Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kamarádovo PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
NemamRadViry
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 12 bře 2014 16:28

Kamarádovo PC

#1 Příspěvek od NemamRadViry »

Logfile of random's system information tool 1.06 (written by random/random)
Run by Admin at 2014-08-15 10:01:12
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 14 GB (18%) free of 76 GB
Total RAM: 894 MB (32% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\ASC7_PerformanceMonitor.job
C:\WINDOWS\tasks\Driver Booster Scan.job
C:\WINDOWS\tasks\Driver Booster Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
ExplorerWnd Helper - C:\Program Files\IOBit\IObit Uninstaller\UninstallExplorer32.dll [2014-05-18 752448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre7\bin\ssv.dll [2013-07-16 463272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}]
Advanced SystemCare Browser Protection - C:\PROGRA~1\IOBit\SURFIN~1\BROWER~1\ASCPLU~1.DLL [2013-11-25 665408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-07-16 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{10921475-03CE-4E04-90CE-E2E7EF20C814} - ExplorerWnd Helper - C:\Program Files\IOBit\IObit Uninstaller\UninstallExplorer32.dll [2014-05-18 752448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-04-12 16132608]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-07-15 32768]
"Samsung Common SM"=C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe [2005-07-03 372736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-03-21 5078504]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2013-03-10 88984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-05-19 1957888]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"Advanced SystemCare Ultimate"=C:\Program Files\IObit\Advanced SystemCare Ultimate 7\ASCTray.exe [2013-12-02 2562368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Java\jre7\bin\javaw.exe"="C:\Program Files\Java\jre7\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\Program Files\GameforgeLive\gfl_client.exe"="C:\Program Files\GameforgeLive\gfl_client.exe:*:Enabled:Gameforge Live"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2611e956-b44d-11df-bec7-001d92012204}]
shell\AutoRun\command - "H:\WD SmartWare.exe" autoplay=true

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3390d080-4c16-11e2-8520-001d92012204}]
shell\AutoRun\command - E:\Startme.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8addac6d-30a1-11e2-84e2-001d92012204}]
shell\AutoRun\command - "G:\WD SmartWare.exe" autoplay=true

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ea42ee81-ff91-11df-bf63-001d92012204}]
shell\AutoRun\command - G:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef3d3360-fbb6-11e0-8204-001d92012204}]
shell\AutoRun\command - "E:\WD SmartWare.exe" autoplay=true


======List of files/folders created in the last 1 months======

2014-08-15 10:01:13 ----D---- C:\Program Files\trend micro
2014-08-15 10:01:12 ----D---- C:\rsit
2014-08-15 09:58:08 ----D---- C:\Program Files\GameforgeLive
2014-08-15 09:08:46 ----D---- C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z

======List of files/folders modified in the last 1 months======

2014-08-15 10:01:13 ----RD---- C:\Program Files
2014-08-15 09:58:11 ----D---- C:\WINDOWS\Prefetch
2014-08-15 09:57:15 ----D---- C:\WINDOWS\Temp
2014-08-15 09:44:24 ----SHD---- C:\WINDOWS\Installer
2014-08-15 09:37:11 ----D---- C:\WINDOWS
2014-08-15 09:36:50 ----D---- C:\WINDOWS\system32
2014-08-15 09:03:11 ----D---- C:\Program Files\Mozilla Firefox
2014-08-14 21:21:21 ----N---- C:\WINDOWS\SchedLgU.Txt
2014-08-14 15:38:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\ProductData
2014-08-11 19:15:34 ----A---- C:\WINDOWS\wincmd.ini
2014-08-11 19:12:32 ----D---- C:\WINDOWS\system32\CatRoot2
2014-07-25 17:44:39 ----HD---- C:\WINDOWS\inf
2014-07-21 17:20:30 ----D---- C:\WINDOWS\system32\config
2014-07-16 15:46:15 ----SD---- C:\WINDOWS\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2013-01-10 161368]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2013-01-10 122240]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2013-03-04 30616]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2013-01-10 105784]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R2 DgiVecp;Team MFP Comm Driver; C:\WINDOWS\System32\Drivers\DgiVecp.sys [2005-03-14 41984]
R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-04-15 42496]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-04-23 4402176]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-10 634880]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2013-07-24 30720]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-07-30 18048]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-07-30 23040]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-07-30 8192]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2004-08-04 25600]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-07-30 8192]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdvancedSystemCareService7;Advanced SystemCare Service 7; C:\Program Files\IObit\Advanced SystemCare Ultimate 7\ASCService.exe [2013-11-15 886592]
R2 ASCAntivirusSrv;AdvancedSystemCareAntivirus; C:\Program Files\IObit\Advanced SystemCare Ultimate 7\ascavsvc.exe [2013-11-28 646976]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2013-03-21 1341664]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-07-16 182184]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-02 2151232]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-27 194032]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-20 129976]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kamarádovo PC

#2 Příspěvek od cernohous13 »

Zdravím,

:???: proč není nainstalovaný SP3? - http://www.microsoft.com/cs-cz/download ... x?id=25129

:arrow: odinstaluj vše od IObit - umí udělat v PC dost chaos :shock:

:arrow: po restartu nový RSIT
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

NemamRadViry
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 12 bře 2014 16:28

Re: Kamarádovo PC

#3 Příspěvek od NemamRadViry »

Proč tam SP3 nebyl nevím - je to kamarádovo PC (každopádně už tu je).

Tady ten log:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Admin at 2014-08-15 18:59:24
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 19 GB (25%) free of 76 GB
Total RAM: 894 MB (31% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre7\bin\ssv.dll [2013-07-16 463272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-07-16 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-04-12 16132608]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-07-15 32768]
"Samsung Common SM"=C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe [2005-07-03 372736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-03-21 5078504]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2013-03-10 88984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-05-19 1957888]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Java\jre7\bin\javaw.exe"="C:\Program Files\Java\jre7\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"C:\Program Files\GameforgeLive\gfl_client.exe"="C:\Program Files\GameforgeLive\gfl_client.exe:*:Enabled:Gameforge Live"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2611e956-b44d-11df-bec7-001d92012204}]
shell\AutoRun\command - "H:\WD SmartWare.exe" autoplay=true

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3390d080-4c16-11e2-8520-001d92012204}]
shell\AutoRun\command - E:\Startme.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8addac6d-30a1-11e2-84e2-001d92012204}]
shell\AutoRun\command - "G:\WD SmartWare.exe" autoplay=true

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ea42ee81-ff91-11df-bf63-001d92012204}]
shell\AutoRun\command - G:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef3d3360-fbb6-11e0-8204-001d92012204}]
shell\AutoRun\command - "E:\WD SmartWare.exe" autoplay=true


======List of files/folders created in the last 1 months======

2014-08-15 18:51:26 ----D---- C:\WINDOWS\system32\PreInstall
2014-08-15 18:48:32 ----SHD---- C:\Config.Msi
2014-08-15 18:46:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2014-08-15 18:46:35 ----D---- C:\WINDOWS\LastGood
2014-08-15 18:44:34 ----D---- C:\WINDOWS\Prefetch
2014-08-15 18:36:00 ----N---- C:\WINDOWS\system32\rwnh.dll
2014-08-15 18:35:59 ----N---- C:\WINDOWS\system32\smtpapi.dll
2014-08-15 18:35:43 ----N---- C:\WINDOWS\system32\aaclient.dll
2014-08-15 18:35:42 ----N---- C:\WINDOWS\system32\azroles.dll
2014-08-15 18:35:41 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2014-08-15 18:35:40 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2014-08-15 18:35:40 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2014-08-15 18:35:40 ----N---- C:\WINDOWS\system32\credssp.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapsvc.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapqec.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eappprxy.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapphost.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eappgnui.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eappcfg.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapolqec.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3ui.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3svc.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3msm.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3api.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dimsroam.dll
2014-08-15 18:35:38 ----N---- C:\WINDOWS\system32\ieencode.dll
2014-08-15 18:35:37 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2014-08-15 18:35:36 ----N---- C:\WINDOWS\system32\kbdpash.dll
2014-08-15 18:35:36 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2014-08-15 18:35:36 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\mmcperf.exe
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\mmcex.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\kmsvc.dll
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\napstat.exe
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\napmontr.dll
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\napipsec.dll
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\mssha.dll
2014-08-15 18:35:32 ----N---- C:\WINDOWS\system32\onex.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\rasqec.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\qutil.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\qcliprov.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\qagentrt.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\qagent.dll
2014-08-15 18:35:30 ----N---- C:\WINDOWS\system32\setupn.exe
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\xpsp3res.dll
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\verclsid.exe
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\tzchange.exe
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\tspkg.dll
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\tsgqec.dll
2014-08-15 18:35:28 ----N---- C:\WINDOWS\system32\wlanapi.dll
2014-08-15 18:35:25 ----D---- C:\WINDOWS\l2schemas
2014-08-15 18:35:24 ----D---- C:\WINDOWS\system32\cs
2014-08-15 18:35:24 ----D---- C:\WINDOWS\system32\bits
2014-08-15 18:29:49 ----D---- C:\WINDOWS\network diagnostic
2014-08-15 18:28:22 ----A---- C:\WINDOWS\005366_.tmp
2014-08-15 10:01:13 ----D---- C:\Program Files\trend micro
2014-08-15 10:01:12 ----D---- C:\rsit
2014-08-15 09:58:08 ----D---- C:\Program Files\GameforgeLive
2014-08-15 09:08:46 ----D---- C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z

======List of files/folders modified in the last 1 months======

2014-08-15 18:59:23 ----HD---- C:\WINDOWS\inf
2014-08-15 18:59:23 ----D---- C:\WINDOWS
2014-08-15 18:59:10 ----HD---- C:\WINDOWS\$hf_mig$
2014-08-15 18:51:26 ----D---- C:\WINDOWS\system32
2014-08-15 18:50:29 ----SHD---- C:\WINDOWS\Installer
2014-08-15 18:48:48 ----D---- C:\WINDOWS\Debug
2014-08-15 18:47:04 ----D---- C:\WINDOWS\Temp
2014-08-15 18:46:44 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-08-15 18:46:44 ----D---- C:\WINDOWS\SoftwareDistribution
2014-08-15 18:46:41 ----HD---- C:\Program Files\WindowsUpdate
2014-08-15 18:46:41 ----D---- C:\WINDOWS\Help
2014-08-15 18:46:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-08-15 18:45:05 ----D---- C:\WINDOWS\system32\CatRoot2
2014-08-15 18:44:07 ----D---- C:\WINDOWS\system32\wbem
2014-08-15 18:44:07 ----D---- C:\WINDOWS\system32\Setup
2014-08-15 18:44:07 ----D---- C:\WINDOWS\AppPatch
2014-08-15 18:44:06 ----RSD---- C:\WINDOWS\Fonts
2014-08-15 18:44:02 ----D---- C:\WINDOWS\system32\drivers
2014-08-15 18:43:29 ----N---- C:\WINDOWS\SchedLgU.Txt
2014-08-15 18:41:04 ----D---- C:\WINDOWS\security
2014-08-15 18:40:18 ----D---- C:\WINDOWS\system32\CatRoot
2014-08-15 18:36:20 ----D---- C:\WINDOWS\WinSxS
2014-08-15 18:36:06 ----D---- C:\Program Files\Messenger
2014-08-15 18:36:03 ----D---- C:\WINDOWS\EHome
2014-08-15 18:35:59 ----D---- C:\WINDOWS\system32\inetsrv
2014-08-15 18:35:58 ----D---- C:\WINDOWS\ime
2014-08-15 18:35:26 ----D---- C:\WINDOWS\system32\cs-cz
2014-08-15 18:35:25 ----D---- C:\WINDOWS\system32\usmt
2014-08-15 18:35:24 ----D---- C:\WINDOWS\peernet
2014-08-15 18:35:24 ----D---- C:\Program Files\Movie Maker
2014-08-15 18:31:47 ----D---- C:\WINDOWS\system32\Restore
2014-08-15 18:31:46 ----D---- C:\WINDOWS\system32\npp
2014-08-15 18:31:43 ----D---- C:\WINDOWS\msagent
2014-08-15 18:31:42 ----D---- C:\WINDOWS\srchasst
2014-08-15 18:31:41 ----D---- C:\Program Files\NetMeeting
2014-08-15 18:31:40 ----D---- C:\WINDOWS\system32\Com
2014-08-15 18:31:37 ----D---- C:\Program Files\Windows Media Player
2014-08-15 18:31:36 ----D---- C:\Program Files\Windows NT
2014-08-15 18:31:36 ----D---- C:\Program Files\Outlook Express
2014-08-15 18:31:32 ----D---- C:\Program Files\Common Files\System
2014-08-15 18:31:18 ----D---- C:\WINDOWS\system32\oobe
2014-08-15 18:31:17 ----D---- C:\WINDOWS\system
2014-08-15 18:28:08 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2014-08-15 18:02:41 ----SD---- C:\WINDOWS\Tasks
2014-08-15 10:01:13 ----RD---- C:\Program Files
2014-08-15 09:03:11 ----D---- C:\Program Files\Mozilla Firefox
2014-08-14 15:38:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\ProductData
2014-08-11 19:15:34 ----A---- C:\WINDOWS\wincmd.ini
2014-07-21 17:20:30 ----D---- C:\WINDOWS\system32\config

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2013-01-10 161368]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2013-01-10 122240]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2013-03-04 30616]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2013-01-10 105784]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 DgiVecp;Team MFP Comm Driver; C:\WINDOWS\System32\Drivers\DgiVecp.sys [2005-03-14 41984]
R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-04-15 42496]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-04-23 4402176]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-10 634880]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2013-07-24 30720]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-07-30 18048]
S3 nmwcdc;Nokia USB Communication Driver; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-07-30 23040]
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-07-30 8192]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-14 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-07-30 8192]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2013-03-21 1341664]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-07-16 182184]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-02 2151232]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-27 194032]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-20 129976]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kamarádovo PC

#4 Příspěvek od cernohous13 »

Výborně, :thumbsup:
teď probereme zbytečnosti

:arrow: Stáhni Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
Ulož jej na plochu a spusť - zobrazí se licenční podminky -> start libovolnou klávesou.
Bude vytvořena záloha a proběhne skenování.
Vyskočí log (nebo je uložen zde c:\JRT jako JRT.txt) - zkopíruj jej sem

:arrow: Stáhni AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Ulož nejlépe na plochu -> ukonči všechny programy -> spusť AdwCleaner -> klikni na Scan po dokončení na Clean
bude provedena oprava, restartuje se - (případně restartuj) a vypadne log C:\AdwCleaner\AdwCleaner[S?].txt , jeho obsah vložíš sem

:arrow: pravděpodobně budeš nucen vypnout na tu chvíli antivir - je to čisté, prověřeno
vyosek píše: :arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • :arrow: Po spuštění do okna vlozte skript nize

    Kód: Vybrat vše

    srinfo;
    autoclean;
    emptyclsid;
    iedefaults;
    process;
    hijackthis;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Log bude zde C:\zoek-results.log
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

NemamRadViry
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 12 bře 2014 16:28

Re: Kamarádovo PC

#5 Příspěvek od NemamRadViry »

JRT:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Microsoft Windows XP x86
Ran by Admin on so 16.08.2014 at 8:17:57,15
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values




~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\search settings
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\imside1egate.application.1
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{628DBF65-C210-4EDD-9A19-2FE0AB8C84C3}



~~~ Files

Successfully deleted: [File] "C:\WINDOWS\system32\conduitengine.tmp"



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\Admin\Data aplikacˇ\desktopicon"
Successfully deleted: [Folder] "C:\Documents and Settings\Admin\Data aplikacˇ\opencandy"
Successfully deleted: [Folder] "C:\Program Files\ask.com"
Successfully deleted: [Folder] "C:\WINDOWS\installer\{86d4b82a-abed-442a-be86-96357b70f4fe}"



~~~ FireFox

Failed to delete: [File] "C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml"
Successfully deleted: [File] C:\Documents and Settings\Admin\Data aplikacˇ\mozilla\firefox\profiles\ch9m0bwa.default\user.js
Successfully deleted: [File] C:\Documents and Settings\Admin\Data aplikacˇ\mozilla\firefox\profiles\ch9m0bwa.default\searchplugins\askcom.xml
Successfully deleted the following from C:\Documents and Settings\Admin\Data aplikacˇ\mozilla\firefox\profiles\ch9m0bwa.default\prefs.js

user_pref("extensions.inboxcomtoolbar@inbox.com.update.url", "hxxp://toolbar.inbox.com/toolbar/firefox/update.aspx?version=%ITEM_VERSION%&status=%ITEM_STATUS%&appVersion=%APP_
user_pref("icqtoolbar.history", "ATC%20zahr%C3%A1dky%20Borov%C3%A1%20Lada||fotbal%20taborsko||asus%20memopad%2010%20root||jak%20rootnout%20tablet||PUP||win32%2Fsomoto||android
user_pref("keyword.URL", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.1.6&q=");
Emptied folder: C:\Documents and Settings\Admin\Data aplikacˇ\mozilla\firefox\profiles\ch9m0bwa.default\minidumps [1 files]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on so 16.08.2014 at 8:22:42,34
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

AdwCleaner hodil dva logy?! Dávám sem jen ten [S0], kdybyste chtěli i ten [R0] Napište :)

# AdwCleaner v3.306 - Report created 16/08/2014 at 08:26:57
# Updated 15/08/2014 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : Admin - AMD-EG260PCW4NG
# Running from : C:\Documents and Settings\Admin\Plocha\adwcleaner_3.306.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\Ask
Folder Deleted : C:\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar
Folder Deleted : C:\Documents and Settings\Admin\Local Settings\Data aplikací\Conduit
Folder Deleted : C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\ICQToolbarData
Folder Deleted : C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
File Deleted : C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\searchplugins\icqplugin.xml
File Deleted : C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\searchplugins\icqplugin-1.xml
File Deleted : C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\searchplugins\icqplugin-2.xml

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Key Deleted : HKCU\Software\XTTB00001
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C9-189F-421A-88CD-07CFE51CFF10}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{055FD26D-3A88-4E15-963D-DC8493744B1D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{4B3803EA-5230-4DC3-A7FC-33638F3D3542}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D7E97865-918F-41E4-9CD0-25AB1C574CE8}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D3D233D5-9F6D-436C-B6C7-E63F77503B30}]
Key Deleted : HKCU\Software\ICQ\ICQToolbar
Key Deleted : HKCU\Software\ICQToolbar
Key Deleted : HKCU\Software\MGShareware
Key Deleted : HKLM\SOFTWARE\ICQ\ICQToolbar
Key Deleted : HKLM\SOFTWARE\MGShareware
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Prev Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Prev Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [SearchAssistant]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [CustomizeSearch]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]

-\\ Mozilla Firefox v12.0 (cs)

[ File : C:\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\prefs.js ]


-\\ Google Chrome v36.0.1985.143

[ File : C:\Documents and Settings\Admin\Local Settings\Data aplikací\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=U3&apn_dtid=OSJ000YYCZ&apn_uid=8E9C162A-0161-4386-BBCE-5FE240275DC8&apn_sauid=C069FBDB-44E4-4633-8D3C-921EE3BEA839

*************************

AdwCleaner[R0].txt - [5970 octets] - [16/08/2014 08:24:54]
AdwCleaner[S0].txt - [5589 octets] - [16/08/2014 08:26:57]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5649 octets] ##########

Zoek:


Zoek.exe v5.0.0.0 Updated 15-08-2014
Tool run by Admin on so 16.08.2014 at 11:38:30,89.
Systém Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Documents and Settings\Admin\Plocha\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

16.8.2014 11:39:26 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1229272821-261903793-839522115-1003\Software\Microsoft\Internet Explorer\SearchScopes\{D4D5D901-5D0F-4AA0-A8D0-D32B9B29A1C9} deleted successfully
HKEY_USERS\S-1-5-21-1229272821-261903793-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\S-1-5-21-1229272821-261903793-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully
HKEY_USERS\S-1-5-21-1229272821-261903793-839522115-1003\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1229272821-261903793-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{32683183-48a0-441b-a342-7c2a440a9478} deleted successfully

==== Running Processes ======================

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Admin\Plocha\zoek.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k imgsvc

==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\DOCUME~1\ALLUSE~1\DATAAP~1\DivX deleted
C:\Program Files\ComPlus Applications deleted
C:\Program Files\VideoDownloadConverter_4zEI deleted
C:\DOCUME~1\ALLUSE~1\DATAAP~1\ezsid.dat deleted
C:\DOCUME~1\ALLUSE~1\DATAAP~1\FreeRIP deleted
C:\DOCUME~1\ALLUSE~1\DATAAP~1\ICQ deleted
C:\DOCUME~1\ALLUSE~1\DATAAP~1\ProductData deleted
C:\WINDOWS\005366_.tmp deleted

======== System Restore Points ========

RP1421: 18.5.2014 9:11:46 - Kontrolní bod systému
RP1422: 18.5.2014 14:16:07 - Byla nainstalována aplikace Windows Internet Explorer 8.
RP1423: 19.5.2014 18:14:20 - Kontrolní bod systému
RP1424: 20.5.2014 19:24:42 - Kontrolní bod systému
RP1425: 21.5.2014 19:41:42 - Kontrolní bod systému
RP1426: 25.5.2014 16:28:29 - Kontrolní bod systému
RP1427: 26.5.2014 20:04:20 - Kontrolní bod systému
RP1428: 27.5.2014 20:39:00 - Kontrolní bod systému
RP1429: 28.5.2014 23:45:48 - Kontrolní bod systému
RP1430: 30.5.2014 16:00:17 - Kontrolní bod systému
RP1431: 31.5.2014 17:21:05 - Kontrolní bod systému
RP1432: 1.6.2014 19:59:21 - Kontrolní bod systému
RP1433: 2.6.2014 20:31:42 - Kontrolní bod systému
RP1434: 3.6.2014 20:53:01 - Kontrolní bod systému
RP1435: 4.6.2014 21:32:12 - Kontrolní bod systému
RP1436: 6.6.2014 17:29:19 - Kontrolní bod systému
RP1437: 7.6.2014 19:53:36 - Kontrolní bod systému
RP1438: 8.6.2014 20:16:10 - Kontrolní bod systému
RP1439: 9.6.2014 23:54:41 - Kontrolní bod systému
RP1440: 11.6.2014 11:13:14 - Kontrolní bod systému
RP1441: 24.6.2014 9:11:59 - Kontrolní bod systému
RP1442: 26.6.2014 16:52:28 - Kontrolní bod systému
RP1443: 27.6.2014 18:19:43 - Kontrolní bod systému
RP1444: 28.6.2014 21:36:33 - Kontrolní bod systému
RP1445: 29.6.2014 22:28:03 - Kontrolní bod systému
RP1446: 30.6.2014 15:46:03 - Operace obnovení
RP1447: 1.7.2014 20:14:40 - Kontrolní bod systému
RP1448: 7.7.2014 11:36:31 - Kontrolní bod systému
RP1449: 8.7.2014 12:54:53 - Kontrolní bod systému
RP1450: 9.7.2014 17:19:03 - Kontrolní bod systému
RP1451: 10.7.2014 21:12:15 - Kontrolní bod systému
RP1452: 12.7.2014 11:48:49 - Kontrolní bod systému
RP1453: 13.7.2014 12:26:45 - Kontrolní bod systému
RP1454: 14.7.2014 13:25:42 - Nainstalováno: Poradce pro upgrade na systém Windows 7
RP1455: 14.7.2014 13:28:12 - Nainstalováno %1 %2.
RP1456: 15.7.2014 17:00:55 - Kontrolní bod systému
RP1457: 16.7.2014 19:49:35 - Kontrolní bod systému
RP1458: 18.7.2014 16:00:16 - Kontrolní bod systému
RP1459: 19.7.2014 19:53:23 - Kontrolní bod systému
RP1460: 20.7.2014 21:16:05 - Kontrolní bod systému
RP1461: 21.7.2014 21:24:29 - Kontrolní bod systému
RP1462: 22.7.2014 22:51:32 - Kontrolní bod systému
RP1463: 24.7.2014 16:46:22 - Kontrolní bod systému
RP1464: 25.7.2014 19:49:26 - Kontrolní bod systému
RP1465: 26.7.2014 20:49:17 - Kontrolní bod systému
RP1466: 28.7.2014 18:40:27 - Kontrolní bod systému
RP1467: 29.7.2014 20:46:01 - Kontrolní bod systému
RP1468: 31.7.2014 13:00:20 - Kontrolní bod systému
RP1469: 1.8.2014 13:07:08 - Kontrolní bod systému
RP1470: 2.8.2014 17:06:02 - Kontrolní bod systému
RP1471: 3.8.2014 17:31:11 - Kontrolní bod systému
RP1472: 4.8.2014 21:07:09 - Kontrolní bod systému
RP1473: 6.8.2014 12:48:16 - Kontrolní bod systému
RP1474: 7.8.2014 19:57:26 - Kontrolní bod systému
RP1475: 8.8.2014 23:38:48 - Kontrolní bod systému
RP1476: 10.8.2014 9:17:50 - Kontrolní bod systému
RP1477: 11.8.2014 16:19:07 - Kontrolní bod systému
RP1478: 12.8.2014 19:24:09 - Kontrolní bod systému
RP1479: 14.8.2014 20:33:41 - Kontrolní bod systému
RP1480: 15.8.2014 9:39:24 - IObit Uninstaller restore point
RP1481: 15.8.2014 9:44:08 - IObit Uninstaller restore point
RP1482: 15.8.2014 9:45:03 - IObit Uninstaller restore point
RP1483: 15.8.2014 18:28:30 - Nainstalováno Windows XP Service Pack 3.
RP1484: 15.8.2014 18:51:13 - Software Distribution Service 3.0
RP1485: 15.8.2014 23:41:01 - Software Distribution Service 3.0
RP1486: 16.8.2014 8:36:19 - Software Distribution Service 3.0
RP1487: 16.8.2014 11:39:26 - zoek.exe restore point

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"bkmrksync@nokia.com"="C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync" [22.01.2011 20:48]

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.centrum.cz/"
"Search Page"="http://www.google.com"
"Prev Search Page"="http://www.google.com"
"Prev Search Bar"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
"SearchMigratedDefaultURL"="http://www.google.com/search?q={searchT ... f8&oe=utf8"
"ICQ Search"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"SearchAssistant"="http://www.google.com"
"CustomizeSearch"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
"CustomizeSearch"="http://www.google.com"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com/ie"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Prev Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Prev Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchMigratedDefaultURL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"ICQ Search"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.centrum.cz/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"SearchAssistant"="http://go.microsoft.com/fwlink/?LinkId=54896"
"CustomizeSearch"="http://go.microsoft.com/fwlink/?LinkId=54896"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{37BFD05F-12CC-4B90-9393-ADD58AA87A5F} Google Url="http://www.google.com/search?q={searchT ... 1I7ADRA_cs"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... urceid=ie7"

==== HijackThis Entries ======================

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4D054067-DE3A-48F9-B19B-BCD229B9AE8D} (PrinterHelpEtcActiveX Control) - http://www.samsungdp.com/printerhelp/Ac ... rinter.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

==== Empty IE Cache ======================

C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\TEMP(2)\Local Settings(2)\Temp(2)\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5 emptied successfully
C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=42 folders=13 276442 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\DOCUME~1\Admin\LOCALS~1\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\index.dat" not deleted

==== EOF on so 16.08.2014 at 11:46:54,32 ======================

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kamarádovo PC

#6 Příspěvek od cernohous13 »

Dobrá čistka, podíváme se po breberkách :wink:

:arrow: Stáhni a nainstaluj MBAM zde http://www.bleepingcomputer.com/downloa ... re/dl/241/ verzi 1.75
Při aktualizaci ti jako první nabídne instalaci nové verze - dáš Storno - bude aktualizována jen databáze
Po instalaci Spustit -> na 1.záložce "Kontrolor" -> Úplná kontrola -> Prohledat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení a program nezavírej
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

NemamRadViry
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 12 bře 2014 16:28

Re: Kamarádovo PC

#7 Příspěvek od NemamRadViry »

Malwarebytes Anti-Malware (Zkušební verze Malwarebytes Anti-Malware.) 1.75.0.1300
www.malwarebytes.org

Verze: v2013.04.04.07

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Admin :: AMD-EG260PCW4NG [administrátor]

Ochrana: Povolena

16.8.2014 16:06:01
MBAM-log-2014-08-16 (19-24-55).txt

Typ: Kompletní kontrola (C:\|)
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 286585
Uplynulý čas: 3 hodin, 15 minut, 27 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 1
HKLM\SOFTWARE\Microsoft\DRM\amty (Worm.Autorun) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 1
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Špatný: (1) Dobrý: (0) -> Nebyla provedena žádná instrukce.

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kamarádovo PC

#8 Příspěvek od cernohous13 »

:arrow: v MBAM nech Odstranit...

:arrow: nový RSIT

:???: jak je na tom PC?
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

NemamRadViry
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 12 bře 2014 16:28

Re: Kamarádovo PC

#9 Příspěvek od NemamRadViry »

Hotovo, pc je na tom v rámci jeho možností docela dobře.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Admin at 2014-08-17 19:13:01
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 19 GB (25%) free of 76 GB
Total RAM: 894 MB (12% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:13:17, on 17.8.2014
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\RSIT.exe
C:\Program Files\trend micro\Admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4D054067-DE3A-48F9-B19B-BCD229B9AE8D} (PrinterHelpEtcActiveX Control) - http://www.samsungdp.com/printerhelp/Ac ... rinter.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: LiveUpdate (LiveUpdateSvc) - IObit - C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 7726 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre7\bin\ssv.dll [2013-07-16 463272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-07-16 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"=C:\WINDOWS\system32\VTTimer.exe [2006-09-21 53248]
"S3Trayp"=C:\WINDOWS\system32\S3trayp.exe [2006-10-09 176128]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-04-12 16132608]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-07-15 32768]
"Samsung Common SM"=C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe [2005-07-03 372736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2013-03-21 5078504]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2013-03-10 88984]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-05-19 1957888]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Vuze\Azureus.exe"="C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Java\jre7\bin\javaw.exe"="C:\Program Files\Java\jre7\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Google\Chrome\Application\chrome.exe"="C:\Program Files\Google\Chrome\Application\chrome.exe:*:Enabled:Google Chrome"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\System32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======List of files/folders created in the last 1 month======

2014-08-17 11:30:40 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2014-08-16 16:01:15 ----D---- C:\Documents and Settings\Admin\Data aplikací\Malwarebytes
2014-08-16 16:00:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2014-08-16 16:00:48 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2014-08-16 16:00:48 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2014-08-16 12:09:10 ----SHD---- C:\Config.Msi
2014-08-16 11:54:37 ----SHD---- C:\RECYCLER
2014-08-16 11:45:33 ----A---- C:\WINDOWS\zoek-delete.exe
2014-08-16 11:45:32 ----D---- C:\WINDOWS\Temp
2014-08-16 11:38:26 ----D---- C:\zoek_backup
2014-08-16 08:25:50 ----A---- C:\WINDOWS\system32\sqlite3.dll
2014-08-16 08:24:28 ----D---- C:\AdwCleaner
2014-08-16 08:15:38 ----D---- C:\WINDOWS\ERUNT
2014-08-15 23:42:18 ----D---- C:\WINDOWS\ie8updates
2014-08-15 19:02:07 ----N---- C:\WINDOWS\system32\browserchoice.exe
2014-08-15 18:54:09 ----N---- C:\WINDOWS\system32\iacenc.dll
2014-08-15 18:51:26 ----D---- C:\WINDOWS\system32\PreInstall
2014-08-15 18:46:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2014-08-15 18:44:34 ----D---- C:\WINDOWS\Prefetch
2014-08-15 18:36:00 ----N---- C:\WINDOWS\system32\rwnh.dll
2014-08-15 18:35:59 ----N---- C:\WINDOWS\system32\smtpapi.dll
2014-08-15 18:35:43 ----N---- C:\WINDOWS\system32\aaclient.dll
2014-08-15 18:35:42 ----N---- C:\WINDOWS\system32\azroles.dll
2014-08-15 18:35:41 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2014-08-15 18:35:40 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2014-08-15 18:35:40 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2014-08-15 18:35:40 ----N---- C:\WINDOWS\system32\credssp.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapsvc.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapqec.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eappprxy.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapphost.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eappgnui.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eappcfg.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\eapolqec.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3ui.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3svc.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3msm.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dot3api.dll
2014-08-15 18:35:39 ----N---- C:\WINDOWS\system32\dimsroam.dll
2014-08-15 18:35:38 ----N---- C:\WINDOWS\system32\ieencode.dll
2014-08-15 18:35:37 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2014-08-15 18:35:36 ----N---- C:\WINDOWS\system32\kbdpash.dll
2014-08-15 18:35:36 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2014-08-15 18:35:36 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\mmcperf.exe
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\mmcex.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2014-08-15 18:35:34 ----N---- C:\WINDOWS\system32\kmsvc.dll
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\napstat.exe
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\napmontr.dll
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\napipsec.dll
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2014-08-15 18:35:33 ----N---- C:\WINDOWS\system32\mssha.dll
2014-08-15 18:35:32 ----N---- C:\WINDOWS\system32\onex.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\rasqec.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\qutil.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\qcliprov.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\qagentrt.dll
2014-08-15 18:35:31 ----N---- C:\WINDOWS\system32\qagent.dll
2014-08-15 18:35:30 ----N---- C:\WINDOWS\system32\setupn.exe
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\xpsp3res.dll
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\verclsid.exe
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\tzchange.exe
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\tspkg.dll
2014-08-15 18:35:29 ----N---- C:\WINDOWS\system32\tsgqec.dll
2014-08-15 18:35:28 ----N---- C:\WINDOWS\system32\wlanapi.dll
2014-08-15 18:35:25 ----D---- C:\WINDOWS\l2schemas
2014-08-15 18:35:24 ----D---- C:\WINDOWS\system32\cs
2014-08-15 18:35:24 ----D---- C:\WINDOWS\system32\bits
2014-08-15 18:29:49 ----D---- C:\WINDOWS\network diagnostic
2014-08-15 18:29:43 ----N---- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2014-08-15 10:01:13 ----D---- C:\Program Files\trend micro
2014-08-15 10:01:12 ----D---- C:\rsit
2014-08-15 09:58:08 ----D---- C:\Program Files\GameforgeLive
2014-08-15 09:08:46 ----D---- C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z

======List of files/folders modified in the last 1 month======

2014-08-17 19:12:54 ----D---- C:\Program Files\Adobe
2014-08-17 19:05:35 ----A---- C:\WINDOWS\SchedLgU.Txt
2014-08-17 19:05:19 ----A---- C:\WINDOWS\wincmd.ini
2014-08-17 11:30:55 ----D---- C:\WINDOWS
2014-08-17 11:30:40 ----D---- C:\WINDOWS\system32
2014-08-17 11:30:23 ----D---- C:\WINDOWS\system32\drivers
2014-08-16 20:18:04 ----HD---- C:\WINDOWS\inf
2014-08-16 16:00:48 ----RD---- C:\Program Files
2014-08-16 12:09:26 ----SHD---- C:\WINDOWS\Installer
2014-08-16 12:09:23 ----D---- C:\Program Files\Nokia
2014-08-16 12:09:23 ----D---- C:\Program Files\Common Files
2014-08-16 12:08:23 ----DC---- C:\WINDOWS\system32\DRVSTORE
2014-08-16 12:06:54 ----D---- C:\WINDOWS\system32\CatRoot2
2014-08-16 12:04:37 ----D---- C:\Program Files\CCleaner
2014-08-16 11:39:33 ----D---- C:\WINDOWS\system32\drivers\etc
2014-08-16 11:32:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-08-16 08:36:49 ----RSHDC---- C:\WINDOWS\system32\dllcache
2014-08-16 08:30:22 ----HD---- C:\WINDOWS\$hf_mig$
2014-08-16 08:11:32 ----D---- C:\WINDOWS\system32\wbem
2014-08-16 08:11:32 ----D---- C:\WINDOWS\AppPatch
2014-08-15 23:54:20 ----D---- C:\Program Files\Messenger
2014-08-15 23:53:51 ----D---- C:\WINDOWS\WinSxS
2014-08-15 23:44:02 ----D---- C:\Program Files\Outlook Express
2014-08-15 23:43:38 ----D---- C:\Program Files\Movie Maker
2014-08-15 23:42:38 ----D---- C:\Program Files\Internet Explorer
2014-08-15 18:48:48 ----D---- C:\WINDOWS\Debug
2014-08-15 18:46:44 ----D---- C:\WINDOWS\SoftwareDistribution
2014-08-15 18:46:41 ----HD---- C:\Program Files\WindowsUpdate
2014-08-15 18:46:41 ----D---- C:\WINDOWS\Help
2014-08-15 18:44:07 ----D---- C:\WINDOWS\system32\Setup
2014-08-15 18:44:06 ----RSD---- C:\WINDOWS\Fonts
2014-08-15 18:41:04 ----D---- C:\WINDOWS\security
2014-08-15 18:40:18 ----D---- C:\WINDOWS\system32\CatRoot
2014-08-15 18:36:04 ----D---- C:\WINDOWS\ServicePackFiles
2014-08-15 18:36:03 ----D---- C:\WINDOWS\EHome
2014-08-15 18:35:59 ----D---- C:\WINDOWS\system32\inetsrv
2014-08-15 18:35:58 ----D---- C:\WINDOWS\ime
2014-08-15 18:35:26 ----D---- C:\WINDOWS\system32\cs-cz
2014-08-15 18:35:25 ----D---- C:\WINDOWS\system32\usmt
2014-08-15 18:35:24 ----D---- C:\WINDOWS\peernet
2014-08-15 18:31:47 ----D---- C:\WINDOWS\system32\Restore
2014-08-15 18:31:46 ----D---- C:\WINDOWS\system32\npp
2014-08-15 18:31:43 ----D---- C:\WINDOWS\msagent
2014-08-15 18:31:42 ----D---- C:\WINDOWS\srchasst
2014-08-15 18:31:41 ----D---- C:\Program Files\NetMeeting
2014-08-15 18:31:40 ----D---- C:\WINDOWS\system32\Com
2014-08-15 18:31:37 ----D---- C:\Program Files\Windows Media Player
2014-08-15 18:31:36 ----D---- C:\Program Files\Windows NT
2014-08-15 18:31:32 ----D---- C:\Program Files\Common Files\System
2014-08-15 18:31:18 ----D---- C:\WINDOWS\system32\oobe
2014-08-15 18:31:17 ----D---- C:\WINDOWS\system
2014-08-15 18:28:17 ----D---- C:\WINDOWS\system32\ReinstallBackups
2014-08-15 18:28:08 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2014-08-15 18:02:41 ----SD---- C:\WINDOWS\Tasks
2014-08-15 09:03:11 ----D---- C:\Program Files\Mozilla Firefox
2014-07-21 17:20:30 ----D---- C:\WINDOWS\system32\config

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 gagp30kx;Filtr Microsoft Generic AGPv3.0 pro procesorovou platformu K8; C:\WINDOWS\System32\DRIVERS\gagp30kx.sys [2008-04-14 46464]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2005-12-05 20640]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 9216]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-07-13 91904]
R0 xfilt;VIA SATA IDE Hot-plug Driver; C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-10-18 17920]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2013-01-10 161368]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2013-01-10 122240]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2013-03-04 30616]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2013-01-10 105784]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 DgiVecp;Team MFP Comm Driver; C:\WINDOWS\System32\Drivers\DgiVecp.sys [2005-03-14 41984]
R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-04-15 42496]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-04-23 4402176]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 S3GIGP;S3GIGP; C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-10 634880]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2013-08-09 32384]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2013-07-24 30720]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-07-03 14976]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2013-08-29 26240]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-07-13 132224]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2013-03-21 1341664]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2013-07-16 182184]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S2 LiveUpdateSvc;LiveUpdate; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-02 2151232]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-29 116648]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-27 194032]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2013-05-20 129976]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kamarádovo PC

#10 Příspěvek od cernohous13 »

:arrow: MBAM odinstaluj
Stáhni OTM z jednoho odkazu a rozbal nejlépe na plochu.
http://oldtimer.geekstogo.com/OTM.exe
http://www.itxassociates.com/OT-Tools/OTM.exe

Spusť program „OTM.exe“
Do okna pod žlutou čáru vlož celý text zeleným písmem ze „Scriptu“

Klikni na červené „MoveIt!“

Při nabídce restartu „YES“
a log potom najdeš v C:\_OTM\MovedFiles\ - dej mi ho sem na kontrolu
Script OTM

Kód: Vybrat vše

:Commands
[resethosts]
[emptytemp]
[emptyflash]
[emptyjava]
[clearallrestorepoints]

:Files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp /s
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\zoek-delete.exe
C:\zoek_backup
C:\WINDOWS\system32\sqlite3.dll
C:\AdwCleaner
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z
C:\Program Files\IObit

:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NBJ"=-

:Services
GMSIPCI
NTACCESS
SetupNTGLM7X
JavaQuickStarterService
gupdate
LiveUpdateSvc
gupdatem
gusvc
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

NemamRadViry
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 12 bře 2014 16:28

Re: Kamarádovo PC

#11 Příspěvek od NemamRadViry »

Tohle počítač opravdu zrychlilo, děkuji :)

All processes killed
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 7135362 bytes
->Temporary Internet Files folder emptied: 62876 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 143094380 bytes
->Google Chrome cache emptied: 234799185 bytes
->Opera cache emptied: 43120464 bytes
->Flash cache emptied: 1110 bytes

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 32881 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: TEMP(2)

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 805459009 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 67 bytes
RecycleBin emptied: 17284695 bytes

Total Files Cleaned = 1 193,00 mb


[EMPTYFLASH]

User: Admin
->Flash cache emptied: 0 bytes

User: Administrator

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: TEMP(2)

Total Flash Files Cleaned = 0,00 mb


[EMPTYJAVA]

User: Admin
->Java cache emptied: 0 bytes

User: Administrator

User: All Users

User: Default User

User: LocalService

User: NetworkService

User: TEMP(2)

Total Java Files Cleaned = 0,00 mb


Restore point Set: OTM Restore Point
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\~wt19.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\~wt3.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\~wt4.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\~wt5.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\~wt6.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\~wt7.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\~wt8.tmp moved successfully.
C:\WINDOWS\system32\config\systemprofile\Data aplikací\Application Updater\temp\~wt9.tmp moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\WINDOWS\zoek-delete.exe moved successfully.
C:\zoek_backup\C_Program Files_VideoDownloadConverter_4zEI\Installr\1.bin folder moved successfully.
C:\zoek_backup\C_Program Files_VideoDownloadConverter_4zEI\Installr folder moved successfully.
C:\zoek_backup\C_Program Files_VideoDownloadConverter_4zEI folder moved successfully.
C:\zoek_backup\C_Program Files_ComPlus Applications folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_ProductData folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_ICQ\ICQNewTab\img folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_ICQ\ICQNewTab folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_ICQ folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_FreeRIP\cddb folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_FreeRIP folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_DivX\Setup\DefaultBanner folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_DivX\Setup folder moved successfully.
C:\zoek_backup\C_DOCUME~1_ALLUSE~1_DATAAP~1_DivX folder moved successfully.
C:\zoek_backup folder moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\sqlite3.dll
C:\WINDOWS\system32\sqlite3.dll moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\Mozilla Firefox\searchplugins folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files\Mozilla Firefox folder moved successfully.
C:\AdwCleaner\Quarantine\C\Program Files folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\TR folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\SK folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\RU folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\IT folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\HE folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\FR folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\ES folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\EN folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\DE folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML\BG folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar\XML folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ\ICQToolbar folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací\ICQ folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users\Data aplikací folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\All Users folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Local Settings\Data aplikací\Conduit\Community Alerts\LanguagePacks folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Local Settings\Data aplikací\Conduit\Community Alerts\Feeds folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Local Settings\Data aplikací\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Local Settings\Data aplikací\Conduit\Community Alerts\Dialogs\AppNotificationDialog folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Local Settings\Data aplikací\Conduit\Community Alerts\Dialogs folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Local Settings\Data aplikací\Conduit\Community Alerts folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Local Settings\Data aplikací\Conduit folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Local Settings\Data aplikací folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Local Settings folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\searchplugins folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\ICQToolbarData folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\sites folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\search_engine folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\META-INF folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\defaults\preferences folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\defaults folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\components folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\skin\favicon folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\skin folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\tr folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\sk folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\ru folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\it folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\he folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\fr folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\es folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\en-US folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\de folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\cs folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale\bg folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\locale folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\content\img folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome\content folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}\chrome folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07} folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default\Extensions folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací\Mozilla folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin\Data aplikací folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings\Admin folder moved successfully.
C:\AdwCleaner\Quarantine\C\Documents and Settings folder moved successfully.
C:\AdwCleaner\Quarantine\C folder moved successfully.
C:\AdwCleaner\Quarantine folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\ch9m0bwa.default folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox\Profiles folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Admin\Data aplikací\Mozilla\Firefox folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Admin\Data aplikací\Mozilla folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Admin\Data aplikací folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings\Admin folder moved successfully.
C:\AdwCleaner\Backup\C\Documents and Settings folder moved successfully.
C:\AdwCleaner\Backup\C folder moved successfully.
C:\AdwCleaner\Backup folder moved successfully.
C:\AdwCleaner folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZZZ...ZZ..ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZZ.ZZZZZ..Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZZ.Z..ZZ.Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZZ..ZZZZ...ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZZ...Z.Z....Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZZ....Z.Z...Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZ.Z...Z.ZZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZ.Z...Z....ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZ..Z.Z.....ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZ...ZZZZ.ZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZ...Z.Z..ZZ.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZZ.....Z.Z...Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZ.ZZZZZZZZZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZ.ZZZZ.ZZ....Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZ.ZZZ...ZZ.ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZ.Z.ZZ......ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZ.Z...ZZ..Z..Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZ..Z.ZZZZZZZ.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZ..Z.ZZZZ...ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZ..Z.Z....Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZZ......ZZZZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.ZZZZZZZZZ.ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.ZZZ.Z...Z..ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.ZZZ..ZZZZ.ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.ZZZ...ZZZ...Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.ZZ.ZZZ....Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.ZZ..ZZ...Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.Z.ZZZZZ.ZZ.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.Z.Z.ZZ...ZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.Z.Z....Z..Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ.Z..Z........Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ..ZZZ..Z.ZZZ.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ..ZZZ...ZZZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ..ZZ.ZZZZZZ..Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ..ZZ.Z...ZZ.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ..ZZ...ZZZZZ.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ..Z.ZZZ...ZZ.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ..Z.ZZ....Z..Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ..Z.Z...Z....Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ...ZZZZZZ...ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ...Z.ZZZZ....Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ....ZZZ..Z.ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ....Z.Z...Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\ZZ....Z....Z.Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZZZZ.ZZZZZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZZ.Z...ZZ.Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZZ...Z....Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZZ....ZZ.ZZ.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZ.ZZ.ZZZ.ZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZ..ZZZZZ.ZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZ..ZZ..Z....Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZ..Z.....Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZ...Z.Z.ZZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZ....ZZ....ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.ZZ....Z..ZZ..Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z.ZZZZZZZ.Z..Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z.ZZZZZ.Z....Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z.ZZ...ZZZZ.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z.Z.ZZZ..Z.ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z.Z.ZZ.ZZ..ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z.Z...Z.ZZZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z..ZZ.ZZZZ...Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z...ZZZ...Z..Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z...Z..ZZ..ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z....ZZ.ZZZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z....Z...Z.Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z.....Z...Z..Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.Z........ZZ.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..ZZZZZ....Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..ZZZ..Z.ZZ.ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..ZZZ.....ZZZ.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..ZZ.Z.Z.Z.Z..Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..Z.ZZZZZ.ZZ.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..Z.Z..ZZZZ..ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..Z..ZZZ.ZZ.Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..Z..ZZZ.Z..ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..Z..ZZ.ZZ.Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..Z..Z.Z.ZZ.Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..Z..Z..Z.Z.Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z..Z...ZZZZZZ.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z...ZZZ.ZZ...Z.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z...ZZ.ZZZ..Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z...ZZ.Z.ZZZ..ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z...Z...Z.Z.ZZ.Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z....ZZZZ.Z.Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z....ZZZ.Z.Z.ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z....ZZ.ZZZZZ..Z folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.....ZZZ.Z.ZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.....ZZ..Z.Z.ZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z......ZZ....ZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z\Z.........ZZZZZZ folder moved successfully.
C:\3590F75ABA9E485486C100C1A9D4FF06ZZ...ZZZZZ.ZZ..Z folder moved successfully.
C:\Program Files\IOBit\Surfing Protection\Database folder moved successfully.
C:\Program Files\IOBit\Surfing Protection\BrowerProtect folder moved successfully.
C:\Program Files\IOBit\Surfing Protection folder moved successfully.
C:\Program Files\IOBit\LiveUpdate\update\Surfing Protection\Database folder moved successfully.
C:\Program Files\IOBit\LiveUpdate\update\Surfing Protection folder moved successfully.
C:\Program Files\IOBit\LiveUpdate\update\ASCandU folder moved successfully.
C:\Program Files\IOBit\LiveUpdate\update folder moved successfully.
C:\Program Files\IOBit\LiveUpdate\Language folder moved successfully.
C:\Program Files\IOBit\LiveUpdate folder moved successfully.
C:\Program Files\IOBit\IObit Uninstaller folder moved successfully.
C:\Program Files\IOBit\Driver Booster folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\Update folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\Toolbox_Download folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\Temp folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\LatestNews folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\Database folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\BootTimeLog folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\ASCServiceLog folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\Antivirus\Scan folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\Antivirus\Plugins folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\Antivirus\BackupRec folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7\Antivirus folder moved successfully.
C:\Program Files\IOBit\Advanced SystemCare Ultimate 7 folder moved successfully.
C:\Program Files\IOBit folder moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\NBJ deleted successfully.
========== SERVICES/DRIVERS ==========
Service GMSIPCI stopped successfully!
Service GMSIPCI deleted successfully!
Service NTACCESS stopped successfully!
Service NTACCESS deleted successfully!
Service SetupNTGLM7X stopped successfully!
Service SetupNTGLM7X deleted successfully!
Service JavaQuickStarterService stopped successfully!
Service JavaQuickStarterService deleted successfully!
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service LiveUpdateSvc stopped successfully!
Service LiveUpdateSvc deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
Service gusvc stopped successfully!
Service gusvc deleted successfully!

OTM by OldTimer - Version 3.1.21.0 log created on 08182014_085821

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kamarádovo PC

#12 Příspěvek od cernohous13 »

To rád vidím, ještě to doděláme :worship:

:arrow: Spusť opět OTM -> CleanUp! - odinstaluje a vyčistí po sobě.

:arrow: Mohu doporučit kontrolu a vyčištění Ccleanerem
Stáhni Ccleaner - http://www.filehippo.com/download_ccleaner
Při instalaci vyhodit fajfku u nabízených toolbarů
Můžeš nastavit potřebný jazyk
zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.
spustit "Nástroje" > "Start" - tady můžeš zkusit deaktivovat procesy, které při spuštění nepotřebuješ (pokud by ti potom něco nechodilo, stejným způsobem je povolíš)

Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx
Ten si můžeš nechat i na budoucí občasné čištění.

:arrow: Po vyčištění by se hodila defragmentace
http://www.filehippo.com/download_defraggler

a mělo by být hotovo :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

NemamRadViry
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 12 bře 2014 16:28

Re: Kamarádovo PC

#13 Příspěvek od NemamRadViry »

Vše hotovo, děkuji za vaší pomoc :)

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Kamarádovo PC

#14 Příspěvek od cernohous13 »

Nemáš zač, rádo se stalo a jsme tady i příště :fez:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

Zamčeno