Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

v prohlížeči mi vyskakuje stále nějaké okna

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
gago1
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 24 srp 2014 08:39

Re: v prohlížeči mi vyskakuje stále nějaké okna

#16 Příspěvek od gago1 »

okno sem tam jestě nějaké vyletí ale už je to o něco lepší

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: v prohlížeči mi vyskakuje stále nějaké okna

#17 Příspěvek od vyosek »

:arrow: V jakem prohlizeci se reklamy zobrazuji??

:arrow: Poprosim o FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

gago1
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 24 srp 2014 08:39

Re: v prohlížeči mi vyskakuje stále nějaké okna

#18 Příspěvek od gago1 »

dělá to v Chrome

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-08-2014 03
Ran by Ondra (administrator) on ONDRA-NTB on 24-08-2014 21:30:23
Running from C:\Users\Ondra\Desktop
Platform: Windows 8 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(SODATSW spol. s .r.o.) C:\Program Files (x86)\StartW8\bin\StartW8Service.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(SODATSW spol. s r.o.) C:\Program Files (x86)\StartW8\bin\StartW8Button.exe
(SODATSW spol. s r. o.) C:\Program Files (x86)\StartW8\bin\StartW8Menu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
() C:\Program Files (x86)\HP HD Webcam Driver\Monitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-08-06] (IDT, Inc.)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [684064 2012-07-17] (PDF Complete Inc)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [334240 2012-08-29] (Hewlett-Packard Company)
HKLM-x32\...\Run: [BtTray] => c:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [364032 2012-08-16] (IVT Corporation)
HKLM-x32\...\Run: [HP HD Webcam Driver_Monitor] => C:\Program Files (x86)\HP HD Webcam Driver\monitor.exe [303480 2012-07-26] ()
HKLM-x32\...\Run: [StartW8Button] => C:\Program Files (x86)\StartW8\bin\StartW8Button.exe [52224 2012-12-19] (SODATSW spol. s r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
Lsa: [Notification Packages] DPPassFilter scecli
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDFJS
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDFJS
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {180790CF-A481-435A-85B2-5DACCB196C61} URL = http://search.creativetoolbars.com/resu ... earchTerms}
SearchScopes: HKCU - {D7A09E9C-7EED-4762-A797-892E5B1F47B6} URL = http://websearch.ask.com/redirect?clien ... CCDE65E05A
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll No File
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll No File
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\SKYPE4~1.DLL (Skype Technologies)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\components\npChromeDPAgent.dll (DigitalPersona, Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ondra\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2012-09-20]
FF HKLM-x32\...\Firefox\Extensions: [12x3q4@3244516.com] - C:\Program Files (x86)\Better-Surf\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha550.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha550\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta481.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta481\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha145.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha145\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha897.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha897\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1117.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1117\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1941.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1941\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home3171.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home3171\ff

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.cz/"
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Chrome DigitalPersona Agent) - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\components\npChromeDPAgent.dll (DigitalPersona, Inc.)
CHR Extension: (Dokumenty Google) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-09]
CHR Extension: (Disk Google) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-09]
CHR Extension: (YouTube) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-09]
CHR Extension: (Vyhledávání Google) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-09]
CHR Extension: (HD-V1.9) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjanbijkblmillaeknkalicgnjidndkl [2014-08-13]
CHR Extension: (VideoDownloadConverter) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkmljihjgjdghdhggolmhbjekicljfci [2014-02-03]
CHR Extension: (Skype Click to Call) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-06-24]
CHR Extension: (DigitalPersona Extension) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncffjdbbodifgldkcbhmiiljfcnbgjab [2013-04-09]
CHR Extension: (Peněženka Google) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (Gmail) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-09]
CHR HKLM-x32\...\Chrome\Extension: [bapjenajgdmnlnmbkiambfbalimpohhn] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha550\ch\WebexpEnhancedV1alpha550.crx []
CHR HKLM-x32\...\Chrome\Extension: [dopbdakonpgdhoggckhijgncmfjhfofc] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha897\ch\MediaViewerV1alpha897.crx []
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx []
CHR HKLM-x32\...\Chrome\Extension: [lnjkbbdnimnhadmalldoinnjmjmkbbme] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1117\ch\MediaViewV1alpha1117.crx []
CHR HKLM-x32\...\Chrome\Extension: [mmifolfpllfdhilecpdpmemhelmanajl] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx []
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\dpchrome.crx [2012-08-25]
CHR HKLM-x32\...\Chrome\Extension: [nihneecleegjbagaijbnpgenjjhhalmg] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1941\ch\MediaViewV1alpha1941.crx [2012-08-25]
CHR HKLM-x32\...\Chrome\Extension: [oebphjfpldppcjjoldfbilnjgocdiilh] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta481\ch\VideoPlayerV3beta481.crx [2012-08-25]
CHR HKLM-x32\...\Chrome\Extension: [onbpfdaeheoicjlbdgjmdboiggbmcohb] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home3171\ch\MediaWatchV1home3171.crx [2012-08-25]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1578496 2012-08-14] (IVT Corporation) [File not signed]
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2012-08-14] (IVT Corporation) [File not signed]
R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [488824 2012-08-25] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [477088 2012-08-01] (Hewlett-Packard Company)
S2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [85504 2012-08-15] (Hewlett-Packard Company) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [523680 2012-08-29] (Hewlett-Packard Company)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-19] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-07-19] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1134624 2012-07-17] (PDF Complete Inc)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [321536 2012-08-06] (IDT, Inc.) [File not signed]
R2 StartW8Service; C:\Program Files (x86)\StartW8\bin\StartW8Service.exe [51200 2012-12-19] (SODATSW spol. s .r.o.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
U4 BthAvrcpTg; No ImagePath
U4 BthHFEnum; No ImagePath
U4 bthhfhid; No ImagePath
R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-20] (Ralink Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48736 2012-08-14] (Ralink Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 DAMDrv; C:\Windows\system32\DRIVERS\DAMDrv64.sys [64832 2012-07-25] (Hewlett-Packard Company)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-14] (DT Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-24] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwNe64.sys [11400192 2012-06-02] (Intel Corporation)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-02] (Ralink Technology, Corp.)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-15] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-15] (Synaptics Incorporated)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1062008 2012-08-03] (Sunplus)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20288 2012-08-03] (Hewlett-Packard Development Company, L.P.)
U5 BlueletAudio; C:\Windows\SysWOW64\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-24 21:30 - 2014-08-24 21:30 - 00020451 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-08-24 21:30 - 2014-08-24 21:30 - 00000000 ____D () C:\FRST
2014-08-24 21:28 - 2014-08-24 21:28 - 02103296 _____ (Farbar) C:\Users\Ondra\Desktop\FRST64.exe
2014-08-24 21:02 - 2014-08-24 21:02 - 00020352 _____ () C:\ComboFix.txt
2014-08-24 20:37 - 2014-08-24 20:37 - 00001204 _____ () C:\CF-Submit.htm
2014-08-24 19:54 - 2014-08-24 21:06 - 00000000 ____D () C:\Qoobox
2014-08-24 19:54 - 2014-08-24 20:47 - 00000000 ____D () C:\Windows\erdnt
2014-08-24 19:54 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-24 19:54 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-24 19:54 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-24 19:50 - 2014-08-24 19:52 - 00002256 _____ () C:\Users\Ondra\Desktop\Rkill.txt
2014-08-24 19:49 - 2014-08-24 19:49 - 05572212 ____R (Swearware) C:\Users\Ondra\Desktop\ComboFix.exe
2014-08-24 19:46 - 2014-08-24 19:46 - 01944824 _____ (Bleeping Computer, LLC) C:\Users\Ondra\Desktop\rkill.com
2014-08-24 18:54 - 2014-08-24 20:48 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-08-24 18:52 - 2014-08-24 19:07 - 00000000 ____D () C:\Users\Ondra\Desktop\mbar
2014-08-24 18:48 - 2014-08-24 18:48 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Ondra\Desktop\mbar-1.07.0.1012.exe
2014-08-24 16:21 - 2014-08-24 16:21 - 00001279 _____ () C:\zoek-results.log
2014-08-24 16:19 - 2014-08-24 16:22 - 00000545 _____ () C:\runcheck.txt
2014-08-24 16:19 - 2014-08-24 16:19 - 00000000 ____D () C:\zoek_backup
2014-08-24 16:17 - 2014-08-24 16:18 - 00000000 ____D () C:\Users\Ondra\Desktop\zoek
2014-08-24 16:17 - 2014-08-24 16:17 - 04245477 _____ () C:\Users\Ondra\Downloads\zoek.rar
2014-08-24 15:34 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-24 15:33 - 2014-08-24 16:12 - 00000000 ____D () C:\AdwCleaner
2014-08-24 15:32 - 2014-08-24 15:33 - 01364531 _____ () C:\Users\Ondra\Downloads\adwcleaner_3.308.exe
2014-08-24 13:14 - 2014-08-24 13:15 - 00284104 _____ () C:\Windows\Minidump\082414-20109-01.dmp
2014-08-24 10:54 - 2014-08-24 10:54 - 00000687 _____ () C:\awh215A.tmp
2014-08-24 10:53 - 2014-08-24 20:49 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-24 10:53 - 2014-08-24 18:52 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-24 10:53 - 2014-08-24 10:53 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-24 10:53 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-24 10:53 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-24 10:52 - 2014-08-24 10:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-24 09:42 - 2014-08-24 09:42 - 00000000 ____D () C:\rsit
2014-08-24 09:42 - 2014-08-24 09:42 - 00000000 ____D () C:\Program Files\trend micro
2014-08-24 09:41 - 2014-08-24 09:41 - 01222144 _____ () C:\Users\Ondra\Desktop\RSITx64.exe
2014-08-24 09:38 - 2014-08-24 09:38 - 00000687 _____ () C:\awhC887.tmp
2014-08-23 21:17 - 2014-08-23 21:17 - 02347384 _____ (ESET) C:\Users\Ondra\Downloads\esetsmartinstaller_csy (1).exe
2014-08-23 21:06 - 2014-08-23 21:06 - 04813544 _____ (Piriform Ltd) C:\Users\Ondra\Downloads\ccsetup416.exe
2014-08-23 15:16 - 2014-08-23 15:16 - 00000687 _____ () C:\awh26F8.tmp
2014-08-23 15:15 - 2014-08-24 10:49 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-23 15:15 - 2014-08-24 10:48 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-08-23 15:15 - 2014-08-23 15:15 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-08-23 15:13 - 2014-08-23 15:14 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Ondra\Downloads\spybot-2.4.exe
2014-08-23 13:28 - 2014-08-23 13:28 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-08-23 13:27 - 2014-08-23 13:28 - 02347384 _____ (ESET) C:\Users\Ondra\Downloads\esetsmartinstaller_csy.exe
2014-08-16 19:58 - 2014-08-16 19:58 - 00000687 _____ () C:\awh9C18.tmp
2014-08-16 19:56 - 2014-08-16 19:56 - 05618120 _____ (Speedchecker Limited ) C:\Users\Ondra\Documents\PCSUUpdate.exe
2014-08-16 19:56 - 2014-08-16 19:56 - 00057128 _____ () C:\Users\Ondra\Documents\PCSpeedUp-Silent-Update.exe
2014-08-16 19:54 - 2014-08-02 02:15 - 00704480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-16 19:54 - 2014-08-02 02:15 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-16 15:29 - 2014-08-16 15:29 - 00021231 _____ () C:\Users\Ondra\Downloads\[CzT]Letopisy_Narnie_Chronicles_of_Narnia_1_2_3_2005_2010_.torrent
2014-08-15 22:04 - 2014-07-16 00:51 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-08-15 21:58 - 2014-06-11 00:44 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-15 21:58 - 2014-06-11 00:43 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-15 07:34 - 2014-07-24 14:09 - 19279872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-15 07:34 - 2014-07-24 12:51 - 14371328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-15 07:34 - 2014-06-13 03:57 - 01453400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-15 07:34 - 2014-06-13 03:55 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-15 07:33 - 2014-07-24 14:11 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-15 07:33 - 2014-07-24 14:10 - 02240000 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-15 07:33 - 2014-07-24 14:10 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-15 07:33 - 2014-07-24 14:10 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-08-15 07:33 - 2014-07-24 14:10 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 15399936 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-15 07:33 - 2014-07-24 14:09 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-15 07:33 - 2014-07-24 12:52 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-15 07:33 - 2014-07-24 12:52 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-15 07:33 - 2014-07-24 12:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 13757440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 02054656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-15 07:33 - 2014-07-24 12:51 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-15 07:33 - 2014-07-24 12:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-15 07:33 - 2014-07-24 12:29 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-15 07:33 - 2014-07-24 10:03 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-08-15 07:33 - 2014-07-16 01:03 - 01300992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-15 07:33 - 2014-07-16 00:55 - 04035072 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-15 07:33 - 2014-07-12 04:36 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-15 07:33 - 2014-06-20 01:35 - 01312768 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-15 07:33 - 2014-06-20 00:24 - 00694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-15 07:33 - 2014-06-05 19:30 - 10116608 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-08-15 07:33 - 2014-06-05 19:29 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-15 07:33 - 2014-06-05 19:28 - 02306560 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-15 07:33 - 2014-06-05 19:28 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-08-15 07:33 - 2014-06-05 15:12 - 08857600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-08-15 07:33 - 2014-06-05 15:11 - 02416128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-15 07:32 - 2014-06-05 19:56 - 00112984 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-15 07:32 - 2014-06-05 19:29 - 00393216 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-15 07:32 - 2014-06-05 15:11 - 00295424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-15 07:32 - 2014-06-05 15:10 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-15 07:32 - 2014-06-05 15:10 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-08-15 07:32 - 2014-05-29 06:04 - 00094552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2014-08-15 07:32 - 2014-05-08 03:34 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-08-13 09:21 - 2014-08-13 09:21 - 00000687 _____ () C:\awh5A3A.tmp
2014-08-12 21:12 - 2014-08-12 21:12 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Seznam.cz
2014-08-12 13:33 - 2014-08-12 13:33 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-07-27 21:09 - 2014-08-12 21:09 - 00002094 _____ () C:\Users\Ondra\Desktop\Continue installation - Windows Update KB12695 Installation.lnk
2014-07-27 11:09 - 2014-07-27 11:09 - 00013476 _____ () C:\Users\Ondra\Downloads\[CzT]2Bobule_2Grapes (1).torrent
2014-07-27 11:07 - 2014-07-27 11:07 - 00013101 _____ () C:\Users\Ondra\Downloads\[CzT]2Bobule_2Grapes.torrent
2014-07-27 10:46 - 2014-07-27 10:46 - 00014659 _____ () C:\Users\Ondra\Downloads\[CzT]Bobule.torrent
2014-07-27 10:42 - 2014-07-27 10:42 - 00029229 _____ () C:\Users\Ondra\Downloads\Bobule.2008.DVDRip.XviD.CZ-LeMuR.torrent
2014-07-27 10:41 - 2014-07-27 10:41 - 00048162 _____ () C:\Users\Ondra\Downloads\Bobule.2008.DVDR.CZ-LeMuR.torrent
2014-07-27 08:41 - 2014-07-27 08:41 - 00000000 ____D () C:\ProgramData\Bitstream
2014-07-27 08:28 - 2014-08-24 19:09 - 00435320 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-27 08:28 - 2014-07-27 08:28 - 00279528 _____ () C:\Windows\Minidump\072714-29812-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-24 21:30 - 2014-08-24 21:30 - 00020451 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-08-24 21:30 - 2014-08-24 21:30 - 00000000 ____D () C:\FRST
2014-08-24 21:28 - 2014-08-24 21:28 - 02103296 _____ (Farbar) C:\Users\Ondra\Desktop\FRST64.exe
2014-08-24 21:09 - 2012-09-20 10:31 - 02026199 _____ () C:\Windows\WindowsUpdate.log
2014-08-24 21:06 - 2014-08-24 19:54 - 00000000 ____D () C:\Qoobox
2014-08-24 21:02 - 2014-08-24 21:02 - 00020352 _____ () C:\ComboFix.txt
2014-08-24 21:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-08-24 20:50 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-08-24 20:49 - 2014-08-24 10:53 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-24 20:49 - 2012-09-20 11:14 - 00004524 _____ () C:\Windows\SysWOW64\LOCALSERVICE.INI
2014-08-24 20:49 - 2012-09-09 07:14 - 00000000 ____D () C:\ProgramData\PDFC
2014-08-24 20:49 - 2012-08-16 02:46 - 00000787 _____ () C:\Windows\SysWOW64\bscs.ini
2014-08-24 20:49 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-24 20:48 - 2014-08-24 18:54 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-08-24 20:48 - 2012-08-01 23:23 - 00058260 _____ () C:\Windows\PFRO.log
2014-08-24 20:48 - 2012-07-26 07:26 - 90439680 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-08-24 20:48 - 2012-07-26 07:26 - 27525120 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-08-24 20:48 - 2012-07-26 07:26 - 00786432 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-08-24 20:48 - 2012-07-26 07:26 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-08-24 20:48 - 2012-07-26 07:26 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-08-24 20:47 - 2014-08-24 19:54 - 00000000 ____D () C:\Windows\erdnt
2014-08-24 20:37 - 2014-08-24 20:37 - 00001204 _____ () C:\CF-Submit.htm
2014-08-24 20:20 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-08-24 20:02 - 2013-04-08 23:35 - 00000000 ____D () C:\Users\Ondra
2014-08-24 19:52 - 2014-08-24 19:50 - 00002256 _____ () C:\Users\Ondra\Desktop\Rkill.txt
2014-08-24 19:49 - 2014-08-24 19:49 - 05572212 ____R (Swearware) C:\Users\Ondra\Desktop\ComboFix.exe
2014-08-24 19:46 - 2014-08-24 19:46 - 01944824 _____ (Bleeping Computer, LLC) C:\Users\Ondra\Desktop\rkill.com
2014-08-24 19:35 - 2013-04-08 23:47 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2315802412-815962061-3052649632-1002
2014-08-24 19:09 - 2014-07-27 08:28 - 00435320 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-24 19:09 - 2012-09-20 11:14 - 00000088 _____ () C:\Windows\SysWOW64\LOCALDEVICE.INI
2014-08-24 19:09 - 2012-07-26 09:20 - 00000000 ____D () C:\Windows\Setup
2014-08-24 19:07 - 2014-08-24 18:52 - 00000000 ____D () C:\Users\Ondra\Desktop\mbar
2014-08-24 18:52 - 2014-08-24 10:53 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-24 18:48 - 2014-08-24 18:48 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Ondra\Desktop\mbar-1.07.0.1012.exe
2014-08-24 16:22 - 2014-08-24 16:19 - 00000545 _____ () C:\runcheck.txt
2014-08-24 16:21 - 2014-08-24 16:21 - 00001279 _____ () C:\zoek-results.log
2014-08-24 16:20 - 2013-04-22 21:07 - 00000000 ____D () C:\Users\Ondra\AppData\Local\CrashDumps
2014-08-24 16:19 - 2014-08-24 16:19 - 00000000 ____D () C:\zoek_backup
2014-08-24 16:18 - 2014-08-24 16:17 - 00000000 ____D () C:\Users\Ondra\Desktop\zoek
2014-08-24 16:17 - 2014-08-24 16:17 - 04245477 _____ () C:\Users\Ondra\Downloads\zoek.rar
2014-08-24 16:16 - 2014-04-16 18:43 - 00000489 _____ () C:\Users\Ondra\rgmnr
2014-08-24 16:12 - 2014-08-24 15:33 - 00000000 ____D () C:\AdwCleaner
2014-08-24 15:33 - 2014-08-24 15:32 - 01364531 _____ () C:\Users\Ondra\Downloads\adwcleaner_3.308.exe
2014-08-24 13:21 - 2012-09-09 07:46 - 00755956 _____ () C:\Windows\system32\perfh005.dat
2014-08-24 13:21 - 2012-09-09 07:46 - 00162886 _____ () C:\Windows\system32\perfc005.dat
2014-08-24 13:21 - 2012-07-26 09:28 - 01851486 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-24 13:15 - 2014-08-24 13:14 - 00284104 _____ () C:\Windows\Minidump\082414-20109-01.dmp
2014-08-24 13:14 - 2013-06-01 19:32 - 614507469 _____ () C:\Windows\MEMORY.DMP
2014-08-24 13:14 - 2013-06-01 19:32 - 00000000 ____D () C:\Windows\Minidump
2014-08-24 10:54 - 2014-08-24 10:54 - 00000687 _____ () C:\awh215A.tmp
2014-08-24 10:53 - 2014-08-24 10:53 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-24 10:52 - 2014-08-24 10:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-24 10:49 - 2014-08-23 15:15 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-24 10:48 - 2014-08-23 15:15 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-08-24 10:48 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-08-24 09:42 - 2014-08-24 09:42 - 00000000 ____D () C:\rsit
2014-08-24 09:42 - 2014-08-24 09:42 - 00000000 ____D () C:\Program Files\trend micro
2014-08-24 09:41 - 2014-08-24 09:41 - 01222144 _____ () C:\Users\Ondra\Desktop\RSITx64.exe
2014-08-24 09:38 - 2014-08-24 09:38 - 00000687 _____ () C:\awhC887.tmp
2014-08-23 21:17 - 2014-08-23 21:17 - 02347384 _____ (ESET) C:\Users\Ondra\Downloads\esetsmartinstaller_csy (1).exe
2014-08-23 21:06 - 2014-08-23 21:06 - 04813544 _____ (Piriform Ltd) C:\Users\Ondra\Downloads\ccsetup416.exe
2014-08-23 15:16 - 2014-08-23 15:16 - 00000687 _____ () C:\awh26F8.tmp
2014-08-23 15:15 - 2014-08-23 15:15 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-08-23 15:14 - 2014-08-23 15:13 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Ondra\Downloads\spybot-2.4.exe
2014-08-23 15:07 - 2013-08-04 15:00 - 00000000 ____D () C:\Firefox
2014-08-23 14:55 - 2014-04-16 12:55 - 00000000 ____D () C:\Program Files (x86)\demoni 2013 horor avi cz dabing cely film
2014-08-23 13:28 - 2014-08-23 13:28 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-08-23 13:28 - 2014-08-23 13:27 - 02347384 _____ (ESET) C:\Users\Ondra\Downloads\esetsmartinstaller_csy.exe
2014-08-20 19:14 - 2013-04-09 08:52 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-20 19:13 - 2013-04-09 08:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-08-17 20:37 - 2014-06-24 19:11 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Skype
2014-08-17 19:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-08-17 09:55 - 2013-12-24 12:25 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\uTorrent
2014-08-16 19:58 - 2014-08-16 19:58 - 00000687 _____ () C:\awh9C18.tmp
2014-08-16 19:56 - 2014-08-16 19:56 - 05618120 _____ (Speedchecker Limited ) C:\Users\Ondra\Documents\PCSUUpdate.exe
2014-08-16 19:56 - 2014-08-16 19:56 - 00057128 _____ () C:\Users\Ondra\Documents\PCSpeedUp-Silent-Update.exe
2014-08-16 19:56 - 2014-06-19 21:56 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\QuickScan
2014-08-16 19:50 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-08-16 16:07 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-08-16 15:44 - 2013-04-09 00:13 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-16 15:29 - 2014-08-16 15:29 - 00021231 _____ () C:\Users\Ondra\Downloads\[CzT]Letopisy_Narnie_Chronicles_of_Narnia_1_2_3_2005_2010_.torrent
2014-08-16 11:45 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-16 10:30 - 2013-08-04 13:38 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 22:16 - 2013-04-09 09:17 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-13 19:31 - 2014-06-24 19:10 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-13 09:21 - 2014-08-13 09:21 - 00000687 _____ () C:\awh5A3A.tmp
2014-08-12 21:12 - 2014-08-12 21:12 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Seznam.cz
2014-08-12 21:09 - 2014-07-27 21:09 - 00002094 _____ () C:\Users\Ondra\Desktop\Continue installation - Windows Update KB12695 Installation.lnk
2014-08-12 13:33 - 2014-08-12 13:33 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-08-02 02:15 - 2014-08-16 19:54 - 00704480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-02 02:15 - 2014-08-16 19:54 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-27 11:09 - 2014-07-27 11:09 - 00013476 _____ () C:\Users\Ondra\Downloads\[CzT]2Bobule_2Grapes (1).torrent
2014-07-27 11:07 - 2014-07-27 11:07 - 00013101 _____ () C:\Users\Ondra\Downloads\[CzT]2Bobule_2Grapes.torrent
2014-07-27 10:46 - 2014-07-27 10:46 - 00014659 _____ () C:\Users\Ondra\Downloads\[CzT]Bobule.torrent
2014-07-27 10:42 - 2014-07-27 10:42 - 00029229 _____ () C:\Users\Ondra\Downloads\Bobule.2008.DVDRip.XviD.CZ-LeMuR.torrent
2014-07-27 10:41 - 2014-07-27 10:41 - 00048162 _____ () C:\Users\Ondra\Downloads\Bobule.2008.DVDR.CZ-LeMuR.torrent
2014-07-27 08:41 - 2014-07-27 08:41 - 00000000 ____D () C:\ProgramData\Bitstream
2014-07-27 08:41 - 2014-02-16 20:44 - 00000000 ____D () C:\ProgramData\Corel
2014-07-27 08:28 - 2014-07-27 08:28 - 00279528 _____ () C:\Windows\Minidump\072714-29812-01.dmp
2014-07-26 23:41 - 2013-04-13 16:58 - 00000024 _____ () C:\SROF.ini
2014-07-26 20:27 - 2013-04-09 10:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-26 20:26 - 2013-04-09 10:40 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-26 20:26 - 2013-04-09 10:40 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-23 15:00

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: v prohlížeči mi vyskakuje stále nějaké okna

#19 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    
    SearchScopes: HKCU - {180790CF-A481-435A-85B2-5DACCB196C61} URL = http://search.creativetoolbars.com/resu ... tbar&g=&q={searchTerms}
    SearchScopes: HKCU - {D7A09E9C-7EED-4762-A797-892E5B1F47B6} URL = http://websearch.ask.com/redirect?clien ... &src=kw&q={searchTerms}&locale=en_EU&apn_ptnrs=^RY&apn_dtid=^YYYYYY^V2^CZ&apn_uid=1763D2DA-4271-408B-A6B4-B9B854F077F4&apn_sauid=B9039284-2294-415E-BF03-AFCCDE65E05A
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll No File
    
    F HKLM-x32\...\Firefox\Extensions: [12x3q4@3244516.com] - C:\Program Files (x86)\Better-Surf\ff
    FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha550.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha550\ff
    FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta481.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta481\ff
    FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha145.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha145\ff
    FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha897.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha897\ff
    FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1117.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1117\ff
    FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1941.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1941\ff
    FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home3171.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home3171\ff
    
    CHR Extension: (HD-V1.9) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjanbijkblmillaeknkalicgnjidndkl [2014-08-13]
    CHR Extension: (VideoDownloadConverter) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkmljihjgjdghdhggolmhbjekicljfci [2014-02-03]
    CHR Extension: (Skype Click to Call) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-06-24]
    CHR HKLM-x32\...\Chrome\Extension: [bapjenajgdmnlnmbkiambfbalimpohhn] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha550\ch\WebexpEnhancedV1alpha550.crx []
    CHR HKLM-x32\...\Chrome\Extension: [dopbdakonpgdhoggckhijgncmfjhfofc] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha897\ch\MediaViewerV1alpha897.crx []
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx []
    CHR HKLM-x32\...\Chrome\Extension: [lnjkbbdnimnhadmalldoinnjmjmkbbme] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1117\ch\MediaViewV1alpha1117.crx []
    CHR HKLM-x32\...\Chrome\Extension: [mmifolfpllfdhilecpdpmemhelmanajl] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx []
    CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\dpchrome.crx [2012-08-25]
    CHR HKLM-x32\...\Chrome\Extension: [nihneecleegjbagaijbnpgenjjhhalmg] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1941\ch\MediaViewV1alpha1941.crx [2012-08-25]
    CHR HKLM-x32\...\Chrome\Extension: [oebphjfpldppcjjoldfbilnjgocdiilh] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta481\ch\VideoPlayerV3beta481.crx [2012-08-25]
    CHR HKLM-x32\...\Chrome\Extension: [onbpfdaeheoicjlbdgjmdboiggbmcohb] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home3171\ch\MediaWatchV1home3171.crx [2012-08-25]
    
    C:\Program Files (x86)\WebexpEnhancedV1
    C:\Program Files (x86)\Better-Surf
    C:\Program Files (x86)\MediaViewerV1
    C:\Program Files (x86)\MediaViewV1
    C:\Program Files (x86)\MediaWatchV1
    C:\Program Files (x86)\VideoPlayerV3
    2014-08-24 21:02 - 2014-08-24 21:02 - 00020352 _____ () C:\ComboFix.txt
    2014-08-24 20:37 - 2014-08-24 20:37 - 00001204 _____ () C:\CF-Submit.htm
    2014-08-24 18:52 - 2014-08-24 19:07 - 00000000 ____D () C:\Users\Ondra\Desktop\mbar
    2014-08-24 18:48 - 2014-08-24 18:48 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Ondra\Desktop\mbar-1.07.0.1012.exe
    2014-08-24 16:21 - 2014-08-24 16:21 - 00001279 _____ () C:\zoek-results.log
    2014-08-24 16:19 - 2014-08-24 16:22 - 00000545 _____ () C:\runcheck.txt
    2014-08-24 16:19 - 2014-08-24 16:19 - 00000000 ____D () C:\zoek_backup
    2014-08-24 16:17 - 2014-08-24 16:18 - 00000000 ____D () C:\Users\Ondra\Desktop\zoek
    2014-08-24 16:17 - 2014-08-24 16:17 - 04245477 _____ () C:\Users\Ondra\Downloads\zoek.rar
    2014-08-24 15:34 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
    2014-08-24 15:33 - 2014-08-24 16:12 - 00000000 ____D () C:\AdwCleaner
    2014-08-24 15:32 - 2014-08-24 15:33 - 01364531 _____ () C:\Users\Ondra\Downloads\adwcleaner_3.308.exe
    2014-08-24 13:14 - 2014-08-24 13:15 - 00284104 _____ () C:\Windows\Minidump\082414-20109-01.dmp
    2014-08-24 10:54 - 2014-08-24 10:54 - 00000687 _____ () C:\awh215A.tmp
    2014-08-24 09:42 - 2014-08-24 09:42 - 00000000 ____D () C:\rsit
    2014-08-24 09:42 - 2014-08-24 09:42 - 00000000 ____D () C:\Program Files\trend micro
    2014-08-24 09:41 - 2014-08-24 09:41 - 01222144 _____ () C:\Users\Ondra\Desktop\RSITx64.exe
    2014-08-23 21:17 - 2014-08-23 21:17 - 02347384 _____ (ESET) C:\Users\Ondra\Downloads\esetsmartinstaller_csy (1).exe
    2014-08-23 21:06 - 2014-08-23 21:06 - 04813544 _____ (Piriform Ltd) C:\Users\Ondra\Downloads\ccsetup416.exe
    2014-08-23 15:16 - 2014-08-23 15:16 - 00000687 _____ () C:\awh26F8.tmp
    2014-08-23 15:15 - 2014-08-24 10:49 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
    2014-08-23 15:15 - 2014-08-24 10:48 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
    2014-08-23 15:15 - 2014-08-23 15:15 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
    2014-08-23 15:13 - 2014-08-23 15:14 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Ondra\Downloads\spybot-2.4.exe
    2014-08-16 19:56 - 2014-08-16 19:56 - 05618120 _____ (Speedchecker Limited ) C:\Users\Ondra\Documents\PCSUUpdate.exe
    2014-08-16 19:56 - 2014-08-16 19:56 - 00057128 _____ () C:\Users\Ondra\Documents\PCSpeedUp-Silent-Update.exe
    
    Hosts:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

gago1
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 24 srp 2014 08:39

Re: v prohlížeči mi vyskakuje stále nějaké okna

#20 Příspěvek od gago1 »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-08-2014 03
Ran by Ondra at 2014-08-24 22:00:12 Run:1
Running from C:\Users\Ondra\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

SearchScopes: HKCU - {180790CF-A481-435A-85B2-5DACCB196C61} URL = http://search.creativetoolbars.com/resu ... tbar&g=&q={searchTerms}
SearchScopes: HKCU - {D7A09E9C-7EED-4762-A797-892E5B1F47B6} URL = http://websearch.ask.com/redirect?clien ... &src=kw&q={searchTerms}&locale=en_EU&apn_ptnrs=^RY&apn_dtid=^YYYYYY^V2^CZ&apn_uid=1763D2DA-4271-408B-A6B4-B9B854F077F4&apn_sauid=B9039284-2294-415E-BF03-AFCCDE65E05A
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll No File

F HKLM-x32\...\Firefox\Extensions: [12x3q4@3244516.com] - C:\Program Files (x86)\Better-Surf\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha550.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha550\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta481.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta481\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha145.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha145\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha897.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha897\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1117.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1117\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1941.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1941\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home3171.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home3171\ff

CHR Extension: (HD-V1.9) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjanbijkblmillaeknkalicgnjidndkl [2014-08-13]
CHR Extension: (VideoDownloadConverter) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkmljihjgjdghdhggolmhbjekicljfci [2014-02-03]
CHR Extension: (Skype Click to Call) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-06-24]
CHR HKLM-x32\...\Chrome\Extension: [bapjenajgdmnlnmbkiambfbalimpohhn] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha550\ch\WebexpEnhancedV1alpha550.crx []
CHR HKLM-x32\...\Chrome\Extension: [dopbdakonpgdhoggckhijgncmfjhfofc] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha897\ch\MediaViewerV1alpha897.crx []
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx []
CHR HKLM-x32\...\Chrome\Extension: [lnjkbbdnimnhadmalldoinnjmjmkbbme] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1117\ch\MediaViewV1alpha1117.crx []
CHR HKLM-x32\...\Chrome\Extension: [mmifolfpllfdhilecpdpmemhelmanajl] - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx []
CHR HKLM-x32\...\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\dpchrome.crx [2012-08-25]
CHR HKLM-x32\...\Chrome\Extension: [nihneecleegjbagaijbnpgenjjhhalmg] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1941\ch\MediaViewV1alpha1941.crx [2012-08-25]
CHR HKLM-x32\...\Chrome\Extension: [oebphjfpldppcjjoldfbilnjgocdiilh] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta481\ch\VideoPlayerV3beta481.crx [2012-08-25]
CHR HKLM-x32\...\Chrome\Extension: [onbpfdaeheoicjlbdgjmdboiggbmcohb] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home3171\ch\MediaWatchV1home3171.crx [2012-08-25]

C:\Program Files (x86)\WebexpEnhancedV1
C:\Program Files (x86)\Better-Surf
C:\Program Files (x86)\MediaViewerV1
C:\Program Files (x86)\MediaViewV1
C:\Program Files (x86)\MediaWatchV1
C:\Program Files (x86)\VideoPlayerV3
2014-08-24 21:02 - 2014-08-24 21:02 - 00020352 _____ () C:\ComboFix.txt
2014-08-24 20:37 - 2014-08-24 20:37 - 00001204 _____ () C:\CF-Submit.htm
2014-08-24 18:52 - 2014-08-24 19:07 - 00000000 ____D () C:\Users\Ondra\Desktop\mbar
2014-08-24 18:48 - 2014-08-24 18:48 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Ondra\Desktop\mbar-1.07.0.1012.exe
2014-08-24 16:21 - 2014-08-24 16:21 - 00001279 _____ () C:\zoek-results.log
2014-08-24 16:19 - 2014-08-24 16:22 - 00000545 _____ () C:\runcheck.txt
2014-08-24 16:19 - 2014-08-24 16:19 - 00000000 ____D () C:\zoek_backup
2014-08-24 16:17 - 2014-08-24 16:18 - 00000000 ____D () C:\Users\Ondra\Desktop\zoek
2014-08-24 16:17 - 2014-08-24 16:17 - 04245477 _____ () C:\Users\Ondra\Downloads\zoek.rar
2014-08-24 15:34 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-08-24 15:33 - 2014-08-24 16:12 - 00000000 ____D () C:\AdwCleaner
2014-08-24 15:32 - 2014-08-24 15:33 - 01364531 _____ () C:\Users\Ondra\Downloads\adwcleaner_3.308.exe
2014-08-24 13:14 - 2014-08-24 13:15 - 00284104 _____ () C:\Windows\Minidump\082414-20109-01.dmp
2014-08-24 10:54 - 2014-08-24 10:54 - 00000687 _____ () C:\awh215A.tmp
2014-08-24 09:42 - 2014-08-24 09:42 - 00000000 ____D () C:\rsit
2014-08-24 09:42 - 2014-08-24 09:42 - 00000000 ____D () C:\Program Files\trend micro
2014-08-24 09:41 - 2014-08-24 09:41 - 01222144 _____ () C:\Users\Ondra\Desktop\RSITx64.exe
2014-08-23 21:17 - 2014-08-23 21:17 - 02347384 _____ (ESET) C:\Users\Ondra\Downloads\esetsmartinstaller_csy (1).exe
2014-08-23 21:06 - 2014-08-23 21:06 - 04813544 _____ (Piriform Ltd) C:\Users\Ondra\Downloads\ccsetup416.exe
2014-08-23 15:16 - 2014-08-23 15:16 - 00000687 _____ () C:\awh26F8.tmp
2014-08-23 15:15 - 2014-08-24 10:49 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-08-23 15:15 - 2014-08-24 10:48 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-08-23 15:15 - 2014-08-23 15:15 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-08-23 15:13 - 2014-08-23 15:14 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Ondra\Downloads\spybot-2.4.exe
2014-08-16 19:56 - 2014-08-16 19:56 - 05618120 _____ (Speedchecker Limited ) C:\Users\Ondra\Documents\PCSUUpdate.exe
2014-08-16 19:56 - 2014-08-16 19:56 - 00057128 _____ () C:\Users\Ondra\Documents\PCSpeedUp-Silent-Update.exe

Hosts:
Reboot:
End
*****************

C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{180790CF-A481-435A-85B2-5DACCB196C61}" => Key deleted successfully.
"HKCR\CLSID\{180790CF-A481-435A-85B2-5DACCB196C61}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D7A09E9C-7EED-4762-A797-892E5B1F47B6}" => Key deleted successfully.
"HKCR\CLSID\{D7A09E9C-7EED-4762-A797-892E5B1F47B6}" => Key not found.
"HKCR\PROTOCOLS\Handler\skypec2c" => Key deleted successfully.
"HKCR\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key deleted successfully.
F HKLM-x32\...\Firefox\Extensions: [12x3q4@3244516.com] - C:\Program Files (x86)\Better-Surf\ff => Error: No automatic fix found for this entry.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@WebexpEnhancedV1alpha550.net => value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@VideoPlayerV3beta481.net => value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaPlayerV1alpha145.net => value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaViewerV1alpha897.net => value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaViewV1alpha1117.net => value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaViewV1alpha1941.net => value deleted successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ext@MediaWatchV1home3171.net => value deleted successfully.
C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjanbijkblmillaeknkalicgnjidndkl => Moved successfully.
C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkmljihjgjdghdhggolmhbjekicljfci => Moved successfully.
C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl => Moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bapjenajgdmnlnmbkiambfbalimpohhn" => Key deleted successfully.
"C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha550\ch\WebexpEnhancedV1alpha550.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dopbdakonpgdhoggckhijgncmfjhfofc" => Key deleted successfully.
"C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha897\ch\MediaViewerV1alpha897.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => Key deleted successfully.
"C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lnjkbbdnimnhadmalldoinnjmjmkbbme" => Key deleted successfully.
"C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1117\ch\MediaViewV1alpha1117.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mmifolfpllfdhilecpdpmemhelmanajl" => Key deleted successfully.
"C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ch\BetterSurfPlus.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ncffjdbbodifgldkcbhmiiljfcnbgjab" => Key deleted successfully.
c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\dpchrome.crx => Moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nihneecleegjbagaijbnpgenjjhhalmg" => Key deleted successfully.
"C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1941\ch\MediaViewV1alpha1941.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\oebphjfpldppcjjoldfbilnjgocdiilh" => Key deleted successfully.
"C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta481\ch\VideoPlayerV3beta481.crx" => File/Directory not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\onbpfdaeheoicjlbdgjmdboiggbmcohb" => Key deleted successfully.
"C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home3171\ch\MediaWatchV1home3171.crx" => File/Directory not found.
"C:\Program Files (x86)\WebexpEnhancedV1" => File/Directory not found.
"C:\Program Files (x86)\Better-Surf" => File/Directory not found.
"C:\Program Files (x86)\MediaViewerV1" => File/Directory not found.
"C:\Program Files (x86)\MediaViewV1" => File/Directory not found.
"C:\Program Files (x86)\MediaWatchV1" => File/Directory not found.
"C:\Program Files (x86)\VideoPlayerV3" => File/Directory not found.
C:\ComboFix.txt => Moved successfully.
C:\CF-Submit.htm => Moved successfully.
C:\Users\Ondra\Desktop\mbar => Moved successfully.
C:\Users\Ondra\Desktop\mbar-1.07.0.1012.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\runcheck.txt => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Ondra\Desktop\zoek => Moved successfully.
C:\Users\Ondra\Downloads\zoek.rar => Moved successfully.
C:\Windows\SysWOW64\sqlite3.dll => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Ondra\Downloads\adwcleaner_3.308.exe => Moved successfully.
C:\Windows\Minidump\082414-20109-01.dmp => Moved successfully.
C:\awh215A.tmp => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Users\Ondra\Desktop\RSITx64.exe => Moved successfully.
C:\Users\Ondra\Downloads\esetsmartinstaller_csy (1).exe => Moved successfully.
C:\Users\Ondra\Downloads\ccsetup416.exe => Moved successfully.
C:\awh26F8.tmp => Moved successfully.
C:\Program Files (x86)\Spybot - Search & Destroy 2 => Moved successfully.
C:\ProgramData\Spybot - Search & Destroy => Moved successfully.
C:\Windows\System32\Tasks\Safer-Networking => Moved successfully.
C:\Users\Ondra\Downloads\spybot-2.4.exe => Moved successfully.
C:\Users\Ondra\Documents\PCSUUpdate.exe => Moved successfully.
C:\Users\Ondra\Documents\PCSpeedUp-Silent-Update.exe => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.


The system needed a reboot.

==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: v prohlížeči mi vyskakuje stále nějaké okna

#21 Příspěvek od vyosek »

Dejte novy log z FRST - Scan

Reklamy stale vyskakuji??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

gago1
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 24 srp 2014 08:39

Re: v prohlížeči mi vyskakuje stále nějaké okna

#22 Příspěvek od gago1 »

vypadá to že už nevyskakují



Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-08-2014 03
Ran by Ondra (administrator) on ONDRA-NTB on 25-08-2014 08:07:51
Running from C:\Users\Ondra\Desktop
Platform: Windows 8 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(DigitalPersona, Inc.) C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(SODATSW spol. s .r.o.) C:\Program Files (x86)\StartW8\bin\StartW8Service.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(SODATSW spol. s r.o.) C:\Program Files (x86)\StartW8\bin\StartW8Button.exe
(SODATSW spol. s r. o.) C:\Program Files (x86)\StartW8\bin\StartW8Menu.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
() C:\Program Files (x86)\HP HD Webcam Driver\Monitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16683_none_62280e15510f8e79\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-08-06] (IDT, Inc.)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [684064 2012-07-17] (PDF Complete Inc)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [334240 2012-08-29] (Hewlett-Packard Company)
HKLM-x32\...\Run: [BtTray] => c:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [364032 2012-08-16] (IVT Corporation)
HKLM-x32\...\Run: [HP HD Webcam Driver_Monitor] => C:\Program Files (x86)\HP HD Webcam Driver\monitor.exe [303480 2012-07-26] ()
HKLM-x32\...\Run: [StartW8Button] => C:\Program Files (x86)\StartW8\bin\StartW8Button.exe [52224 2012-12-19] (SODATSW spol. s r.o.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\DeviceNP-x32: DeviceNP.dll [X]
Lsa: [Notification Packages] DPPassFilter scecli
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDFJS
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=CMNTDFJS
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll No File
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll No File
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\components\npChromeDPAgent.dll (DigitalPersona, Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ondra\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF HKLM-x32\...\Firefox\Extensions: [otis@digitalpersona.com] - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2012-09-20]
FF HKLM-x32\...\Firefox\Extensions: [12x3q4@3244516.com] - C:\Program Files (x86)\Better-Surf\ff

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.cz/"
CHR DefaultSuggestURL: {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.143\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Chrome DigitalPersona Agent) - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\components\npChromeDPAgent.dll (DigitalPersona, Inc.)
CHR Extension: (Dokumenty Google) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-04-09]
CHR Extension: (Disk Google) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-09]
CHR Extension: (YouTube) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-09]
CHR Extension: (Vyhledávání Google) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-09]
CHR Extension: (Peněženka Google) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (Gmail) - C:\Users\Ondra\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-09]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1578496 2012-08-14] (IVT Corporation) [File not signed]
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [138752 2012-08-14] (IVT Corporation) [File not signed]
R2 DpHost; c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [488824 2012-08-25] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [477088 2012-08-01] (Hewlett-Packard Company)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [85504 2012-08-15] (Hewlett-Packard Company) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [523680 2012-08-29] (Hewlett-Packard Company)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-07-19] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-07-19] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1134624 2012-07-17] (PDF Complete Inc)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [321536 2012-08-06] (IDT, Inc.) [File not signed]
R2 StartW8Service; C:\Program Files (x86)\StartW8\bin\StartW8Service.exe [51200 2012-12-19] (SODATSW spol. s .r.o.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
U5 BlueletAudio; C:\Windows\System32\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
U4 BthAvrcpTg; No ImagePath
U4 BthHFEnum; No ImagePath
U4 bthhfhid; No ImagePath
R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-20] (Ralink Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48736 2012-08-14] (Ralink Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 DAMDrv; C:\Windows\system32\DRIVERS\DAMDrv64.sys [64832 2012-07-25] (Hewlett-Packard Company)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-04-14] (DT Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwNe64.sys [11400192 2012-06-02] (Intel Corporation)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-02] (Ralink Technology, Corp.)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-15] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-15] (Synaptics Incorporated)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1062008 2012-08-03] (Sunplus)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20288 2012-08-03] (Hewlett-Packard Development Company, L.P.)
U5 BlueletAudio; C:\Windows\SysWOW64\Drivers\BlueletAudio.sys [34912 2012-06-15] (Ralink Corporation.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-24 21:31 - 2014-08-24 21:31 - 00060427 _____ () C:\Users\Ondra\Desktop\Addition.txt
2014-08-24 21:30 - 2014-08-25 08:07 - 00016757 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-08-24 21:30 - 2014-08-25 08:07 - 00000000 ____D () C:\FRST
2014-08-24 21:28 - 2014-08-24 21:28 - 02103296 _____ (Farbar) C:\Users\Ondra\Desktop\FRST64.exe
2014-08-24 19:54 - 2014-08-24 21:06 - 00000000 ____D () C:\Qoobox
2014-08-24 19:54 - 2014-08-24 20:47 - 00000000 ____D () C:\Windows\erdnt
2014-08-24 19:54 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-24 19:54 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-24 19:54 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-24 19:54 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-24 19:50 - 2014-08-24 19:52 - 00002256 _____ () C:\Users\Ondra\Desktop\Rkill.txt
2014-08-24 19:49 - 2014-08-24 19:49 - 05572212 ____R (Swearware) C:\Users\Ondra\Desktop\ComboFix.exe
2014-08-24 19:46 - 2014-08-24 19:46 - 01944824 _____ (Bleeping Computer, LLC) C:\Users\Ondra\Desktop\rkill.com
2014-08-24 18:54 - 2014-08-24 20:48 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-08-24 10:53 - 2014-08-25 01:15 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-24 10:53 - 2014-08-24 18:52 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-24 10:53 - 2014-08-24 10:53 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-24 10:53 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-24 10:53 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-24 10:52 - 2014-08-24 10:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-24 09:38 - 2014-08-24 09:38 - 00000687 _____ () C:\awhC887.tmp
2014-08-23 13:28 - 2014-08-23 13:28 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-08-23 13:27 - 2014-08-23 13:28 - 02347384 _____ (ESET) C:\Users\Ondra\Downloads\esetsmartinstaller_csy.exe
2014-08-16 19:58 - 2014-08-16 19:58 - 00000687 _____ () C:\awh9C18.tmp
2014-08-16 19:54 - 2014-08-02 02:15 - 00704480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-16 19:54 - 2014-08-02 02:15 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-16 15:29 - 2014-08-16 15:29 - 00021231 _____ () C:\Users\Ondra\Downloads\[CzT]Letopisy_Narnie_Chronicles_of_Narnia_1_2_3_2005_2010_.torrent
2014-08-15 22:04 - 2014-07-16 00:51 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-08-15 21:58 - 2014-06-11 00:44 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-15 21:58 - 2014-06-11 00:43 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-15 07:34 - 2014-07-24 14:09 - 19279872 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-15 07:34 - 2014-07-24 12:51 - 14371328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-15 07:34 - 2014-06-13 03:57 - 01453400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-15 07:34 - 2014-06-13 03:55 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-15 07:33 - 2014-07-24 14:11 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-15 07:33 - 2014-07-24 14:10 - 02240000 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-15 07:33 - 2014-07-24 14:10 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-15 07:33 - 2014-07-24 14:10 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-08-15 07:33 - 2014-07-24 14:10 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 15399936 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-15 07:33 - 2014-07-24 14:09 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-15 07:33 - 2014-07-24 14:09 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-15 07:33 - 2014-07-24 12:52 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-15 07:33 - 2014-07-24 12:52 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-15 07:33 - 2014-07-24 12:52 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 13757440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 02054656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-15 07:33 - 2014-07-24 12:51 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-15 07:33 - 2014-07-24 12:51 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-15 07:33 - 2014-07-24 12:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-15 07:33 - 2014-07-24 12:29 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-15 07:33 - 2014-07-24 10:03 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-08-15 07:33 - 2014-07-16 01:03 - 01300992 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-15 07:33 - 2014-07-16 00:55 - 04035072 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-15 07:33 - 2014-07-12 04:36 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-15 07:33 - 2014-06-20 01:35 - 01312768 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-15 07:33 - 2014-06-20 00:24 - 00694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-15 07:33 - 2014-06-05 19:30 - 10116608 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2014-08-15 07:33 - 2014-06-05 19:29 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-15 07:33 - 2014-06-05 19:28 - 02306560 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-15 07:33 - 2014-06-05 19:28 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-08-15 07:33 - 2014-06-05 15:12 - 08857600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2014-08-15 07:33 - 2014-06-05 15:11 - 02416128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-15 07:32 - 2014-06-05 19:56 - 00112984 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-15 07:32 - 2014-06-05 19:29 - 00393216 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-15 07:32 - 2014-06-05 15:11 - 00295424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-15 07:32 - 2014-06-05 15:10 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-15 07:32 - 2014-06-05 15:10 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2014-08-15 07:32 - 2014-05-29 06:04 - 00094552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2014-08-15 07:32 - 2014-05-08 03:34 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-08-13 09:21 - 2014-08-13 09:21 - 00000687 _____ () C:\awh5A3A.tmp
2014-08-12 21:12 - 2014-08-12 21:12 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Seznam.cz
2014-08-12 13:33 - 2014-08-12 13:33 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-07-27 21:09 - 2014-08-12 21:09 - 00002094 _____ () C:\Users\Ondra\Desktop\Continue installation - Windows Update KB12695 Installation.lnk
2014-07-27 11:09 - 2014-07-27 11:09 - 00013476 _____ () C:\Users\Ondra\Downloads\[CzT]2Bobule_2Grapes (1).torrent
2014-07-27 11:07 - 2014-07-27 11:07 - 00013101 _____ () C:\Users\Ondra\Downloads\[CzT]2Bobule_2Grapes.torrent
2014-07-27 10:46 - 2014-07-27 10:46 - 00014659 _____ () C:\Users\Ondra\Downloads\[CzT]Bobule.torrent
2014-07-27 10:42 - 2014-07-27 10:42 - 00029229 _____ () C:\Users\Ondra\Downloads\Bobule.2008.DVDRip.XviD.CZ-LeMuR.torrent
2014-07-27 10:41 - 2014-07-27 10:41 - 00048162 _____ () C:\Users\Ondra\Downloads\Bobule.2008.DVDR.CZ-LeMuR.torrent
2014-07-27 08:41 - 2014-07-27 08:41 - 00000000 ____D () C:\ProgramData\Bitstream
2014-07-27 08:28 - 2014-08-24 22:01 - 00435320 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-27 08:28 - 2014-07-27 08:28 - 00279528 _____ () C:\Windows\Minidump\072714-29812-01.dmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-25 08:08 - 2014-08-24 21:30 - 00016757 _____ () C:\Users\Ondra\Desktop\FRST.txt
2014-08-25 08:07 - 2014-08-24 21:30 - 00000000 ____D () C:\FRST
2014-08-25 08:06 - 2012-09-20 10:31 - 01055688 _____ () C:\Windows\WindowsUpdate.log
2014-08-25 08:03 - 2012-09-20 11:14 - 00004524 _____ () C:\Windows\SysWOW64\LOCALSERVICE.INI
2014-08-25 06:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-08-25 01:15 - 2014-08-24 10:53 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-24 22:07 - 2012-09-09 07:46 - 00755956 _____ () C:\Windows\system32\perfh005.dat
2014-08-24 22:07 - 2012-09-09 07:46 - 00162886 _____ () C:\Windows\system32\perfc005.dat
2014-08-24 22:07 - 2012-07-26 09:28 - 01851486 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-24 22:01 - 2014-07-27 08:28 - 00435320 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-24 22:01 - 2014-01-30 20:14 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-08-24 22:01 - 2012-09-09 07:14 - 00000000 ____D () C:\ProgramData\PDFC
2014-08-24 22:01 - 2012-08-16 02:46 - 00000787 _____ () C:\Windows\SysWOW64\bscs.ini
2014-08-24 22:01 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-24 22:00 - 2013-06-01 19:32 - 00000000 ____D () C:\Windows\Minidump
2014-08-24 22:00 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-08-24 21:31 - 2014-08-24 21:31 - 00060427 _____ () C:\Users\Ondra\Desktop\Addition.txt
2014-08-24 21:28 - 2014-08-24 21:28 - 02103296 _____ (Farbar) C:\Users\Ondra\Desktop\FRST64.exe
2014-08-24 21:06 - 2014-08-24 19:54 - 00000000 ____D () C:\Qoobox
2014-08-24 20:50 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-08-24 20:48 - 2014-08-24 18:54 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-08-24 20:48 - 2012-08-01 23:23 - 00058260 _____ () C:\Windows\PFRO.log
2014-08-24 20:48 - 2012-07-26 07:26 - 90439680 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-08-24 20:48 - 2012-07-26 07:26 - 27525120 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-08-24 20:48 - 2012-07-26 07:26 - 00786432 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-08-24 20:48 - 2012-07-26 07:26 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-08-24 20:48 - 2012-07-26 07:26 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-08-24 20:47 - 2014-08-24 19:54 - 00000000 ____D () C:\Windows\erdnt
2014-08-24 20:20 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-08-24 20:02 - 2013-04-08 23:35 - 00000000 ____D () C:\Users\Ondra
2014-08-24 19:52 - 2014-08-24 19:50 - 00002256 _____ () C:\Users\Ondra\Desktop\Rkill.txt
2014-08-24 19:49 - 2014-08-24 19:49 - 05572212 ____R (Swearware) C:\Users\Ondra\Desktop\ComboFix.exe
2014-08-24 19:46 - 2014-08-24 19:46 - 01944824 _____ (Bleeping Computer, LLC) C:\Users\Ondra\Desktop\rkill.com
2014-08-24 19:35 - 2013-04-08 23:47 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2315802412-815962061-3052649632-1002
2014-08-24 19:09 - 2012-09-20 11:14 - 00000088 _____ () C:\Windows\SysWOW64\LOCALDEVICE.INI
2014-08-24 19:09 - 2012-07-26 09:20 - 00000000 ____D () C:\Windows\Setup
2014-08-24 18:52 - 2014-08-24 10:53 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-24 16:20 - 2013-04-22 21:07 - 00000000 ____D () C:\Users\Ondra\AppData\Local\CrashDumps
2014-08-24 16:16 - 2014-04-16 18:43 - 00000489 _____ () C:\Users\Ondra\rgmnr
2014-08-24 13:14 - 2013-06-01 19:32 - 614507469 _____ () C:\Windows\MEMORY.DMP
2014-08-24 10:53 - 2014-08-24 10:53 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-24 10:53 - 2014-08-24 10:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-24 10:52 - 2014-08-24 10:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ondra\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-24 10:48 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-08-24 09:38 - 2014-08-24 09:38 - 00000687 _____ () C:\awhC887.tmp
2014-08-23 15:07 - 2013-08-04 15:00 - 00000000 ____D () C:\Firefox
2014-08-23 14:55 - 2014-04-16 12:55 - 00000000 ____D () C:\Program Files (x86)\demoni 2013 horor avi cz dabing cely film
2014-08-23 13:28 - 2014-08-23 13:28 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-08-23 13:28 - 2014-08-23 13:27 - 02347384 _____ (ESET) C:\Users\Ondra\Downloads\esetsmartinstaller_csy.exe
2014-08-20 19:14 - 2013-04-09 08:52 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-20 19:13 - 2013-04-09 08:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-08-17 20:37 - 2014-06-24 19:11 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Skype
2014-08-17 19:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-08-17 09:55 - 2013-12-24 12:25 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\uTorrent
2014-08-16 19:58 - 2014-08-16 19:58 - 00000687 _____ () C:\awh9C18.tmp
2014-08-16 19:56 - 2014-06-19 21:56 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\QuickScan
2014-08-16 19:50 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-08-16 16:07 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-08-16 15:44 - 2013-04-09 00:13 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-08-16 15:29 - 2014-08-16 15:29 - 00021231 _____ () C:\Users\Ondra\Downloads\[CzT]Letopisy_Narnie_Chronicles_of_Narnia_1_2_3_2005_2010_.torrent
2014-08-16 11:45 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-16 10:30 - 2013-08-04 13:38 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 22:16 - 2013-04-09 09:17 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-13 19:31 - 2014-06-24 19:10 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-08-13 09:21 - 2014-08-13 09:21 - 00000687 _____ () C:\awh5A3A.tmp
2014-08-12 21:12 - 2014-08-12 21:12 - 00000000 ____D () C:\Users\Ondra\AppData\Roaming\Seznam.cz
2014-08-12 21:09 - 2014-07-27 21:09 - 00002094 _____ () C:\Users\Ondra\Desktop\Continue installation - Windows Update KB12695 Installation.lnk
2014-08-12 13:33 - 2014-08-12 13:33 - 00108544 _____ () C:\Windows\SysWOW64\hfnapi.dll
2014-08-02 02:15 - 2014-08-16 19:54 - 00704480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-02 02:15 - 2014-08-16 19:54 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-27 11:09 - 2014-07-27 11:09 - 00013476 _____ () C:\Users\Ondra\Downloads\[CzT]2Bobule_2Grapes (1).torrent
2014-07-27 11:07 - 2014-07-27 11:07 - 00013101 _____ () C:\Users\Ondra\Downloads\[CzT]2Bobule_2Grapes.torrent
2014-07-27 10:46 - 2014-07-27 10:46 - 00014659 _____ () C:\Users\Ondra\Downloads\[CzT]Bobule.torrent
2014-07-27 10:42 - 2014-07-27 10:42 - 00029229 _____ () C:\Users\Ondra\Downloads\Bobule.2008.DVDRip.XviD.CZ-LeMuR.torrent
2014-07-27 10:41 - 2014-07-27 10:41 - 00048162 _____ () C:\Users\Ondra\Downloads\Bobule.2008.DVDR.CZ-LeMuR.torrent
2014-07-27 08:41 - 2014-07-27 08:41 - 00000000 ____D () C:\ProgramData\Bitstream
2014-07-27 08:41 - 2014-02-16 20:44 - 00000000 ____D () C:\ProgramData\Corel
2014-07-27 08:28 - 2014-07-27 08:28 - 00279528 _____ () C:\Windows\Minidump\072714-29812-01.dmp
2014-07-26 23:41 - 2013-04-13 16:58 - 00000024 _____ () C:\SROF.ini
2014-07-26 20:27 - 2013-04-09 10:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-26 20:26 - 2013-04-09 10:40 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-26 20:26 - 2013-04-09 10:40 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-23 15:00

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: v prohlížeči mi vyskakuje stále nějaké okna

#23 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět