asi nějaký červík,nebo dva

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
bajo
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 04 Pro 2006 19:34

asi nějaký červík,nebo dva

#1 Příspěvek od bajo »

Dobrý den
Mám problémy hlavně s internetovým prohlížečem ...přepisuje se domovská stránka,pořád se automaticky zapínají doplňky na reklamy a hlavně při scanovaní pc essentials microsoftem něco antivir ukončuje.........????Počítač užívá hlavně dcera a choť :(
Předem děkuji za pomoc


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-09-2014
Ran by Venca at 2014-09-19 11:51:25
Running from C:\Users\Venca\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer Crystal Eye Webcam (HKLM-x32\...\{7760D94E-B1B5-40A0-9AA0-ABF942108755}) (Version: 5.2.9.3 - Suyin Optronics Corp)
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.05.3004 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Acer Incorporated)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.02.3006 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.5.0715 - Acer Incorporated)
Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3502 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden
Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.7.700.202 - Adobe Systems Incorporated)
Adobe Reader XI - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.0.112 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}) (Version: 1.4.17.35005 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.4.17.35005 - Alcor Micro Corp.) Hidden
Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 3.5 - Auslogics Software Pty Ltd)
Barbie(TM) Dobrodružství s koňmi(TM) (HKLM-x32\...\{F827DB7E-9F8F-46BA-9F22-46CE2CEE1D7E}) (Version: 1.00.0000 - )
BlockIt Ad remover (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - BlockIt Ad remover) <==== ATTENTION
Brave (HKLM-x32\...\Brave_is1) (Version: - R.G. Origami)
Broadcom Gigabit NetLink Controller (HKLM\...\{A325B368-A9EC-40EF-A95C-9DEAD3683AE3}) (Version: 12.33.03 - Broadcom Corporation)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
CCC Help Czech (x32 Version: 2009.1209.2334.42329 - Název společnosti:) Hidden
CCC Help Danish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Dutch (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help English (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Finnish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help French (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help German (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Greek (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Italian (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Japanese (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Korean (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Polish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Russian (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Spanish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Swedish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Thai (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Turkish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
ccc-core-static (x32 Version: 2009.1209.2335.42329 - Název společnosti:) Hidden
ccc-utility64 (Version: 2009.1209.2335.42329 - ATI) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.22 - Piriform)
CoupExteunnsiion (HKLM-x32\...\{6933C2BA-C67D-42C7-8C77-1FF4B364AF54}) (Version: - "")
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.4.0316 - DT Soft Ltd)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{42CBCE27-DE9B-4094-B9EB-D4C4C135FFA8}) (Version: - Microsoft)
Disney Popelka (HKLM-x32\...\{2048F008-BDCD-485E-B552-B60E15BDC668}) (Version: 1.0 - Disney Interactive)
Disney princezna - Moje pohádkové dobrodružství verzia 1.0 (HKLM-x32\...\Disney princezna - Moje pohádkové dobrodružství_is1) (Version: 1.0 - CzTorrent.net)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
Indeo® Software (HKLM-x32\...\Indeo® Software) (Version: - )
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.00.01.1002 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.186.6 - Intel)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Kreslení pro děti (doporučená instalace) (HKLM-x32\...\Kreslení pro děti (doporučená instalace)) (Version: - )
Launch Manager (HKLM-x32\...\LManager) (Version: 3.0.05 - Acer Inc.)
LeapFrog Connect (HKLM-x32\...\UPCShell) (Version: 4.2.9.15649 - LeapFrog)
LeapFrog Connect (x32 Version: 4.2.9.15649 - LeapFrog) Hidden
LeapFrog LeapPad Explorer Plugin (x32 Version: 4.2.11.15696 - LeapFrog) Hidden
LG United Mobile Drivers (HKLM-x32\...\{5DB849D6-9392-4FB7-9ABB-87ED433152E5}) (Version: 3.8.1 - LG Electronics)
LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.98 - LSI Corporation)
Microsoft .NET Framework 4.5.1 (CSY) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation)
Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.6.0305.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{99D7DE4C-2775-4B16-B155-7F09AE939E8E}) (Version: 9.7.0621 - Microsoft Corporation)
MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (HKLM-x32\...\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.76.0 - Egis Technology Inc.)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.45.6 - Black Tree Gaming)
NTI Backup Now 5 (HKLM-x32\...\InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}) (Version: 5.1.2.627 - NewTech Infosystems)
NTI Backup Now Standard (x32 Version: 5.1.2.627 - NewTech Infosystems) Hidden
NTI Media Maker 8 (HKLM-x32\...\InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}) (Version: 8.0.12.6623 - NewTech Infosystems)
NTI Media Maker 8 (x32 Version: 8.0.12.6623 - NewTech Infosystems) Hidden
PhotoFiltre 7 (HKCU\...\PhotoFiltre 7) (Version: - )
Picture Collage Maker Pro 4.1.2 (HKLM-x32\...\{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1) (Version: 4.1.2 - PearlMountain Technology Co., Ltd)
QuickTime (HKLM-x32\...\QuickTime) (Version: - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5969 - Realtek Semiconductor Corp.)
saevE net (HKLM-x32\...\{7DD5E91C-3864-77EC-7635-D14910C2A03E}) (Version: 4.3.0.1667 - Save NEt) <==== ATTENTION
Scooby Doo - Prokletí sfingy (HKLM-x32\...\{A5F21073-4C0F-4844-B306-F20ADFEB12E2}) (Version: 1.00.000 - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Sestry - spojeny krví v1.0 (HKLM-x32\...\{Sestry - spojeny krvi}_is1) (Version: - Špidla Data Processing, s.r.o.)
SNT (HKLM-x32\...\{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}) (Version: 3.3.0.1255 - SNT) <==== ATTENTION
Software Bluetooth WIDCOMM (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.800 - Broadcom)
SW-Booster (HKLM-x32\...\S-530512871) (Version: 3.3.0.1605 - PremiumSoft) <==== ATTENTION
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
SW-Sustainer 1.80 (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}) (Version: - Certified Publisher) <==== ATTENTION
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.6.0 - Synaptics Incorporated)
TES V - Skyrim CZ update 1.4.21.0.4 (HKLM-x32\...\TES V - Skyrim CZ update 1.4.21.0.4) (Version: - )
TES V - Skyrim CZ update 1.5.24.0.5 (HKLM-x32\...\TES V - Skyrim CZ update 1.5.24.0.5) (Version: - )
The Elder Scrolls V - Skyrim (HKLM-x32\...\The Elder Scrolls V - Skyrim_is1) (Version: - )
The Elder Scrolls V Skyrim Dragonborn (c) Bethesda Softworks version 1 (HKLM-x32\...\The Elder Scrolls V Skyrim Dragonborn (c) Bethes~300CD4A2_is1) (Version: 1 - )
The KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.9.0.124 - PandoraTV)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version: - Microsoft)
Update for Microsoft Excel 2010 (KB2889836) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{AC36E3B7-5095-43B9-9A74-928420F88714}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{84B191B5-5319-463A-A305-8C4D53B1D20A}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{DB0B0CDF-77EC-47B0-94E2-4738573A1E58}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{1AA82E2E-7DB7-4C70-910C-BBB657A6B3A5}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2687502) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{B114A387-8A14-4C43-AE51-82F17EB81D49}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{6E760BBA-B83F-4C2D-918F-5F91EF6C9861}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0044-0405-1000-0000000FF1CE}_Office14.PROPLUSR_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{D1F3B526-7EB2-4701-92DB-0784988D78DE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837606) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{52BEF8AE-9324-40A1-9A92-E5A8FB63A475}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8F699D53-05FB-488E-B7D3-E4E47257BE5D}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-001A-0405-1000-0000000FF1CE}_Office14.PROPLUSR_{EF3CB32B-993B-4741-875E-9A41E9E7E520}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{DDDC32A5-9528-4771-B91A-97A8E1D7957B}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0018-0405-1000-0000000FF1CE}_Office14.PROPLUSR_{475E6B60-AD7E-4CCB-870D-D67FC71DBCED}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A20A650C-F820-4CE4-AEA5-EC140192FAFB}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F6F342A1-530B-4D48-A468-1E3F70928984}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{C950A55F-82E3-4CC8-8FA2-E8A2A0F651F3}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{89FDC8D9-FB84-4EFE-950D-AF4EECC3B64C}) (Version: - Microsoft)
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin) (HKLM-x32\...\LeapPadExplorerPlugin) (Version: - LeapFrog)
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.00.3008 - Acer Incorporated)
Win7codecs (HKLM-x32\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 3.8.0 - Shark007)
Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) (HKLM\...\6B6B5E96843E55CF5CF8C7E45FB457F1FE642FF1) (Version: 07/30/2009 6.2.0.9405 - Broadcom)
Windows Driver Package - Broadcom Bluetooth (09/11/2009 6.2.0.9407) (HKLM\...\3932CA781A7894D20116FDF60F878301800EA8AB) (Version: 09/11/2009 6.2.0.9407 - Broadcom)
Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) (HKLM\...\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Windows Live Communications Platform (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 14.0.8081.709 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 14.0.8091.0730 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{068B46A0-8858-4CEB-80BC-A4AE787A05FC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Writer (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinRAR 4.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH)
x64 Components v3.8.0 (HKLM\...\x64 Components_is1) (Version: 3.8.0 - Shark007)
YoutubeAdblocker (HKLM-x32\...\{4820778D-AB0D-6D18-C316-52A6A0E1D507}) (Version: 4.3.0.1958 - YoutubeAdblocker) <==== ATTENTION
Zoner Photo Studio 13 (HKLM\...\ZonerPhotoStudio13_CZ_is1) (Version: 13.0.1.7 - ZONER software)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1536291864-4088397285-1847172743-1001_Classes\CLSID\{BCAFD618-3FAE-4EFE-BF4E-4C43A7E1320B}\InprocServer32 -> C:\Program Files (x86)\Zoner\Photo Studio 13\Program64\SHELLEXT.DLL (ZONER software)

==================== Restore Points =========================

20-08-2014 05:04:37 Windows Update
25-08-2014 11:53:07 Windows Update
28-08-2014 11:29:18 Windows Update
31-08-2014 17:04:37 Windows Update
07-09-2014 13:24:50 Windows Update
10-09-2014 16:50:53 Windows Update
11-09-2014 07:41:10 Windows Update
11-09-2014 14:36:25 Installed LG United Mobile Drivers.
15-09-2014 09:09:00 Windows Update
18-09-2014 16:00:25 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2014-05-16 20:34 - 00001021 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 im.adtech.de
127.0.0.1 adserver.adtech.de
127.0.0.1 adtech.de
127.0.0.1 ar.atwola.com
127.0.0.1 atwola.com
127.0.0.1 adserver.71i.de
127.0.0.1 adicqserver.71i.de
127.0.0.1 71i.de


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {3096D27C-48A2-47C9-9A1E-825D988B23A0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-06] (Google Inc.)
Task: {39D2D469-2963-40C3-8932-D350EF6851FE} - System32\Tasks\SW-Booster-S-530512871 => c:\programdata\itsreadyapp\sw-booster\SW-Booster.exe [2014-05-09] () <==== ATTENTION
Task: {4D4053E9-A8B5-46EC-B212-2E45101800E3} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-04-05] (Acer Incorporated)
Task: {BE6D43C6-32EE-47BA-B131-D4893D2E245C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-06] (Google Inc.)
Task: {C617A0CC-34E7-4540-B5AF-DAEF9C679EAF} - \AutoKMS No Task File <==== ATTENTION
Task: {C869F121-4308-46BB-BEFB-330394BD3DE7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-08-22] (Piriform Ltd)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SW-Booster-S-530512871.job => c:\programdata\itsreadyapp\sw-booster\SW-Booster.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2012-10-12 10:16 - 2012-02-17 20:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll
2014-05-09 15:04 - 2014-05-09 15:04 - 00729600 _____ () c:\programdata\itsreadyapp\sw-booster\SW-Booster.exe
2014-05-09 15:04 - 2014-05-09 15:04 - 04210176 _____ () C:\Program Files (x86)\SW-Booster\Assistant_x64.dll
2012-10-12 08:47 - 2009-11-20 15:34 - 00200704 _____ () C:\Windows\PLFSetI.exe
2009-07-29 13:10 - 2009-07-29 13:10 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2012-10-12 08:43 - 2012-10-12 08:43 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-05-09 15:04 - 2014-05-09 15:04 - 04296192 _____ () c:\Program Files (x86)\SW-Booster\Assistant.dll
2014-05-09 15:04 - 2014-05-09 15:04 - 00174928 _____ () c:\Program Files (x86)\SW-Booster\AssistantSvc.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libglesv2.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libegl.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\ProgramData\Temp:444C53BA
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:4D066AD2
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:93DE1838
AlternateDataStreams: C:\ProgramData\Temp:AB689DEA
AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E3C56885

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: EgisTecLiveUpdate => "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"
MSCONFIG\startupreg: LManager => C:\Program Files (x86)\Launch Manager\LManager.exe
MSCONFIG\startupreg: Monitor => "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"
MSCONFIG\startupreg: mwlDaemon => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/18/2014 08:07:26 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1 se nezdařilo. Chyba v souboru manifestu nebo zásady WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2 na řádku WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definice je WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (09/18/2014 08:06:29 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Generování kontextu aktivace pro assemblyIdentity1 se nezdařilo. Chyba v souboru manifestu nebo zásady assemblyIdentity2 na řádku assemblyIdentity3.
Hodnota MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR atributu version v prvku assemblyIdentity je neplatná.

Error: (08/23/2014 01:13:11 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1 se nezdařilo. Chyba v souboru manifestu nebo zásady WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2 na řádku WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definice je WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (08/23/2014 01:12:48 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: Generování kontextu aktivace pro assemblyIdentity1 se nezdařilo. Chyba v souboru manifestu nebo zásady assemblyIdentity2 na řádku assemblyIdentity3.
Hodnota MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR atributu version v prvku assemblyIdentity je neplatná.

Error: (08/22/2014 11:20:27 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1 se nezdařilo. Chyba v souboru manifestu nebo zásady WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2 na řádku WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definice je WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (08/22/2014 11:19:33 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Generování kontextu aktivace pro assemblyIdentity1 se nezdařilo. Chyba v souboru manifestu nebo zásady assemblyIdentity2 na řádku assemblyIdentity3.
Hodnota MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR atributu version v prvku assemblyIdentity je neplatná.

Error: (08/22/2014 03:24:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: MsMpEng.exe, verze: 4.5.216.0, časové razítko: 0x531f64e3
Název chybujícího modulu: mpengine.dll, verze: 1.1.10903.0, časové razítko: 0x53e338e3
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000005abf0f
ID chybujícího procesu: 0x12d4
Čas spuštění chybující aplikace: 0xMsMpEng.exe0
Cesta k chybující aplikaci: MsMpEng.exe1
Cesta k chybujícímu modulu: MsMpEng.exe2
ID zprávy: MsMpEng.exe3

Error: (08/22/2014 03:16:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: MsMpEng.exe, verze: 4.5.216.0, časové razítko: 0x531f64e3
Název chybujícího modulu: mpengine.dll, verze: 1.1.10903.0, časové razítko: 0x53e338e3
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000005abf0f
ID chybujícího procesu: 0x3b4
Čas spuštění chybující aplikace: 0xMsMpEng.exe0
Cesta k chybující aplikaci: MsMpEng.exe1
Cesta k chybujícímu modulu: MsMpEng.exe2
ID zprávy: MsMpEng.exe3

Error: (08/22/2014 02:51:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program chrome.exe verze 35.0.1916.114 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: cf0

Čas spuštění: 01cfbe0776a06667

Čas ukončení: 4

Cesta k aplikaci: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

ID hlášení:

Error: (08/13/2014 09:28:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program KMPlayer.exe verze 3.9.0.124 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: e68

Čas spuštění: 01cfb6fe7d8d3026

Čas ukončení: 36

Cesta k aplikaci: C:\Program Files (x86)\The KMPlayer\KMPlayer.exe

ID hlášení:


System errors:
=============
Error: (09/11/2014 04:46:08 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (09/10/2014 06:54:42 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (09/10/2014 06:54:42 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (09/10/2014 06:54:41 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (09/10/2014 06:54:41 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (09/10/2014 06:54:34 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR1.

Error: (09/07/2014 03:37:28 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x000000c2 (0x0000000000000007, 0x000000000000109b, 0x0000000004ce0000, 0xfffffa8006520010)C:\Windows\MEMORY.DMP090714-20950-01

Error: (08/22/2014 03:49:50 PM) (Source: Tcpip) (EventID: 4199) (User: )
Description: Systém zjistil konflikt IP adresy 192.168.1.102 se systémem,
jehož síťová hardwarová adresa je 58-A2-B5-B9-5C-08. Síťové operace v systému mohou
být přerušeny.

Error: (08/22/2014 03:24:43 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Microsoft Antimalware Service byla nečekaně ukončena. Stalo se to 2 krát. Následující opravná akce bude spuštěna za 15000 milisekund: Restartovat službu.

Error: (08/22/2014 03:24:38 PM) (Source: Microsoft Antimalware) (EventID: 3002) (User: )
Description: %%860 Funkce ochrany v reálném čase zjistila chybu a nezdařila se.

Funkce: %%886

Kód chyby: 0x80070006

Popis chyby: Neplatný popisovač.

Důvod: %%836


Microsoft Office Sessions:
=========================
Error: (09/18/2014 08:07:26 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8

Error: (09/18/2014 08:06:29 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (08/23/2014 01:13:11 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8

Error: (08/23/2014 01:12:48 AM) (Source: SideBySide) (EventID: 63) (User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (08/22/2014 11:20:27 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8

Error: (08/22/2014 11:19:33 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3

Error: (08/22/2014 03:24:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: MsMpEng.exe4.5.216.0531f64e3mpengine.dll1.1.10903.053e338e3c000000500000000005abf0f12d401cfbe0b57fb27b4c:\Program Files\Microsoft Security Client\MsMpEng.exec:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{67321C80-AD54-4DC2-A303-A894AE1EC322}\mpengine.dlla9133954-29ff-11e4-ab6d-00262d863078

Error: (08/22/2014 03:16:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: MsMpEng.exe4.5.216.0531f64e3mpengine.dll1.1.10903.053e338e3c000000500000000005abf0f3b401cfbe0748bec62bc:\Program Files\Microsoft Security Client\MsMpEng.exec:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6CB564F8-A770-4B1A-A1EB-75A943F46528}\mpengine.dll8772ba6f-29fe-11e4-ab6d-00262d863078

Error: (08/22/2014 02:51:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: chrome.exe35.0.1916.114cf001cfbe0776a066674C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Error: (08/13/2014 09:28:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: KMPlayer.exe3.9.0.124e6801cfb6fe7d8d302636C:\Program Files (x86)\The KMPlayer\KMPlayer.exe


CodeIntegrity Errors:
===================================
Date: 2013-03-10 19:32:36.425
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atikmpag.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2013-03-10 19:32:36.332
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atikmpag.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz
Percentage of memory in use: 33%
Total physical RAM: 3956.5 MB
Available physical RAM: 2621.81 MB
Total Pagefile: 7911.18 MB
Available Pagefile: 6376.56 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:452.97 GB) (Free:252.24 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 5F3E5F3E)
Partition 1: (Not Active) - (Size=12.7 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=453 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: asi nějaký červík,nebo dva

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

bajo
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 04 Pro 2006 19:34

Re: asi nějaký červík,nebo dva

#3 Příspěvek od bajo »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.7 (09.18.2014:2)
OS: Windows 7 Home Premium x64
Ran by Venca on p  19.09.2014 at 14:50:13,78
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\nextlive
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-1536291864-4088397285-1847172743-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{c670dcae-e392-aa32-6f42-143c7fc4bdfd}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskSLib_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskSLib_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskSLib_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskSLib_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4BBA2A61-1CB7-8A7A-23CA-51160E91FC69}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4BBA2A61-1CB7-8A7A-23CA-51160E91FC69}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4BBA2A61-1CB7-8A7A-23CA-51160E91FC69}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0FD0A43-D810-37B2-A2DA-07B07C096A6C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{C0FD0A43-D810-37B2-A2DA-07B07C096A6C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C0FD0A43-D810-37B2-A2DA-07B07C096A6C}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] "hkey_current_user\software\pip"



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\partner"
Successfully deleted: [Folder] "C:\ProgramData\snt"
Successfully deleted: [Folder] "C:\ProgramData\youtubeadblocker"
Successfully deleted: [Folder] "C:\Users\Venca\AppData\Roaming\newnext.me"
Successfully deleted: [Folder] "C:\Users\Venca\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Program Files (x86)\snt"
Successfully deleted: [Folder] "C:\Program Files (x86)\youtubeadblocker"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p  19.09.2014 at 15:01:11,38
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

bajo
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 04 Pro 2006 19:34

Re: asi nějaký červík,nebo dva

#4 Příspěvek od bajo »

# AdwCleaner v3.310 - Report created 19/09/2014 at 15:03:48
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Venca - VENCA-PC
# Running from : C:\Users\Venca\Desktop\adwcleaner_3.310.exe
# Option : Scan

***** [ Services ] *****

Service Found : d0e87c27

***** [ Files / Folders ] *****

File Found : C:\Users\Venca\daemonprocess.txt
Folder Found : C:\Program Files (x86)\ShOpDrrop
Folder Found : C:\Program Files (x86)\sw-booster
Folder Found : C:\ProgramData\Alawar Stargaze
Folder Found : C:\ProgramData\BesTSaveFoRYou
Folder Found : C:\ProgramData\CoupExteunnsiion
Folder Found : C:\ProgramData\Happy22SavE
Folder Found : C:\ProgramData\CheapMEo
Folder Found : C:\ProgramData\ItsReadyApp
Folder Found : C:\ProgramData\saevE net
Folder Found : C:\ProgramData\ShOpDrrop
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhmcdokcgimknjjijnjhhmndfkflnehd
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejpgoojgmjdomkolokmhgkpllkccmbm
Folder Found : C:\Users\Administrator\AppData\Local\Chromatic Browser
Folder Found : C:\Users\Administrator\AppData\Local\torch
Folder Found : C:\Users\Venca\AppData\Local\genienext
Folder Found : C:\Users\Venca\AppData\Local\Chromatic Browser
Folder Found : C:\Users\Venca\AppData\Local\Mobogenie
Folder Found : C:\Users\Venca\AppData\Local\torch
Folder Found : C:\Users\Venca\AppData\Roaming\EZDownloader

***** [ Scheduled Tasks ] *****

Task Found : SW-Booster-S-530512871

***** [ Shortcuts ] *****


***** [ Registry ] *****

Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\sw-boo~1\assist~1.dll
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SW-BOO~1\ASSIST~2.DLL
Key Found : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Found : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\RegisteredApplicationsEx
Key Found : [x64] HKCU\Software\RegisteredApplicationsEx
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Found : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Found : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Found : HKLM\SOFTWARE\Classes\.
Key Found : HKLM\SOFTWARE\Classes\..9
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2cde833e-2a54-4ef4-a645-09c3eed8f609}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2cde833e-2a54-4ef4-a645-09c3eed8f609}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2cde833e-2a54-4ef4-a645-09c3eed8f609}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6933C2BA-C67D-42C7-8C77-1FF4B364AF54}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E957849A-94AC-6F46-4623-C31474E3C170}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-530512871
Key Found : HKLM\SOFTWARE\PIP
Key Found : HKLM\SOFTWARE\SW-Booster
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{2cde833e-2a54-4ef4-a645-09c3eed8f609}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2cde833e-2a54-4ef4-a645-09c3eed8f609}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280

Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://search.gboxapp.com/

-\\ Google Chrome v35.0.1916.114

[ File : C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Found [Homepage] : hxxp://search.gboxapp.com/

*************************

AdwCleaner[R0].txt - [5179 octets] - [19/09/2014 15:03:48]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [5239 octets] ##########

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: asi nějaký červík,nebo dva

#5 Příspěvek od vyosek »

:arrow: Spustte znovu AdwCleaner
  • Pokud pouzivate Win Vista ci W7, kliknete na AdwCleaner pravym a dejte Run As Administrator ci Spustit jako spravce
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

bajo
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 04 Pro 2006 19:34

Re: asi nějaký červík,nebo dva

#6 Příspěvek od bajo »

# AdwCleaner v3.310 - Report created 19/09/2014 at 15:29:45
# Updated 12/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Venca - VENCA-PC
# Running from : C:\Users\Venca\Desktop\adwcleaner_3.310.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17280


-\\ Google Chrome v35.0.1916.114

[ File : C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Homepage] : hxxp://search.gboxapp.com/

*************************

AdwCleaner[R0].txt - [5355 octets] - [19/09/2014 15:03:48]
AdwCleaner[R1].txt - [971 octets] - [19/09/2014 15:28:31]
AdwCleaner[S0].txt - [4635 octets] - [19/09/2014 15:05:40]
AdwCleaner[S1].txt - [895 octets] - [19/09/2014 15:29:45]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [954 octets] ##########

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: asi nějaký červík,nebo dva

#7 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

bajo
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 04 Pro 2006 19:34

Re: asi nějaký červík,nebo dva

#8 Příspěvek od bajo »

Zoek.exe v5.0.0.0 Updated 20-September-2014
Tool run by Venca on so 20.09.2014 at 17:57:45,06.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Venca\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

20.9.2014 17:59:25 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1536291864-4088397285-1847172743-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
HKEY_USERS\S-1-5-21-1536291864-4088397285-1847172743-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
HKEY_USERS\S-1-5-21-1536291864-4088397285-1847172743-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} deleted successfully
HKEY_USERS\S-1-5-21-1536291864-4088397285-1847172743-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{29CE7E78-10F9-23B5-0CE0-58654B0B5AFC} deleted successfully
HKEY_USERS\S-1-5-21-1536291864-4088397285-1847172743-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{29CE7E78-10F9-23B5-0CE0-58654B0B5AFC} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{29CE7E78-10F9-23B5-0CE0-58654B0B5AFC} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{29CE7E78-10F9-23B5-0CE0-58654B0B5AFC} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{29CE7E78-10F9-23B5-0CE0-58654B0B5AFC} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{29CE7E78-10F9-23B5-0CE0-58654B0B5AFC} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} deleted successfully

==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~3\Špidla Data Processing, s.r.o not found
C:\Users\Venca\AppData\LocalLow\{00234251-C8FC-4076-A1D7-F6ADF18691F4} deleted
C:\Users\Venca\AppData\LocalLow\{105B7B0F-FF7E-944D-8F1E-35B81F9165CB} deleted
C:\Users\Venca\AppData\LocalLow\{29CE7E78-10F9-23B5-0CE0-58654B0B5AFC} deleted
C:\Users\Venca\AppData\LocalLow\{4BBA2A61-1CB7-8A7A-23CA-51160E91FC69} deleted
C:\Users\Venca\AppData\LocalLow\{7B685FDE-8025-7D9A-7EA3-CC6731CECEFA} deleted
C:\Users\Venca\AppData\LocalLow\{7FB73C1D-D1E9-1FD3-7543-19D174D1EF8D} deleted
C:\Users\Venca\AppData\LocalLow\{B5C7B45E-9F67-79F7-DFBF-81C88D09F300} deleted
C:\Users\Venca\AppData\LocalLow\{C0FD0A43-D810-37B2-A2DA-07B07C096A6C} deleted
C:\Users\Venca\AppData\LocalLow\{D0D33D5E-9304-2C17-092B-A81FBD78D960} deleted
C:\Users\Venca\AppData\LocalLow\{EAE5D48D-023B-F3B8-CB34-A7477256F789} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{00234251-C8FC-4076-A1D7-F6ADF18691F4} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{105B7B0F-FF7E-944D-8F1E-35B81F9165CB} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{29CE7E78-10F9-23B5-0CE0-58654B0B5AFC} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{4BBA2A61-1CB7-8A7A-23CA-51160E91FC69} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{7B685FDE-8025-7D9A-7EA3-CC6731CECEFA} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{7FB73C1D-D1E9-1FD3-7543-19D174D1EF8D} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{B5C7B45E-9F67-79F7-DFBF-81C88D09F300} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{C0FD0A43-D810-37B2-A2DA-07B07C096A6C} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{D0D33D5E-9304-2C17-092B-A81FBD78D960} deleted
C:\Users\Venca\AppData\Local\Packages\windows_ie_ac_001\AC\{EAE5D48D-023B-F3B8-CB34-A7477256F789} deleted
C:\PROGRA~3\2635740e53f0e267 deleted
C:\Users\Venca\.android deleted
C:\PROGRA~3\RobOeSaaver deleted
C:\PROGRA~2\RobOeSaaver deleted
C:\PROGRA~3\RuoboSSaveeri deleted
C:\PROGRA~2\RuoboSSaveeri deleted
C:\PROGRA~3\IIsaveer deleted
C:\PROGRA~2\IIsaveer deleted
C:\PROGRA~2\Alawar deleted
C:\PROGRA~3\InstallMate deleted
C:\Users\Venca\AppData\Local\cache deleted
C:\Windows\WININIT.INI deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted

==== Chromium Look ======================

Angry Birds - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
save net - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\dhmcdokcgimknjjijnjhhmndfkflnehd
YoutubeAdblocker - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gejpgoojgmjdomkolokmhgkpllkccmbm
SNT - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gencpkkanmogmkamlbecimfaaigjekdo
Angry Birds - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
SNT - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gencpkkanmogmkamlbecimfaaigjekdo
Angry Birds - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
save net - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\dhmcdokcgimknjjijnjhhmndfkflnehd
YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gejpgoojgmjdomkolokmhgkpllkccmbm
SNT - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gencpkkanmogmkamlbecimfaaigjekdo
Fauxbar - Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hibkhcnpkakjniplpfblaoikiggkopka
Epic Soccer Barcelona - Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kacgddpcndpmmpoepbdklplpfhlcgikn
Bookmark Checker - Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnboppjpcdnckcklbmjmdahfkpmgglec
HoofSounds - Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pakhjhphleppgakhlffhlfhbekfnobbk
Angry Birds - Venca\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
save net - Venca\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\dhmcdokcgimknjjijnjhhmndfkflnehd
YoutubeAdblocker - Venca\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gejpgoojgmjdomkolokmhgkpllkccmbm
SNT - Venca\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gencpkkanmogmkamlbecimfaaigjekdo

==== Chromium Startpages ======================

C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.seznam.cz/",
"startup_urls": [ "http://www.seznam.cz/" ],


==== Chromium Fix ======================

C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\dhmcdokcgimknjjijnjhhmndfkflnehd deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gejpgoojgmjdomkolokmhgkpllkccmbm deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gencpkkanmogmkamlbecimfaaigjekdo deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhmcdokcgimknjjijnjhhmndfkflnehd deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejpgoojgmjdomkolokmhgkpllkccmbm deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gencpkkanmogmkamlbecimfaaigjekdo deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\dhmcdokcgimknjjijnjhhmndfkflnehd deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gejpgoojgmjdomkolokmhgkpllkccmbm deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gencpkkanmogmkamlbecimfaaigjekdo deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\hibkhcnpkakjniplpfblaoikiggkopka deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\kacgddpcndpmmpoepbdklplpfhlcgikn deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnboppjpcdnckcklbmjmdahfkpmgglec deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pakhjhphleppgakhlffhlfhbekfnobbk deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\dhmcdokcgimknjjijnjhhmndfkflnehd deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gejpgoojgmjdomkolokmhgkpllkccmbm deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gencpkkanmogmkamlbecimfaaigjekdo deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-devtools_devtools_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-devtools_devtools_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eemcgdkfndhakfknompkggombfjjjeno_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_eemcgdkfndhakfknompkggombfjjjeno_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hibkhcnpkakjniplpfblaoikiggkopka_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hibkhcnpkakjniplpfblaoikiggkopka_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_impaepofmnammebeenafgmllpnjaiime_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_impaepofmnammebeenafgmllpnjaiime_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kacgddpcndpmmpoepbdklplpfhlcgikn_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kacgddpcndpmmpoepbdklplpfhlcgikn_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lnboppjpcdnckcklbmjmdahfkpmgglec_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lnboppjpcdnckcklbmjmdahfkpmgglec_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pafkbggdmjlpgkdkcbjmhmfcdpncadgh_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pakhjhphleppgakhlffhlfhbekfnobbk_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pakhjhphleppgakhlffhlfhbekfnobbk_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_connexity.net_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_cs-cz.facebook.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_email.seznam.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_f.vimeocdn.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_go.eu.bbelements.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ls.hit.gemius.pl_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ls.hit.gemius.pl_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_plus.google.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_secure.adnxs.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.olark.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_system.cinemaware.eu_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.facebook.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.google.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.seznam.cz_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.seznam.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.youtube-nocookie.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.youtube.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_8girl.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.doubleclick.net_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ad.turn.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ads.adk2.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ads.exoclick.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ads.incmd02.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ads.incmd03.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ads.pubmatic.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ads.yahoo.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_adsby.bidtheatre.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_advert.uloz.to_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ams1.ib.adnxs.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_atemda.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_aukro.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_babycar.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_bbnaut.ibillboard.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdn.adk2.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cdncache-a.akamaihd.net_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_cm.g.doubleclick.net_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_connexity.net_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_dancerfish.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_deti.bazos.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_disqus.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_dorty.artmama.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_farma-zh.blog.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_fitplan.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_fra1.ib.adnxs.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_gabculinka.webnode.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_go.cz.bbelements.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_go.eu.bbelements.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_go.turboloves.net_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_googleads.g.doubleclick.net_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ib.adnxs.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_kazdodenninoviny.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_kgczz.promorewards.updatedlunch.eu_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ls.hit.gemius.pl_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mkczimg2.asmirasro.netdna-cdn.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mmotraffic.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mojetelo.blogspot.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_mujsoubor.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nym1.ib.adnxs.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_om.forgeofempires.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_passport.game321.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_penzionpodserakem.jeseniky.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pixel.quantserve.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_plarium.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_platform.twitter.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_player.vimeo.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_programy.sms.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.datafastguru.info_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_reklama.warforum.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.seznam.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_secure-us.imrworldwide.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_secure.demand-go.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_signup.lotro.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_skokynalyzich.nepise.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_skolky.koprivnice.org_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_slunce11.rajce.idnes.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_smartconsumers.info_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_stahnu.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_szyzz.promorewards.updatedlunch.eu_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_tr.adsplats.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_tracking.crobo.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_tv.seznam.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ubytovani.kamsi.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_uloz.to_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_ulozto.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_veozz.exclusiverewards.treatmenthook.biz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_vsezprirody.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_w.prize44.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_web.prize3.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_wlogin.icq.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.adcash.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.aliexpress.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.autoesa.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.baby-prikrmy.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.babydracek.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.babyonline.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bambino.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bazos.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.berslevu.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bleepingcomputer.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.bylinky-prozdravi.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.csfd.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.czc.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.denik.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.dorty-katrin.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.dortyodradunny.estranky.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.dortyvbrne.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.eandilek.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.emimino.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.eshop-prozdravi.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.eshop-rychle.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.fhserve.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.firmy.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.fishingtackleshop.com.au_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.girlsgogames.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.gorilamobil.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.gotrip.co_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.hotel-savannah.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.hracky-kidsmall.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.hryprodivky.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.hukvaldy.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.intervaltimer.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.janackovyhukvaldy.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.karaoketexty.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.kasa.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.koberce-trend.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.kocarky-ruzovypanter.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.kocarky-zlin.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.krystofkemp.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.legenio.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.lidl.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.lidl.sk_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mapy.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.maxikovy-hracky.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.modrykonik.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mrk.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.nejlepsi-autopujcka.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.novinky.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.obchod.kajman.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.operetta.estranky.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.pene.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.picturecollagesoftware.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.prag-info.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.prirodoukezdravi.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.probeauty.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.promena.info_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.prozeny.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.rinmarugames.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.rybarske-potreby-kral.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.rybashop24.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.seznam.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.sport.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.srzmichalovce.sk_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.stream.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.super.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.titulky.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.toys-sery.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.turbofish.sk_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.vagaskylures.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.viry.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.vitalita-shop.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.vyzivaprobudoucnost.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.w-blog.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.warforum.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.wowgirls.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.youtube.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.yr.no_0.localstorage deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.yr.no_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.zapmeta.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.zbozi.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.zdravicko-harmonie.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.zonerpress.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.zsmilhor.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_x.bidswitch.net_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_zc.zeroredirect1.com_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_zlin.cz_0.localstorage-journal deleted successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pafkbggdmjlpgkdkcbjmhmfcdpncadgh deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://homepage.acer.com/rdr.aspx?b=ACA ... 5t5481d767"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{67A2568C-7A0A-4EED-AECC-B5405DE63B64} Google Url="http://www.google.com/search?sourceid=i ... AW_csCZ505"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Unknown Url="Not_Found"

==== Reset Google Chrome ======================

C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1536291864-4088397285-1847172743-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\eeae1ba7-41a8-45ae-9b79-4243b2301d2d deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA} deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Venca\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=765 folders=361 9564153 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Venca\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Venca\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia" deleted

==== EOF on so 20.09.2014 at 18:19:44,88 ======================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: asi nějaký červík,nebo dva

#9 Příspěvek od vyosek »

Poprosim o novy log z FRST
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

bajo
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 04 Pro 2006 19:34

Re: asi nějaký červík,nebo dva

#10 Příspěvek od bajo »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-09-2014 01
Ran by Venca at 2014-09-21 20:41:08
Running from C:\Users\Venca\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer Crystal Eye Webcam (HKLM-x32\...\{7760D94E-B1B5-40A0-9AA0-ABF942108755}) (Version: 5.2.9.3 - Suyin Optronics Corp)
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.05.3004 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Acer Incorporated)
Acer Registration (HKLM-x32\...\Acer Registration) (Version: 1.02.3006 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.5.0715 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe AIR (x32 Version: 1.5.0.7220 - Adobe Systems Inc.) Hidden
Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.0.32.18 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 11.7.700.202 - Adobe Systems Incorporated)
Adobe Reader XI - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.0.112 - Adobe Systems, Inc.)
Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{DBCE1208-433D-4D3E-A26A-CB1B5E71A8F5}) (Version: 1.4.17.35005 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.4.17.35005 - Alcor Micro Corp.) Hidden
Auslogics Disk Defrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 3.5 - Auslogics Software Pty Ltd)
Barbie(TM) Dobrodružství s koňmi(TM) (HKLM-x32\...\{F827DB7E-9F8F-46BA-9F22-46CE2CEE1D7E}) (Version: 1.00.0000 - )
BlockIt Ad remover (HKLM-x32\...\{37476589-E48E-439E-A706-56189E2ED4C4}_is1) (Version: - BlockIt Ad remover) <==== ATTENTION
Brave (HKLM-x32\...\Brave_is1) (Version: - R.G. Origami)
Broadcom Gigabit NetLink Controller (HKLM\...\{A325B368-A9EC-40EF-A95C-9DEAD3683AE3}) (Version: 12.33.03 - Broadcom Corporation)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2009.1209.2335.42329 - ATI) Hidden
CCC Help Czech (x32 Version: 2009.1209.2334.42329 - Název společnosti:) Hidden
CCC Help Danish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Dutch (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help English (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Finnish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help French (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help German (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Greek (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Italian (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Japanese (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Korean (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Polish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Russian (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Spanish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Swedish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Thai (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
CCC Help Turkish (x32 Version: 2009.1209.2334.42329 - ATI) Hidden
ccc-core-static (x32 Version: 2009.1209.2335.42329 - Název společnosti:) Hidden
ccc-utility64 (Version: 2009.1209.2335.42329 - ATI) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.22 - Piriform)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.45.4.0316 - DT Soft Ltd)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{42CBCE27-DE9B-4094-B9EB-D4C4C135FFA8}) (Version: - Microsoft)
Disney Popelka (HKLM-x32\...\{2048F008-BDCD-485E-B552-B60E15BDC668}) (Version: 1.0 - Disney Interactive)
Disney princezna - Moje pohádkové dobrodružství verzia 1.0 (HKLM-x32\...\Disney princezna - Moje pohádkové dobrodružství_is1) (Version: 1.0 - CzTorrent.net)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.114 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3003 - Acer Incorporated)
Indeo® Software (HKLM-x32\...\Indeo® Software) (Version: - )
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel(R) Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.00.01.1002 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.186.6 - Intel)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
Junk Mail filter update (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Kreslení pro děti (doporučená instalace) (HKLM-x32\...\Kreslení pro děti (doporučená instalace)) (Version: - )
Launch Manager (HKLM-x32\...\LManager) (Version: 3.0.05 - Acer Inc.)
LeapFrog Connect (HKLM-x32\...\UPCShell) (Version: 4.2.9.15649 - LeapFrog)
LeapFrog Connect (x32 Version: 4.2.9.15649 - LeapFrog) Hidden
LeapFrog LeapPad Explorer Plugin (x32 Version: 4.2.11.15696 - LeapFrog) Hidden
LG United Mobile Drivers (HKLM-x32\...\{5DB849D6-9392-4FB7-9ABB-87ED433152E5}) (Version: 3.8.1 - LG Electronics)
LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.98 - LSI Corporation)
Microsoft .NET Framework 4.5.1 (CSY) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation)
Microsoft Choice Guard (x32 Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Slovak) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (Czech) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.6.0305.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{99D7DE4C-2775-4B16-B155-7F09AE939E8E}) (Version: 9.7.0621 - Microsoft Corporation)
MSVCRT (x32 Version: 14.0.1468.721 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (HKLM-x32\...\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.76.0 - Egis Technology Inc.)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.45.6 - Black Tree Gaming)
NTI Backup Now 5 (HKLM-x32\...\InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}) (Version: 5.1.2.627 - NewTech Infosystems)
NTI Backup Now Standard (x32 Version: 5.1.2.627 - NewTech Infosystems) Hidden
NTI Media Maker 8 (HKLM-x32\...\InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}) (Version: 8.0.12.6623 - NewTech Infosystems)
NTI Media Maker 8 (x32 Version: 8.0.12.6623 - NewTech Infosystems) Hidden
QuickTime (HKLM-x32\...\QuickTime) (Version: - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5969 - Realtek Semiconductor Corp.)
Scooby Doo - Prokletí sfingy (HKLM-x32\...\{A5F21073-4C0F-4844-B306-F20ADFEB12E2}) (Version: 1.00.000 - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Sestry - spojeny krví v1.0 (HKLM-x32\...\{Sestry - spojeny krvi}_is1) (Version: - Špidla Data Processing, s.r.o.)
Software Bluetooth WIDCOMM (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.800 - Broadcom)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.6.0 - Synaptics Incorporated)
TES V - Skyrim CZ update 1.4.21.0.4 (HKLM-x32\...\TES V - Skyrim CZ update 1.4.21.0.4) (Version: - )
TES V - Skyrim CZ update 1.5.24.0.5 (HKLM-x32\...\TES V - Skyrim CZ update 1.5.24.0.5) (Version: - )
The Elder Scrolls V - Skyrim (HKLM-x32\...\The Elder Scrolls V - Skyrim_is1) (Version: - )
The Elder Scrolls V Skyrim Dragonborn (c) Bethesda Softworks version 1 (HKLM-x32\...\The Elder Scrolls V Skyrim Dragonborn (c) Bethes~300CD4A2_is1) (Version: 1 - )
The KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.9.0.124 - PandoraTV)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{FEF4C57D-0975-4D3C-ACC7-DCD038C3788F}) (Version: - Microsoft)
Update for Microsoft Excel 2010 (KB2889836) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{AC36E3B7-5095-43B9-9A74-928420F88714}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{84B191B5-5319-463A-A305-8C4D53B1D20A}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{DB0B0CDF-77EC-47B0-94E2-4738573A1E58}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{1AA82E2E-7DB7-4C70-910C-BBB657A6B3A5}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{79C725A1-3964-421C-A528-78C1C083C7C7}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{95BE5D45-A3DD-4CB1-8C35-D75DD7B4D862}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{EBD18DE5-BC84-4B57-9A30-097044871F9A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{4AD36582-256B-433D-8593-F31773A15CA4}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2687502) 64-Bit Edition (HKLM\...\{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{B114A387-8A14-4C43-AE51-82F17EB81D49}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F216169C-2B40-429B-8370-B5BA06EC5423}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{B6AD7E27-012A-4B63-82BA-AF62893E5435}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{07DC9C6C-E916-4F42-8677-716930ED0393}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{6E760BBA-B83F-4C2D-918F-5F91EF6C9861}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{90140000-0044-0405-1000-0000000FF1CE}_Office14.PROPLUSR_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{43F59F4D-7179-497E-BE99-BC6F7D1DDCBA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{D1F3B526-7EB2-4701-92DB-0784988D78DE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837606) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{52BEF8AE-9324-40A1-9A92-E5A8FB63A475}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{56551B9F-2FE1-4705-ACF0-8FA920535E18}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 64-Bit Edition (HKLM\...\{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUSR_{8F699D53-05FB-488E-B7D3-E4E47257BE5D}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{3029C408-1DD1-4273-8E58-87CB1B638FC8}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{90140000-001A-0405-1000-0000000FF1CE}_Office14.PROPLUSR_{EF3CB32B-993B-4741-875E-9A41E9E7E520}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{DDDC32A5-9528-4771-B91A-97A8E1D7957B}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{90140000-0018-0405-1000-0000000FF1CE}_Office14.PROPLUSR_{475E6B60-AD7E-4CCB-870D-D67FC71DBCED}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A20A650C-F820-4CE4-AEA5-EC140192FAFB}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{77374F16-2DC6-4EEF-AFAD-C59FDA2E010D}) (Version: - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F6F342A1-530B-4D48-A468-1E3F70928984}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{C950A55F-82E3-4CC8-8FA2-E8A2A0F651F3}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{89FDC8D9-FB84-4EFE-950D-AF4EECC3B64C}) (Version: - Microsoft)
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin) (HKLM-x32\...\LeapPadExplorerPlugin) (Version: - LeapFrog)
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.00.3008 - Acer Incorporated)
Win7codecs (HKLM-x32\...\{8C0CAA7A-3272-4991-A808-2C7559DE3409}) (Version: 3.8.0 - Shark007)
Windows Driver Package - Broadcom Bluetooth (07/30/2009 6.2.0.9405) (HKLM\...\6B6B5E96843E55CF5CF8C7E45FB457F1FE642FF1) (Version: 07/30/2009 6.2.0.9405 - Broadcom)
Windows Driver Package - Broadcom Bluetooth (09/11/2009 6.2.0.9407) (HKLM\...\3932CA781A7894D20116FDF60F878301800EA8AB) (Version: 09/11/2009 6.2.0.9407 - Broadcom)
Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) (HKLM\...\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Windows Live Communications Platform (x32 Version: 14.0.8064.206 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 14.0.8081.709 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 14.0.8091.0730 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{068B46A0-8858-4CEB-80BC-A4AE787A05FC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Writer (x32 Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinRAR 4.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH)
x64 Components v3.8.0 (HKLM\...\x64 Components_is1) (Version: 3.8.0 - Shark007)
Zoner Photo Studio 13 (HKLM\...\ZonerPhotoStudio13_CZ_is1) (Version: 13.0.1.7 - ZONER software)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-1536291864-4088397285-1847172743-1001_Classes\CLSID\{BCAFD618-3FAE-4EFE-BF4E-4C43A7E1320B}\InprocServer32 -> C:\Program Files (x86)\Zoner\Photo Studio 13\Program64\SHELLEXT.DLL (ZONER software)

==================== Restore Points =========================

20-08-2014 05:04:37 Windows Update
25-08-2014 11:53:07 Windows Update
28-08-2014 11:29:18 Windows Update
31-08-2014 17:04:37 Windows Update
07-09-2014 13:24:50 Windows Update
10-09-2014 16:50:53 Windows Update
11-09-2014 07:41:10 Windows Update
11-09-2014 14:36:25 Installed LG United Mobile Drivers.
15-09-2014 09:09:00 Windows Update
18-09-2014 16:00:25 Windows Update
20-09-2014 15:58:58 zoek.exe restore point

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2014-09-20 17:59 - 00000840 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {3096D27C-48A2-47C9-9A1E-825D988B23A0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-06] (Google Inc.)
Task: {4D4053E9-A8B5-46EC-B212-2E45101800E3} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-04-05] (Acer Incorporated)
Task: {BE6D43C6-32EE-47BA-B131-D4893D2E245C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-06] (Google Inc.)
Task: {C617A0CC-34E7-4540-B5AF-DAEF9C679EAF} - \AutoKMS No Task File <==== ATTENTION
Task: {C869F121-4308-46BB-BEFB-330394BD3DE7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-08-22] (Piriform Ltd)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2012-10-12 10:16 - 2012-02-17 20:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll
2012-10-12 08:47 - 2009-11-20 15:34 - 00200704 _____ () C:\Windows\PLFSetI.exe
2009-07-29 13:10 - 2009-07-29 13:10 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2012-10-12 08:43 - 2012-10-12 08:43 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libglesv2.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\libegl.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\pdf.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ppGoogleNaClPluginChrome.dll
2014-06-06 20:12 - 2014-05-14 01:40 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.114\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\ProgramData\Temp:444C53BA
AlternateDataStreams: C:\ProgramData\Temp:4CF61E54
AlternateDataStreams: C:\ProgramData\Temp:4D066AD2
AlternateDataStreams: C:\ProgramData\Temp:5D7E5A8F
AlternateDataStreams: C:\ProgramData\Temp:93DE1838
AlternateDataStreams: C:\ProgramData\Temp:AB689DEA
AlternateDataStreams: C:\ProgramData\Temp:ABE89FFE
AlternateDataStreams: C:\ProgramData\Temp:E1F04E8D
AlternateDataStreams: C:\ProgramData\Temp:E3C56885

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: EgisTecLiveUpdate => "C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe"
MSCONFIG\startupreg: LManager => C:\Program Files (x86)\Launch Manager\LManager.exe
MSCONFIG\startupreg: Monitor => "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"
MSCONFIG\startupreg: mwlDaemon => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/21/2014 06:54:02 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1 se nezdařilo. Chyba v souboru manifestu nebo zásady WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2 na řádku WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definice je WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (09/21/2014 06:53:21 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: Generování kontextu aktivace pro assemblyIdentity1 se nezdařilo. Chyba v souboru manifestu nebo zásady assemblyIdentity2 na řádku assemblyIdentity3.
Hodnota MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR atributu version v prvku assemblyIdentity je neplatná.


System errors:
=============
Error: (09/20/2014 06:14:35 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (09/20/2014 06:14:35 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (09/20/2014 06:14:35 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (09/20/2014 06:14:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (09/20/2014 06:14:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.


Microsoft Office Sessions:
=========================
Error: (09/21/2014 06:54:02 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1"c:\program files (x86)\windows live\photo gallery\MovieMaker.Exec:\program files (x86)\windows live\photo gallery\WLMFDS.DLL8

Error: (09/21/2014 06:53:21 PM) (Source: SideBySide) (EventID: 63) (User: )
Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3


CodeIntegrity Errors:
===================================
Date: 2013-03-10 19:32:36.425
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atikmpag.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2013-03-10 19:32:36.332
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\atikmpag.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5 CPU M 430 @ 2.27GHz
Percentage of memory in use: 33%
Total physical RAM: 3956.5 MB
Available physical RAM: 2614.01 MB
Total Pagefile: 7911.18 MB
Available Pagefile: 6406.7 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB

==================== Drives ================================

Drive c: (ACER) (Fixed) (Total:452.97 GB) (Free:254.15 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 5F3E5F3E)
Partition 1: (Not Active) - (Size=12.7 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=453 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: asi nějaký červík,nebo dva

#11 Příspěvek od vyosek »

Jeste log FRST.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

bajo
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 04 Pro 2006 19:34

Re: asi nějaký červík,nebo dva

#12 Příspěvek od bajo »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-09-2014 01
Ran by Venca (administrator) on VENCA-PC on 21-09-2014 20:39:43
Running from C:\Users\Venca\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Windows\PLFSetI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Ghisler Software GmbH) C:\Program Files (x86)\totalcmd\TOTALCMD64.EXE
(forum.viry.cz) C:\Users\Venca\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323072 2009-07-23] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-29] (Realtek Semiconductor)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2009-11-20] ()
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-18] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-12-09] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-1536291864-4088397285-1847172743-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
HKU\S-1-5-21-1536291864-4088397285-1847172743-1001\...\MountPoints2: {c9a1a3b4-30eb-11e3-b846-00262d863078} - F:\LGAutoRun.exe
ShellIconOverlayIdentifiers: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => No File
ShellIconOverlayIdentifiers-x32: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... lz=1I7ACAW
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = http://www.google.com/search?sourceid=i ... AW_csCZ505
BHO: No Name -> {4BBA2A61-1CB7-8A7A-23CA-51160E91FC69} -> No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: RuoboSSaveeri -> {C0FD0A43-D810-37B2-A2DA-07B07C096A6C} -> C:\ProgramData\RuoboSSaveeri\g0Zcmzn.x64.dll No File
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.10.10.1 10.10.10.2

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

Chrome:
=======
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-20]
CHR Extension: (Disk Google) - C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-20]
CHR Extension: (YouTube) - C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-20]
CHR Extension: (Vyhledávání Google) - C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-20]
CHR Extension: (Gmail) - C:\Users\Venca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-20]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-11] (Egis Technology Inc.)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [552960 2012-12-19] (Advanced Micro Devices, Inc.) [File not signed]
R1 Amfilter; C:\Windows\System32\DRIVERS\Amfltx64.sys [12288 2007-10-15] ((Standard mouse types))
S3 Amusbprt; C:\Windows\System32\DRIVERS\Amusbx64.sys [17920 2008-02-13] (A4Tech Co.,Ltd.)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2012-07-03] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2012-07-03] (LG Electronics Inc.)
S3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [96256 2012-11-06] () [File not signed]
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-10-17] (DT Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] ()

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-21 20:39 - 2014-09-21 20:40 - 00011400 _____ () C:\Users\Venca\Desktop\FRST.txt
2014-09-21 20:39 - 2014-09-21 20:39 - 00029696 _____ () C:\Users\Venca\AppData\Local\MSGBOX.EXE
2014-09-21 20:39 - 2014-09-21 20:39 - 00015327 _____ () C:\Users\Venca\Desktop\LM.bat
2014-09-21 20:39 - 2014-09-21 20:39 - 00000000 ____D () C:\FRST
2014-09-21 20:38 - 2014-09-21 20:38 - 00112640 _____ (forum.viry.cz) C:\Users\Venca\Desktop\FRSTLauncher.exe
2014-09-21 20:37 - 2014-09-21 20:37 - 02105856 _____ (Farbar) C:\Users\Venca\Desktop\FRST64.exe
2014-09-20 19:36 - 2014-09-20 20:18 - 1131458560 _____ () C:\Users\Venca\Downloads\20140918_15.avi
2014-09-20 18:19 - 2014-09-20 18:19 - 00000328 _____ () C:\Windows\PFRO.log
2014-09-20 18:18 - 2014-09-20 17:57 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-20 17:58 - 2014-09-20 18:19 - 00045257 _____ () C:\zoek-results.log
2014-09-20 17:57 - 2014-09-20 18:16 - 00000000 ____D () C:\zoek_backup
2014-09-20 17:56 - 2014-09-20 17:57 - 01290752 _____ () C:\Users\Venca\Desktop\zoek.exe
2014-09-20 17:54 - 2014-09-20 17:54 - 00097032 _____ () C:\Users\Venca\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-20 17:53 - 2014-09-21 20:31 - 00000336 _____ () C:\Windows\setupact.log
2014-09-20 17:53 - 2014-09-20 17:53 - 00377624 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-20 17:53 - 2014-09-20 17:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-19 19:57 - 2014-09-19 19:57 - 00008874 _____ () C:\Users\Venca\Documents\cc_20140919_195727.reg
2014-09-19 15:04 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-19 14:50 - 2014-09-19 14:50 - 00000000 ____D () C:\Windows\ERUNT
2014-09-19 11:41 - 2014-09-08 08:30 - 1592733696 _____ () C:\Users\Venca\Downloads\Appleseed Alpha (2014) Novinka CZ dabing Animovaný Akční Sci-Fi výborná kvalita.avi
2014-09-19 10:45 - 2014-09-19 11:13 - 1849281658 _____ () C:\Users\Venca\Downloads\20140918_13.mkv
2014-09-15 11:30 - 2014-09-15 11:30 - 00000000 ____D () C:\Users\Venca\AppData\Roaming\PearlMountain
2014-09-15 11:30 - 2014-09-15 11:30 - 00000000 ____D () C:\ProgramData\PearlMountain
2014-09-15 11:15 - 2014-09-19 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7
2014-09-11 16:37 - 2014-09-11 16:37 - 00000000 ____D () C:\Program Files (x86)\LG Electronics
2014-09-11 09:51 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-11 09:51 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-11 09:51 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-11 09:51 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-11 09:51 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-11 09:51 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-11 09:51 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-11 09:51 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-11 09:51 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-11 09:51 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-11 09:51 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-11 09:51 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-11 09:51 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-11 09:51 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-11 09:51 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-11 09:51 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-11 09:51 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-11 09:51 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-11 09:51 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-11 09:51 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-11 09:51 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-11 09:51 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-11 09:51 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-11 09:51 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-11 09:51 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-11 09:51 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-11 09:51 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-11 09:51 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-11 09:51 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-11 09:51 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-11 09:51 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-11 09:51 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-11 09:51 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-11 09:51 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-11 09:51 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-11 09:51 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-11 09:51 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-11 09:51 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-11 09:51 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-11 09:51 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-11 09:51 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-11 09:51 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 09:51 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-11 09:51 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-11 09:51 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-11 09:51 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-11 09:51 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-11 09:51 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-11 09:51 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-11 09:51 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-11 09:51 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-11 09:51 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-11 09:51 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-11 09:51 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-11 09:51 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-11 09:51 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-11 09:41 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 09:41 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-11 09:24 - 2014-09-05 04:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-11 09:24 - 2014-09-05 04:05 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-11 09:24 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-11 09:24 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-11 09:24 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-11 09:24 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-11 09:24 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-11 09:24 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-11 09:24 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-11 09:24 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-11 09:24 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-10 18:35 - 2014-09-10 18:50 - 988518400 _____ () C:\Users\Venca\Downloads\Jurský park .(1993) CZ Dabing - 1. část z trilogie Jurského parku .avi
2014-08-28 11:20 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 11:20 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 11:20 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-25 19:06 - 2014-08-25 19:06 - 00000000 ____D () C:\ProgramData\BlockIt Ad remover
2014-08-22 22:30 - 2014-08-22 22:41 - 736593920 _____ () C:\Users\Venca\Downloads\Bitva o Černobyl.avi

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-21 20:40 - 2014-09-21 20:39 - 00011400 _____ () C:\Users\Venca\Desktop\FRST.txt
2014-09-21 20:39 - 2014-09-21 20:39 - 00029696 _____ () C:\Users\Venca\AppData\Local\MSGBOX.EXE
2014-09-21 20:39 - 2014-09-21 20:39 - 00015327 _____ () C:\Users\Venca\Desktop\LM.bat
2014-09-21 20:39 - 2014-09-21 20:39 - 00000000 ____D () C:\FRST
2014-09-21 20:39 - 2009-07-14 06:45 - 00025840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-21 20:39 - 2009-07-14 06:45 - 00025840 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-21 20:38 - 2014-09-21 20:38 - 00112640 _____ (forum.viry.cz) C:\Users\Venca\Desktop\FRSTLauncher.exe
2014-09-21 20:37 - 2014-09-21 20:37 - 02105856 _____ (Farbar) C:\Users\Venca\Desktop\FRST64.exe
2014-09-21 20:34 - 2012-12-14 09:21 - 01851663 _____ () C:\Windows\WindowsUpdate.log
2014-09-21 20:31 - 2014-09-20 17:53 - 00000336 _____ () C:\Windows\setupact.log
2014-09-21 20:31 - 2014-06-06 20:11 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-21 20:31 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-21 19:16 - 2014-06-06 20:11 - 00000950 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-20 20:18 - 2014-09-20 19:36 - 1131458560 _____ () C:\Users\Venca\Downloads\20140918_15.avi
2014-09-20 18:19 - 2014-09-20 18:19 - 00000328 _____ () C:\Windows\PFRO.log
2014-09-20 18:19 - 2014-09-20 17:58 - 00045257 _____ () C:\zoek-results.log
2014-09-20 18:16 - 2014-09-20 17:57 - 00000000 ____D () C:\zoek_backup
2014-09-20 18:14 - 2012-10-12 08:35 - 00000000 ____D () C:\Users\Venca
2014-09-20 17:57 - 2014-09-20 18:18 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-20 17:57 - 2014-09-20 17:56 - 01290752 _____ () C:\Users\Venca\Desktop\zoek.exe
2014-09-20 17:54 - 2014-09-20 17:54 - 00097032 _____ () C:\Users\Venca\AppData\Local\GDIPFONTCACHEV1.DAT
2014-09-20 17:53 - 2014-09-20 17:53 - 00377624 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-20 17:53 - 2014-09-20 17:53 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-19 19:57 - 2014-09-19 19:57 - 00008874 _____ () C:\Users\Venca\Documents\cc_20140919_195727.reg
2014-09-19 19:56 - 2014-09-15 11:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre 7
2014-09-19 19:56 - 2013-03-10 20:32 - 00000000 ____D () C:\Windows\Minidump
2014-09-19 14:57 - 2012-10-13 15:36 - 00000000 ____D () C:\Program Files (x86)\totalcmd
2014-09-19 14:50 - 2014-09-19 14:50 - 00000000 ____D () C:\Windows\ERUNT
2014-09-19 11:19 - 2014-07-28 20:16 - 00000000 ____D () C:\Users\Venca\Pohádky
2014-09-19 11:13 - 2014-09-19 10:45 - 1849281658 _____ () C:\Users\Venca\Downloads\20140918_13.mkv
2014-09-18 20:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-09-18 18:03 - 2012-10-12 18:18 - 00669132 _____ () C:\Windows\system32\perfh005.dat
2014-09-18 18:03 - 2012-10-12 18:18 - 00141760 _____ () C:\Windows\system32\perfc005.dat
2014-09-18 18:03 - 2009-07-14 07:13 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-15 11:30 - 2014-09-15 11:30 - 00000000 ____D () C:\Users\Venca\AppData\Roaming\PearlMountain
2014-09-15 11:30 - 2014-09-15 11:30 - 00000000 ____D () C:\ProgramData\PearlMountain
2014-09-11 16:37 - 2014-09-11 16:37 - 00000000 ____D () C:\Program Files (x86)\LG Electronics
2014-09-11 09:51 - 2009-11-05 05:21 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-11 09:49 - 2014-02-27 09:55 - 01560276 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 09:48 - 2013-03-05 09:07 - 00002121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-09-11 09:48 - 2012-10-12 09:48 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-09-11 09:48 - 2012-10-12 09:48 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-09-11 09:48 - 2012-10-12 09:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-09-11 09:47 - 2013-08-14 09:36 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 09:42 - 2012-10-12 14:05 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-11 09:41 - 2014-05-07 21:42 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-10 18:50 - 2014-09-10 18:35 - 988518400 _____ () C:\Users\Venca\Downloads\Jurský park .(1993) CZ Dabing - 1. část z trilogie Jurského parku .avi
2014-09-08 08:30 - 2014-09-19 11:41 - 1592733696 _____ () C:\Users\Venca\Downloads\Appleseed Alpha (2014) Novinka CZ dabing Animovaný Akční Sci-Fi výborná kvalita.avi
2014-09-05 04:10 - 2014-09-11 09:24 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-05 04:05 - 2014-09-11 09:24 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-25 19:06 - 2014-08-25 19:06 - 00000000 ____D () C:\ProgramData\BlockIt Ad remover
2014-08-23 04:07 - 2014-08-28 11:20 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-28 11:20 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-28 11:20 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-22 22:41 - 2014-08-22 22:30 - 736593920 _____ () C:\Users\Venca\Downloads\Bitva o Černobyl.avi
2014-08-22 22:31 - 2012-11-27 17:56 - 00000000 ___RD () C:\Users\Venca\Lenička

Some content of TEMP:
====================
C:\Users\Venca\AppData\Local\Temp\DisneyPrincess.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-09-18 20:05

==================== End Of Log ============================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: asi nějaký červík,nebo dva

#13 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    
    HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
    HKU\S-1-5-21-1536291864-4088397285-1847172743-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
    HKU\S-1-5-21-1536291864-4088397285-1847172743-1001\...\MountPoints2: {c9a1a3b4-30eb-11e3-b846-00262d863078} - F:\LGAutoRun.exe
    ShellIconOverlayIdentifiers: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => No File
    ShellIconOverlayIdentifiers-x32: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => No File
    
    BHO: No Name -> {4BBA2A61-1CB7-8A7A-23CA-51160E91FC69} -> No File
    BHO: RuoboSSaveeri -> {C0FD0A43-D810-37B2-A2DA-07B07C096A6C} -> C:\ProgramData\RuoboSSaveeri\g0Zcmzn.x64.dll No File
    C:\ProgramData\RuoboSSaveeri
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    
    2014-09-21 20:39 - 2014-09-21 20:40 - 00011400 _____ () C:\Users\Venca\Desktop\FRST.txt
    2014-09-21 20:39 - 2014-09-21 20:39 - 00029696 _____ () C:\Users\Venca\AppData\Local\MSGBOX.EXE
    2014-09-21 20:39 - 2014-09-21 20:39 - 00015327 _____ () C:\Users\Venca\Desktop\LM.bat
    2014-09-21 20:38 - 2014-09-21 20:38 - 00112640 _____ (forum.viry.cz) C:\Users\Venca\Desktop\FRSTLauncher.exe
    2014-09-20 18:19 - 2014-09-20 18:19 - 00000328 _____ () C:\Windows\PFRO.log
    2014-09-20 18:18 - 2014-09-20 17:57 - 00024064 _____ () C:\Windows\zoek-delete.exe
    2014-09-20 17:58 - 2014-09-20 18:19 - 00045257 _____ () C:\zoek-results.log
    2014-09-20 17:57 - 2014-09-20 18:16 - 00000000 ____D () C:\zoek_backup
    2014-09-20 17:56 - 2014-09-20 17:57 - 01290752 _____ () C:\Users\Venca\Desktop\zoek.exe
    2014-09-19 15:04 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
    2014-09-19 14:50 - 2014-09-19 14:50 - 00000000 ____D () C:\Windows\ERUNT
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

bajo
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 04 Pro 2006 19:34

Re: asi nějaký červík,nebo dva

#14 Příspěvek od bajo »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-09-2014 01
Ran by Venca at 2014-09-22 08:31:27 Run:1
Running from C:\Users\Venca\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:

HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKU\S-1-5-21-1536291864-4088397285-1847172743-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671904 2012-08-28] (DT Soft Ltd)
HKU\S-1-5-21-1536291864-4088397285-1847172743-1001\...\MountPoints2: {c9a1a3b4-30eb-11e3-b846-00262d863078} - F:\LGAutoRun.exe
ShellIconOverlayIdentifiers: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => No File
ShellIconOverlayIdentifiers-x32: egisPSDP -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => No File

BHO: No Name -> {4BBA2A61-1CB7-8A7A-23CA-51160E91FC69} -> No File
BHO: RuoboSSaveeri -> {C0FD0A43-D810-37B2-A2DA-07B07C096A6C} -> C:\ProgramData\RuoboSSaveeri\g0Zcmzn.x64.dll No File
C:\ProgramData\RuoboSSaveeri
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

2014-09-21 20:39 - 2014-09-21 20:40 - 00011400 _____ () C:\Users\Venca\Desktop\FRST.txt
2014-09-21 20:39 - 2014-09-21 20:39 - 00029696 _____ () C:\Users\Venca\AppData\Local\MSGBOX.EXE
2014-09-21 20:39 - 2014-09-21 20:39 - 00015327 _____ () C:\Users\Venca\Desktop\LM.bat
2014-09-21 20:38 - 2014-09-21 20:38 - 00112640 _____ (forum.viry.cz) C:\Users\Venca\Desktop\FRSTLauncher.exe
2014-09-20 18:19 - 2014-09-20 18:19 - 00000328 _____ () C:\Windows\PFRO.log
2014-09-20 18:18 - 2014-09-20 17:57 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-20 17:58 - 2014-09-20 18:19 - 00045257 _____ () C:\zoek-results.log
2014-09-20 17:57 - 2014-09-20 18:16 - 00000000 ____D () C:\zoek_backup
2014-09-20 17:56 - 2014-09-20 17:57 - 01290752 _____ () C:\Users\Venca\Desktop\zoek.exe
2014-09-19 15:04 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-09-19 14:50 - 2014-09-19 14:50 - 00000000 ____D () C:\Windows\ERUNT

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value deleted successfully.
HKU\S-1-5-21-1536291864-4088397285-1847172743-1001\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
"HKU\S-1-5-21-1536291864-4088397285-1847172743-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c9a1a3b4-30eb-11e3-b846-00262d863078}" => Key deleted successfully.
"HKCR\CLSID\{c9a1a3b4-30eb-11e3-b846-00262d863078}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\egisPSDP" => Key deleted successfully.
"HKCR\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" => Key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\egisPSDP" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4BBA2A61-1CB7-8A7A-23CA-51160E91FC69}" => Key deleted successfully.
"HKCR\CLSID\{4BBA2A61-1CB7-8A7A-23CA-51160E91FC69}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0FD0A43-D810-37B2-A2DA-07B07C096A6C}" => Key deleted successfully.
"HKCR\CLSID\{C0FD0A43-D810-37B2-A2DA-07B07C096A6C}" => Key deleted successfully.
"C:\ProgramData\RuoboSSaveeri" => File/Directory not found.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"C:\Users\Venca\Desktop\FRST.txt" => File/Directory not found.
"C:\Users\Venca\AppData\Local\MSGBOX.EXE" => File/Directory not found.
"C:\Users\Venca\Desktop\LM.bat" => File/Directory not found.
C:\Users\Venca\Desktop\FRSTLauncher.exe => Moved successfully.
"C:\Windows\PFRO.log" => File/Directory not found.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Venca\Desktop\zoek.exe => Moved successfully.
C:\Windows\SysWOW64\sqlite3.dll => Moved successfully.
C:\Windows\ERUNT => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 27.9 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: asi nějaký červík,nebo dva

#15 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno