19 - 00000000 ____D () C:\swsetup
2014-05-29 17:18 - 2013-05-21 22:57 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-05-29 17:18 - 2013-05-21 22:43 - 00000000 ____D () C:\Program Files (x86)\HP
2014-05-29 16:35 - 2014-05-29 16:35 - 00000000 ____D () C:\Program Files (x86)\AMD APP
2014-05-29 16:11 - 2013-10-29 10:53 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-05-29 15:48 - 2014-05-29 15:46 - 170769181 ____R () C:\Users\Laba\Desktop\Age-of-Empires1-.rar
2014-05-28 18:26 - 2013-12-12 17:57 - 00000000 ___RD () C:\Program Files (x86)\Skype

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-06-09 22:30




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:463.56 GB) (Free:207.07 GB) NTFS
Drive e: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.98 GB) FAT32
Drive f: (PES2014_R2) (CDROM) (Total:5.79 GB) (Free:0 GB) UDF

Available physical RAM: 2535.64 MB
Total physical RAM: 3893.86 MB
Percentage of memory in use: 34%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 554E6A8B)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=464 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=2 GB) - (Type=0C)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Laba\Desktop" je 19052 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zelene pismenka - odkazy

#11 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
    HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\Run: [icq] => C:\Users\Laba\AppData\Roaming\ICQM\icq.exe [28698984 2013-09-18] (ICQ)
    HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\Run: [] => [X]
    HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\MountPoints2: {42afd595-d0d4-11e2-9463-c80aa9f08d7a} - F:\autorun.exe
    HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\MountPoints2: {b2a8f6df-6ee3-11e3-8af1-70f39559660e} - G:\HTC_Sync_Manager_PC.exe
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    
    KCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7E3C4A247954CE01
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
    SearchScopes: HKLM-x32 - DefaultScope value is missing.
    
    R2 ServiceUpdater; C:\Windows\SysWOW64\netupdsrv.exe [162304 2014-06-20] () [File not signed]
    R2 NetHttpService; C:\Windows\SysWOW64\nethtsrv.exe [180736 2014-06-20] () [File not signed]
    R1 nethfdrv; C:\Windows\system32\drivers\nethfdrv.sys [46160 2014-06-20] (nethfdrv)
    S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
    S3 iscFlash; \??\c:\SwSetup\SP55299\iscflashx64.sys [X]
    
    2014-06-25 21:10 - 2014-06-25 21:10 - 00112640 _____ (forum.viry.cz) C:\Users\Laba\Desktop\FRSTLauncher.exe
    2014-06-25 21:07 - 2014-06-25 21:07 - 00000687 _____ () C:\awh33AC.tmp
    2014-06-25 21:00 - 2014-06-25 20:48 - 00024064 _____ () C:\Windows\zoek-delete.exe
    2014-06-25 20:49 - 2014-06-25 21:02 - 00008500 _____ () C:\zoek-results.log
    2014-06-25 20:48 - 2014-06-25 20:59 - 00000000 ____D () C:\zoek_backup
    2014-06-25 20:45 - 2014-06-25 20:46 - 01285120 _____ () C:\Users\Laba\Desktop\zoek.exe
    2014-06-25 20:43 - 2014-06-25 20:43 - 00000687 _____ () C:\awh401C.tmp
    2014-06-25 19:54 - 2014-06-25 19:55 - 00000000 ____D () C:\AdwCleaner
    2014-06-25 19:51 - 2014-06-25 19:51 - 00003223 _____ () C:\Users\Laba\Desktop\JRT.txt
    2014-06-25 19:42 - 2014-06-25 19:42 - 00000000 ____D () C:\Windows\ERUNT
    2014-06-25 19:40 - 2014-06-25 19:40 - 01342659 _____ () C:\Users\Laba\Desktop\adwcleaner_3.213.exe
    2014-06-25 19:40 - 2014-06-25 19:40 - 01016261 _____ (Thisisu) C:\Users\Laba\Desktop\JRT.exe
    2014-06-25 19:11 - 2014-06-25 19:12 - 00000000 ____D () C:\Users\Laba\Desktop\rsit
    2014-06-25 19:11 - 2014-06-25 19:12 - 00000000 ____D () C:\Program Files\trend micro
    2014-06-25 18:42 - 2014-06-25 18:42 - 00000687 _____ () C:\awh12B5.tmp
    2014-06-25 18:27 - 2014-06-25 18:35 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\Lavasoft
    2014-06-25 18:16 - 2014-06-25 18:16 - 00000687 _____ () C:\awh1100.tmp
    2014-06-25 18:10 - 2014-06-25 21:01 - 00007116 _____ () C:\Windows\PFRO.log
    2014-06-25 18:10 - 2014-06-25 21:01 - 00000280 _____ () C:\Windows\setupact.log
    2014-06-25 18:10 - 2014-06-25 18:10 - 00000000 _____ () C:\Windows\setuperr.log
    2014-06-25 15:10 - 2014-06-25 15:10 - 00000687 _____ () C:\awh27DA.tmp
    2014-06-25 06:55 - 2014-06-25 06:55 - 00000687 _____ () C:\awh1E49.tmp
    2014-06-24 22:14 - 2014-06-24 22:14 - 00000687 _____ () C:\awh1959.tmp
    2014-06-24 14:40 - 2014-06-24 14:40 - 00000687 _____ () C:\awh315C.tmp
    2014-06-23 15:47 - 2014-06-23 15:47 - 00000687 _____ () C:\awh1A91.tmp
    2014-06-23 06:13 - 2014-06-23 06:13 - 00000687 _____ () C:\awh2F59.tmp
    2014-06-22 20:13 - 2014-06-22 20:13 - 00000687 _____ () C:\awh4F47.tmp
    2014-06-20 08:11 - 2014-06-20 08:11 - 00180736 _____ () C:\Windows\SysWOW64\nethtsrv.exe
    2014-06-20 08:11 - 2014-06-20 08:11 - 00162304 _____ () C:\Windows\SysWOW64\netupdsrv.exe
    2014-06-20 08:11 - 2014-06-20 08:11 - 00111104 _____ () C:\Windows\SysWOW64\installd.exe
    2014-06-20 08:11 - 2014-06-20 08:11 - 00046160 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
    2014-06-20 08:10 - 2014-06-20 08:10 - 00246784 _____ () C:\Windows\SysWOW64\hfpapi.dll
    2014-06-20 08:10 - 2014-06-20 08:10 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    
    Hosts:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Laba
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 25 čer 2014 18:16

Re: zelene pismenka - odkazy

#12 Příspěvek od Laba »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-06-2014
Ran by Laba at 2014-06-25 21:32:15 Run:1
Running from C:\Users\Laba\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\Run: [icq] => C:\Users\Laba\AppData\Roaming\ICQM\icq.exe [28698984 2013-09-18] (ICQ)
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\Run: [] => [X]
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\MountPoints2: {42afd595-d0d4-11e2-9463-c80aa9f08d7a} - F:\autorun.exe
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\...\MountPoints2: {b2a8f6df-6ee3-11e3-8af1-70f39559660e} - G:\HTC_Sync_Manager_PC.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

KCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7E3C4A247954CE01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM-x32 - DefaultScope value is missing.

R2 ServiceUpdater; C:\Windows\SysWOW64\netupdsrv.exe [162304 2014-06-20] () [File not signed]
R2 NetHttpService; C:\Windows\SysWOW64\nethtsrv.exe [180736 2014-06-20] () [File not signed]
R1 nethfdrv; C:\Windows\system32\drivers\nethfdrv.sys [46160 2014-06-20] (nethfdrv)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 iscFlash; \??\c:\SwSetup\SP55299\iscflashx64.sys [X]

2014-06-25 21:10 - 2014-06-25 21:10 - 00112640 _____ (forum.viry.cz) C:\Users\Laba\Desktop\FRSTLauncher.exe
2014-06-25 21:07 - 2014-06-25 21:07 - 00000687 _____ () C:\awh33AC.tmp
2014-06-25 21:00 - 2014-06-25 20:48 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-25 20:49 - 2014-06-25 21:02 - 00008500 _____ () C:\zoek-results.log
2014-06-25 20:48 - 2014-06-25 20:59 - 00000000 ____D () C:\zoek_backup
2014-06-25 20:45 - 2014-06-25 20:46 - 01285120 _____ () C:\Users\Laba\Desktop\zoek.exe
2014-06-25 20:43 - 2014-06-25 20:43 - 00000687 _____ () C:\awh401C.tmp
2014-06-25 19:54 - 2014-06-25 19:55 - 00000000 ____D () C:\AdwCleaner
2014-06-25 19:51 - 2014-06-25 19:51 - 00003223 _____ () C:\Users\Laba\Desktop\JRT.txt
2014-06-25 19:42 - 2014-06-25 19:42 - 00000000 ____D () C:\Windows\ERUNT
2014-06-25 19:40 - 2014-06-25 19:40 - 01342659 _____ () C:\Users\Laba\Desktop\adwcleaner_3.213.exe
2014-06-25 19:40 - 2014-06-25 19:40 - 01016261 _____ (Thisisu) C:\Users\Laba\Desktop\JRT.exe
2014-06-25 19:11 - 2014-06-25 19:12 - 00000000 ____D () C:\Users\Laba\Desktop\rsit
2014-06-25 19:11 - 2014-06-25 19:12 - 00000000 ____D () C:\Program Files\trend micro
2014-06-25 18:42 - 2014-06-25 18:42 - 00000687 _____ () C:\awh12B5.tmp
2014-06-25 18:27 - 2014-06-25 18:35 - 00000000 ____D () C:\Users\Laba\AppData\Roaming\Lavasoft
2014-06-25 18:16 - 2014-06-25 18:16 - 00000687 _____ () C:\awh1100.tmp
2014-06-25 18:10 - 2014-06-25 21:01 - 00007116 _____ () C:\Windows\PFRO.log
2014-06-25 18:10 - 2014-06-25 21:01 - 00000280 _____ () C:\Windows\setupact.log
2014-06-25 18:10 - 2014-06-25 18:10 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-25 15:10 - 2014-06-25 15:10 - 00000687 _____ () C:\awh27DA.tmp
2014-06-25 06:55 - 2014-06-25 06:55 - 00000687 _____ () C:\awh1E49.tmp
2014-06-24 22:14 - 2014-06-24 22:14 - 00000687 _____ () C:\awh1959.tmp
2014-06-24 14:40 - 2014-06-24 14:40 - 00000687 _____ () C:\awh315C.tmp
2014-06-23 15:47 - 2014-06-23 15:47 - 00000687 _____ () C:\awh1A91.tmp
2014-06-23 06:13 - 2014-06-23 06:13 - 00000687 _____ () C:\awh2F59.tmp
2014-06-22 20:13 - 2014-06-22 20:13 - 00000687 _____ () C:\awh4F47.tmp
2014-06-20 08:11 - 2014-06-20 08:11 - 00180736 _____ () C:\Windows\SysWOW64\nethtsrv.exe
2014-06-20 08:11 - 2014-06-20 08:11 - 00162304 _____ () C:\Windows\SysWOW64\netupdsrv.exe
2014-06-20 08:11 - 2014-06-20 08:11 - 00111104 _____ () C:\Windows\SysWOW64\installd.exe
2014-06-20 08:11 - 2014-06-20 08:11 - 00046160 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
2014-06-20 08:10 - 2014-06-20 08:10 - 00246784 _____ () C:\Windows\SysWOW64\hfpapi.dll
2014-06-20 08:10 - 2014-06-20 08:10 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Hosts:
Reboot:
End
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Run\\icq => value deleted successfully.
HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
'HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{42afd595-d0d4-11e2-9463-c80aa9f08d7a}' => Key deleted successfully.
'HKCR\CLSID\{42afd595-d0d4-11e2-9463-c80aa9f08d7a}'=> Key not found.
'HKU\S-1-5-21-3976672655-2574289889-1708759391-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a8f6df-6ee3-11e3-8af1-70f39559660e}' => Key deleted successfully.
'HKCR\CLSID\{b2a8f6df-6ee3-11e3-8af1-70f39559660e}'=> Key not found.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP => Value not found.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
ServiceUpdater => Service stopped successfully.
ServiceUpdater => Service deleted successfully.
NetHttpService => Service stopped successfully.
NetHttpService => Service deleted successfully.
nethfdrv => Service stopped successfully.
nethfdrv => Service deleted successfully.
esgiguard => Service deleted successfully.
iscFlash => Service deleted successfully.
C:\Users\Laba\Desktop\FRSTLauncher.exe => Moved successfully.
"C:\awh33AC.tmp" => File/Directory not found.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Laba\Desktop\zoek.exe => Moved successfully.
C:\awh401C.tmp => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Laba\Desktop\JRT.txt => Moved successfully.
C:\Windows\ERUNT => Moved successfully.
C:\Users\Laba\Desktop\adwcleaner_3.213.exe => Moved successfully.
C:\Users\Laba\Desktop\JRT.exe => Moved successfully.
C:\Users\Laba\Desktop\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\awh12B5.tmp => Moved successfully.
C:\Users\Laba\AppData\Roaming\Lavasoft => Moved successfully.
C:\awh1100.tmp => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\awh27DA.tmp => Moved successfully.
C:\awh1E49.tmp => Moved successfully.
C:\awh1959.tmp => Moved successfully.
C:\awh315C.tmp => Moved successfully.
C:\awh1A91.tmp => Moved successfully.
C:\awh2F59.tmp => Moved successfully.
C:\awh4F47.tmp => Moved successfully.
C:\Windows\SysWOW64\nethtsrv.exe => Moved successfully.
C:\Windows\SysWOW64\netupdsrv.exe => Moved successfully.
C:\Windows\SysWOW64\installd.exe => Moved successfully.
C:\Windows\system32\Drivers\nethfdrv.sys => Moved successfully.
C:\Windows\SysWOW64\hfpapi.dll => Moved successfully.
C:\Windows\SysWOW64\hfnapi.dll => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.


The system needed a reboot.

==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zelene pismenka - odkazy

#13 Příspěvek od vyosek »

Jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Laba
Návštěvník
Návštěvník
Příspěvky: 8
Registrován: 25 čer 2014 18:16

Re: zelene pismenka - odkazy

#14 Příspěvek od Laba »

No asi to tu uz nemam :) velmi pekne Vam dakujem za ochotu a cas :), snad to tak uz ostane :)))

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: zelene pismenka - odkazy

#15 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno