prosba o kontrolu logu - vyskakují okna
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
prosba o kontrolu logu - vyskakují okna
Logfile of random's system information tool 1.10 (written by random/random)
Run by HoP at 2014-09-21 21:41:20
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 19 GB (11%) free of 172 GB
Total RAM: 8149 MB (77% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:41:22, on 21.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe
C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files (x86)\PicPick\picpick.exe
C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\twain_32\fjscan32\SOP\FtLnSOP.exe
C:\Program Files (x86)\Suunto\Moveslink for Movestick Mini\Moveslink.exe
C:\Windows\PIXTRAN\fujitsu\FiWiaChecker.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\5429c7d215901eb.exe
C:\Program Files\trend micro\HoP.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:40611
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [FtLnSOP_setup] C:\Windows\Twain_32\Fjscan32\SOP\FtLnSOP.exe
O4 - HKLM\..\Run: [“FjISIS WIA Service Checker] C:\Windows\pixtran\fujitsu\FiWiaChecker.exe
O4 - HKLM\..\Run: [OV3_Monitor] "C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe" /OS
O4 - HKLM\..\Run: [NSU_agent] "C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [OV3_Monitor] "C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [T-Mobile CManager] "C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe" -autorun
O4 - HKCU\..\Run: [NokiaPCInternetAccess] "C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b
O4 - HKCU\..\Run: [Dark] C:\Program Files (x86)\Microsoft\DarkSetup\Dark.exe
O4 - HKCU\..\Run: [PicPick Start] C:\Program Files (x86)\PicPick\picpick.exe /startup
O4 - HKCU\..\Run: [Google Update] "C:\Users\HoP\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Error Recovery Guide.lnk = C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe
O4 - Global Startup: Moveslink for Movestick Mini.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O23 - Service: 068f03c44bb6a6c.exe - Unknown owner - C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EmbassyService - Unknown owner - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe
O23 - Service: EMC Captiva Cloud Service (Emc.Captiva.WebCaptureService) - EMC Corporation - C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebCaptureService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: IBM Notes Diagnostics - IBM - C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Služba IBM Notes Smart Upgrade (LNSUSvc) - IBM Corp - C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files (x86)\IBM\Lotus\Notes\ntmulti.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\DRIVERS\o2flash.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: NTRU TSS v1.2.1.37 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: Wave Authentication Manager Service - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WvPCR - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe
--
End of file - 11733 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe"
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe"
"C:\Program Files\Common Files\SPBA\upeksvr.exe"
C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe"
"C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebCaptureService.exe"
"C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe"
"C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe" -svcinvoke -ini "c:\Program Files (x86)\IBM\Lotus\Notes\notes.ini"
"C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe"
"C:\Program Files (x86)\IBM\Lotus\Notes\ntmulti.exe"
C:\Windows\system32\DRIVERS\o2flash.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
C:\Windows\SysWOW64\vmnat.exe
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe"
C:\Windows\SysWOW64\svchost.exe -k MbnExt
"C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe"
C:\Windows\SysWOW64\vmnetdhcp.exe
"C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\UI0Detect.exe
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-cc41f377-919b-405b-af65-4f378f3d67fa -SystemEventPortName:HostProcess-6be934f0-ad1d-4a34-a890-db4aa868bad9 -IoCancelEventPortName:HostProcess-48b6afc8-087d-4299-9a2c-9a756ecf52de -NonStateChangingEventPortName:HostProcess-126f4878-ef9c-4dd9-9bec-1295c136b58f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e0dd82e9-06b0-480b-a7ce-69ee05197701 -DeviceGroupId:
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe"
"C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
"C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
"C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe"
"C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe" -autorun
"C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b
"C:\Program Files (x86)\Microsoft\DarkSetup\Dark.exe"
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
{87AF7709-692B-459F-992F-0A0F11BE2BF8}
{B5C03F5B-F244-440F-8356-0B0422C245DC}
"C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebToolkitHost.exe" -port:10091 -launchedByClient -ChannelType:NamedPipe
"C:\Program Files (x86)\PicPick\picpick.exe" /startup
"C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe"
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Windows\twain_32\fjscan32\SOP\FtLnSOP.exe"
"C:\Program Files (x86)\Suunto\Moveslink for Movestick Mini\Moveslink.exe" /AutoStart
"C:\Windows\PIXTRAN\fujitsu\FiWiaChecker.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
5429c7d215901eb.exe
"C:\Windows\system32\wuauclt.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\HoP\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Run by HoP at 2014-09-21 21:41:20
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 19 GB (11%) free of 172 GB
Total RAM: 8149 MB (77% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:41:22, on 21.9.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17239)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe
C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files (x86)\PicPick\picpick.exe
C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\twain_32\fjscan32\SOP\FtLnSOP.exe
C:\Program Files (x86)\Suunto\Moveslink for Movestick Mini\Moveslink.exe
C:\Windows\PIXTRAN\fujitsu\FiWiaChecker.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\5429c7d215901eb.exe
C:\Program Files\trend micro\HoP.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:40611
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [FtLnSOP_setup] C:\Windows\Twain_32\Fjscan32\SOP\FtLnSOP.exe
O4 - HKLM\..\Run: [“FjISIS WIA Service Checker] C:\Windows\pixtran\fujitsu\FiWiaChecker.exe
O4 - HKLM\..\Run: [OV3_Monitor] "C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe" /OS
O4 - HKLM\..\Run: [NSU_agent] "C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [OscarEditor] "C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
O4 - HKCU\..\Run: [OV3_Monitor] "C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [T-Mobile CManager] "C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe" -autorun
O4 - HKCU\..\Run: [NokiaPCInternetAccess] "C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b
O4 - HKCU\..\Run: [Dark] C:\Program Files (x86)\Microsoft\DarkSetup\Dark.exe
O4 - HKCU\..\Run: [PicPick Start] C:\Program Files (x86)\PicPick\picpick.exe /startup
O4 - HKCU\..\Run: [Google Update] "C:\Users\HoP\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Error Recovery Guide.lnk = C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe
O4 - Global Startup: Moveslink for Movestick Mini.lnk = ?
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/s ... wflash.cab
O23 - Service: 068f03c44bb6a6c.exe - Unknown owner - C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EmbassyService - Unknown owner - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe
O23 - Service: EMC Captiva Cloud Service (Emc.Captiva.WebCaptureService) - EMC Corporation - C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebCaptureService.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: IBM Notes Diagnostics - IBM - C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Služba IBM Notes Smart Upgrade (LNSUSvc) - IBM Corp - C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files (x86)\IBM\Lotus\Notes\ntmulti.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\DRIVERS\o2flash.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: NTRU TSS v1.2.1.37 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware USB Arbitration Service (VMUSBArbService) - VMware, Inc. - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: Wave Authentication Manager Service - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WvPCR - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe
--
End of file - 11733 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
winlogon.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\System32\spoolsv.exe
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe"
"C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe"
"C:\Program Files\Common Files\SPBA\upeksvr.exe"
C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe"
"C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebCaptureService.exe"
"C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe"
"C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe" -svcinvoke -ini "c:\Program Files (x86)\IBM\Lotus\Notes\notes.ini"
"C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe"
"C:\Program Files (x86)\IBM\Lotus\Notes\ntmulti.exe"
C:\Windows\system32\DRIVERS\o2flash.exe
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
C:\Windows\SysWOW64\vmnat.exe
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe"
C:\Windows\SysWOW64\svchost.exe -k MbnExt
"C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe"
C:\Windows\SysWOW64\vmnetdhcp.exe
"C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\UI0Detect.exe
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-cc41f377-919b-405b-af65-4f378f3d67fa -SystemEventPortName:HostProcess-6be934f0-ad1d-4a34-a890-db4aa868bad9 -IoCancelEventPortName:HostProcess-48b6afc8-087d-4299-9a2c-9a756ecf52de -NonStateChangingEventPortName:HostProcess-126f4878-ef9c-4dd9-9bec-1295c136b58f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e0dd82e9-06b0-480b-a7ce-69ee05197701 -DeviceGroupId:
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe"
"C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
"C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe" Minimum
"C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe"
"C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe" -autorun
"C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b
"C:\Program Files (x86)\Microsoft\DarkSetup\Dark.exe"
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
{87AF7709-692B-459F-992F-0A0F11BE2BF8}
{B5C03F5B-F244-440F-8356-0B0422C245DC}
"C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebToolkitHost.exe" -port:10091 -launchedByClient -ChannelType:NamedPipe
"C:\Program Files (x86)\PicPick\picpick.exe" /startup
"C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe"
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Windows\twain_32\fjscan32\SOP\FtLnSOP.exe"
"C:\Program Files (x86)\Suunto\Moveslink for Movestick Mini\Moveslink.exe" /AutoStart
"C:\Windows\PIXTRAN\fujitsu\FiWiaChecker.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
5429c7d215901eb.exe
"C:\Windows\system32\wuauclt.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 532 536 544 65536 540
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\HoP\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Re: prosba o kontrolu logu - vyskakují okna
log je čerstvě po pročištění nb pomocí adwcleaner_3.310
Re: prosba o kontrolu logu - vyskakují okna
Zdravim
Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: prosba o kontrolu logu - vyskakují okna
omlouvám se za odmlku, zde je výsledek
Zoek.exe v5.0.0.0 Updated 21-09-2014
Tool run by HoP on ne 21.09.2014 at 23:26:25,98.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\HoP\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
21.9.2014 23:27:12 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
"C:\Windows\Installer\3e488.msi" deleted
==== Chromium Look ======================
Video Viewer - HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\dejgnnjohnpljeijfendiiafgpaenbip
==== Chromium Fix ======================
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.cernykrasavec.estranky.cz_0.localstorage deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.cernykrasavec.estranky.cz_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.dell.com"
"Default_Page_URL"="http://www.dell.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.dell.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
==== Reset Google Chrome ======================
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyServer"="http=127.0.0.1:40611"
"ProxyOverride"="<local>;*origin.com;*ea.com;*akamaihd.net"
"ProxyEnable"=dword:00000001
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\65F8E9A2B13CBBD4FB2EF0E48C913255 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7130468A-F53F-4698-8C09-A339EA3B05E6} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2A9E8F56-C31B-4DBB-BFE2-0F4EC8192355} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\65F8E9A2B13CBBD4FB2EF0E48C913255 deleted successfully
HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\A8640317F35F8964C8903A93AEB3506E deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\HoP\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85HPW25D will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DUTYGZVP will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E600VNGY will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F9OV5THM will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P5RCR821 will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QW7GJH9X will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XWRP53EC will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=8 folders=0 187009 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\HoP\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\HoP\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85HPW25D" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DUTYGZVP" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E600VNGY" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F9OV5THM" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P5RCR821" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QW7GJH9X" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XWRP53EC" not found
==== EOF on ne 21.09.2014 at 23:37:24,25 ======================
Zoek.exe v5.0.0.0 Updated 21-09-2014
Tool run by HoP on ne 21.09.2014 at 23:26:25,98.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\HoP\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
21.9.2014 23:27:12 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
"C:\Windows\Installer\3e488.msi" deleted
==== Chromium Look ======================
Video Viewer - HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\dejgnnjohnpljeijfendiiafgpaenbip
==== Chromium Fix ======================
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.cernykrasavec.estranky.cz_0.localstorage deleted successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.cernykrasavec.estranky.cz_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.dell.com"
"Default_Page_URL"="http://www.dell.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.dell.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
==== Reset Google Chrome ======================
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyServer"="http=127.0.0.1:40611"
"ProxyOverride"="<local>;*origin.com;*ea.com;*akamaihd.net"
"ProxyEnable"=dword:00000001
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\65F8E9A2B13CBBD4FB2EF0E48C913255 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{7130468A-F53F-4698-8C09-A339EA3B05E6} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{2A9E8F56-C31B-4DBB-BFE2-0F4EC8192355} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\65F8E9A2B13CBBD4FB2EF0E48C913255 deleted successfully
HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\A8640317F35F8964C8903A93AEB3506E deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\HoP\AppData\Local\Temp\acrord32_sbx\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85HPW25D will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DUTYGZVP will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E600VNGY will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F9OV5THM will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P5RCR821 will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QW7GJH9X will be deleted at reboot
C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XWRP53EC will be deleted at reboot
==== Empty FireFox Cache ======================
No FireFox Cache found
==== Empty Chrome Cache ======================
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=8 folders=0 187009 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\HoP\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\HoP\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\85HPW25D" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DUTYGZVP" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E600VNGY" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F9OV5THM" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P5RCR821" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QW7GJH9X" not found
"C:\Users\HoP\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XWRP53EC" not found
==== EOF on ne 21.09.2014 at 23:37:24,25 ======================
Re: prosba o kontrolu logu - vyskakují okna
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-09-2014 01
Ran by HoP (administrator) on GRAYLATITUDE on 21-09-2014 23:50:57
Running from C:\Users\HoP\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
(Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
() C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe
() C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe
(EMC Corporation) C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebCaptureService.exe
(UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(IBM) C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe
(IBM Corp) C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe
(IBM Corp) C:\Program Files (x86)\IBM\Lotus\Notes\ntmulti.exe
(O2Micro International) C:\Windows\System32\drivers\o2flash.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(EMC Corporation) C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebToolkitHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
() C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\5429c7d215901eb.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe
() C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
() C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
(OLYMPUS IMAGING CORP.) C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
(Gemfor s.r.o.) C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe
(Nokia) C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe
(Codegeeks) C:\Program Files (x86)\Microsoft\DarkSetup\Dark.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(PFU LIMITED) C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(PFU LIMITED) C:\Windows\twain_32\fjscan32\SOP\FtLnSOP.exe
(Suunto Oy) C:\Program Files (x86)\Suunto\Moveslink for Movestick Mini\Moveslink.exe
(PFU LIMITED) C:\Windows\PIXTRAN\fujitsu\FiWiaChecker.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Windows\ehome\mcGlidHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NVHotkey] => rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1692264 2011-05-05] ()
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [TdmNotify] => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [381296 2011-12-08] (Wave Systems Corp.)
HKLM-x32\...\Run: [RUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FtLnSOP_setup] => C:\Windows\Twain_32\Fjscan32\SOP\FtLnSOP.exe [233472 2012-04-05] (PFU LIMITED)
HKLM-x32\...\Run: [“FjISIS WIA Service Checker] => C:\Windows\pixtran\fujitsu\FiWiaChecker.exe [86016 2009-10-21] (PFU LIMITED)
HKLM-x32\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe [55656 2013-01-25] (OLYMPUS IMAGING CORP.)
HKLM-x32\...\Run: [NSU_agent] => C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [190768 2012-02-28] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [OscarEditor] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] ()
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [supertintin_skype] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] ()
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe [420200 2013-01-25] (OLYMPUS IMAGING CORP.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PC Suite Tray] => C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [T-Mobile CManager] => C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe [2166552 2013-10-31] (Gemfor s.r.o.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [NokiaPCInternetAccess] => C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [651264 2009-05-26] (Nokia)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Dark] => C:\Program Files (x86)\Microsoft\DarkSetup\Dark.exe [88576 2009-11-25] (Codegeeks)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [13323608 2014-02-13] (NTeWORKS)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Google Update] => C:\Users\HoP\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-06-03] (Google Inc.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21648480 2014-07-02] (Skype Technologies S.A.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\MountPoints2: {f59d3bdf-93c0-11e2-947c-60d819f83ef5} - E:\NokiaPCIA_Autorun.exe
Lsa: [Authentication Packages] msv1_0 wvauth
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Error Recovery Guide.lnk
ShortcutTarget: Error Recovery Guide.lnk -> C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Moveslink for Movestick Mini.lnk
ShortcutTarget: Moveslink for Movestick Mini.lnk -> C:\Windows\Installer\{4D036ACA-DFDF-41B2-A680-E0D736F3E947}\_22A9010B636AF7A61D8E03.exe ()
ShellIconOverlayIdentifiers: EnabledUnlockedFDEIconOverlay -> {30D3C2AF-9709-4D05-9CF4-13335F3C1E4A} => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll (Wave Systems Corp.)
ShellIconOverlayIdentifiers: UninitializedFdeIconOverlay -> {CF08DA3E-C97D-4891-A66B-E39B28DD270F} => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll (Wave Systems Corp.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:17132
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/s ... wflash.cab
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin -> C:\Users\HoP\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin -> C:\Users\HoP\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\HoP\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\HoP\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\HoP\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Users\HoP\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\HoP\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\HoP\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
Chrome:
=======
CHR Profile: C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-21]
CHR Extension: (Google Docs) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-21]
CHR Extension: (Google Drive) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-23]
CHR Extension: (YouTube) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-23]
CHR Extension: (Google Search) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-23]
CHR Extension: (Video Viewer) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\dejgnnjohnpljeijfendiiafgpaenbip [2012-12-23]
CHR Extension: (Tennis) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekkomjfglgnfeeachhdckcbgjhfiahco [2012-12-23]
CHR Extension: (Google Sheets) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-21]
CHR Extension: (Hit The Jackpot 2) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgjacmakiifbpglpcogkbenamalgaoei [2012-12-23]
CHR Extension: (Apple Shooter) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbcjjgkapdombcilbfbjapkbpnocbkcf [2012-12-23]
CHR Extension: (Google Wallet) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
CHR Extension: (Gmail) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-23]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 068f03c44bb6a6c.exe; C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe [93696 2014-05-27] () [File not signed]
R2 EmbassyService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [218504 2012-01-17] ()
R2 Emc.Captiva.WebCaptureService; C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebCaptureService.exe [39936 2012-04-04] (EMC Corporation) [File not signed]
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [100864 2012-09-07] (Freemake) [File not signed]
R2 IBM Notes Diagnostics; C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe [5164136 2013-10-15] (IBM)
R2 LNSUSvc; C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe [1654376 2013-10-15] (IBM Corp)
R2 MbnExt; C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\MbnExt.dll [417128 2013-12-02] (Gemfor s.r.o.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1637888 2011-10-08] () [File not signed]
R2 VMAuthdService; C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [79872 2012-11-01] (VMware, Inc.) [File not signed]
R2 Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [1679872 2012-01-05] (Wave Systems Corp.) [File not signed]
S3 WvPCR; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [198144 2012-01-16] (Wave Systems Corp.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-24] (DT Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 RegFltrX64; C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\RegFltrX64.sys [18064 2014-05-27] ()
R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [101376 2011-11-21] (Renesas Electronics Corporation)
R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [217088 2011-11-21] (Renesas Electronics Corporation)
R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [31384 2012-11-01] (VMware, Inc.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [70296 2012-10-24] (VMware, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 23:50 - 2014-09-21 23:51 - 00019625 _____ () C:\Users\HoP\Desktop\FRST.txt
2014-09-21 23:50 - 2014-09-21 23:50 - 00029696 _____ () C:\Users\HoP\AppData\Local\MSGBOX.EXE
2014-09-21 23:50 - 2014-09-21 23:50 - 00015327 _____ () C:\Users\HoP\Desktop\LM.bat
2014-09-21 23:47 - 2014-09-21 23:49 - 00112640 _____ (forum.viry.cz) C:\Users\HoP\Desktop\FRSTLauncher.exe
2014-09-21 23:47 - 2014-09-21 23:47 - 02105856 _____ (Farbar) C:\Users\HoP\Desktop\FRST64.exe
2014-09-21 23:34 - 2014-09-21 23:25 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 23:27 - 2014-09-21 23:37 - 00008876 _____ () C:\zoek-results.log
2014-09-21 23:25 - 2014-09-21 23:33 - 00000000 ____D () C:\zoek_backup
2014-09-21 23:24 - 2014-09-21 23:25 - 01290752 _____ () C:\Users\HoP\Desktop\zoek.exe
2014-09-21 21:31 - 2014-09-21 21:41 - 00000000 ____D () C:\Program Files\trend micro
2014-09-21 21:31 - 2014-09-21 21:31 - 00000000 ____D () C:\rsit
2014-09-21 20:20 - 2014-09-21 20:20 - 00009013 _____ () C:\Users\HoP\Downloads\attach.xsp
2014-09-18 14:59 - 2014-09-18 14:59 - 00023014 _____ () C:\Users\HoP\Downloads\00099168 (1).odt
2014-09-18 14:53 - 2014-09-18 14:53 - 00023003 _____ () C:\Users\HoP\Downloads\00099213.odt
2014-09-18 14:49 - 2014-09-18 14:49 - 00023014 _____ () C:\Users\HoP\Downloads\00099168.odt
2014-09-14 12:42 - 2014-09-14 12:42 - 01503538 _____ () C:\Users\HoP\Downloads\Silo---Hugh-Howey.mobi
2014-09-14 12:39 - 2014-09-14 12:40 - 00579241 _____ () C:\Users\HoP\Downloads\Grzedowicz_Popel_a_prach.rar
2014-09-11 22:45 - 2014-09-11 22:36 - 20957453 _____ () C:\Users\HoP\Desktop\uni.zip
2014-09-09 21:41 - 2014-09-09 21:51 - 71109440 _____ () C:\Users\HoP\Downloads\Ge-D.zip
2014-09-07 09:29 - 2014-09-07 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aplikace společnosti IBM
2014-09-07 09:29 - 2014-09-07 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aplikace spolecnosti IBM
2014-09-07 09:25 - 2014-09-07 09:25 - 00000000 ____D () C:\Users\HoP\AppData\Local\Lotus
2014-09-07 09:20 - 2014-09-07 09:29 - 00245525 _____ () C:\Users\HoP\Documents\IBMNotesInstall.log
2014-09-01 23:15 - 2014-09-01 23:17 - 12938084 _____ () C:\Users\HoP\Downloads\ilka.rar
2014-08-27 22:06 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-27 22:06 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-27 22:06 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-26 23:30 - 2014-08-27 09:25 - 00020080 _____ () C:\Users\HoP\Desktop\výsledky.xlsx
2014-08-26 22:44 - 2014-08-27 02:01 - 1467938816 _____ () C:\Users\HoP\Downloads\Sherlock-03x02-Znameni-tri.avi
2014-08-26 22:33 - 2014-08-26 23:55 - 1467924480 _____ () C:\Users\HoP\Downloads\Sherlock-03x01-Prázdný-katafalk.avi
2014-08-26 07:18 - 2014-08-26 07:18 - 00864018 _____ () C:\Users\HoP\Downloads\25838-4-40540.zip
2014-08-23 17:45 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-23 17:45 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-23 17:45 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-23 17:45 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-23 17:45 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-23 17:45 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-23 17:45 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-23 17:45 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 23:51 - 2014-09-21 23:50 - 00019625 _____ () C:\Users\HoP\Desktop\FRST.txt
2014-09-21 23:50 - 2014-09-21 23:50 - 00029696 _____ () C:\Users\HoP\AppData\Local\MSGBOX.EXE
2014-09-21 23:50 - 2014-09-21 23:50 - 00015327 _____ () C:\Users\HoP\Desktop\LM.bat
2014-09-21 23:50 - 2014-06-03 16:40 - 00000954 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322501825-3049014203-3362302476-1000UA.job
2014-09-21 23:50 - 2014-03-10 07:11 - 00000000 ____D () C:\FRST
2014-09-21 23:49 - 2014-09-21 23:47 - 00112640 _____ (forum.viry.cz) C:\Users\HoP\Desktop\FRSTLauncher.exe
2014-09-21 23:47 - 2014-09-21 23:47 - 02105856 _____ (Farbar) C:\Users\HoP\Desktop\FRST64.exe
2014-09-21 23:44 - 2009-07-14 06:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-21 23:44 - 2009-07-14 06:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-21 23:40 - 2012-12-24 01:41 - 00669340 _____ () C:\Windows\system32\perfh005.dat
2014-09-21 23:40 - 2012-12-24 01:41 - 00141530 _____ () C:\Windows\system32\perfc005.dat
2014-09-21 23:40 - 2012-12-23 16:46 - 01842877 _____ () C:\Windows\WindowsUpdate.log
2014-09-21 23:40 - 2009-07-14 07:13 - 01585528 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-21 23:38 - 2012-12-24 16:34 - 00000000 ____D () C:\Users\HoP\AppData\Roaming\Skype
2014-09-21 23:37 - 2014-09-21 23:27 - 00008876 _____ () C:\zoek-results.log
2014-09-21 23:36 - 2012-12-23 17:51 - 00000942 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-21 23:35 - 2014-05-31 23:34 - 00002276 _____ () C:\Windows\PFRO.log
2014-09-21 23:35 - 2014-03-10 16:15 - 00045339 _____ () C:\Windows\setupact.log
2014-09-21 23:35 - 2012-12-24 13:57 - 00000000 ____D () C:\ProgramData\VMware
2014-09-21 23:35 - 2012-12-24 04:17 - 00055928 _____ () C:\SUService.log
2014-09-21 23:35 - 2012-12-23 17:16 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-21 23:35 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-21 23:33 - 2014-09-21 23:25 - 00000000 ____D () C:\zoek_backup
2014-09-21 23:33 - 2012-12-23 17:51 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-21 23:25 - 2014-09-21 23:34 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 23:25 - 2014-09-21 23:24 - 01290752 _____ () C:\Users\HoP\Desktop\zoek.exe
2014-09-21 22:05 - 2012-12-25 14:28 - 00000000 ____D () C:\Users\HoP\Downloads\obr
2014-09-21 22:04 - 2014-03-10 19:13 - 00000000 ____D () C:\Users\HoP\Desktop\Anti
2014-09-21 21:41 - 2014-09-21 21:31 - 00000000 ____D () C:\Program Files\trend micro
2014-09-21 21:31 - 2014-09-21 21:31 - 00000000 ____D () C:\rsit
2014-09-21 21:13 - 2014-03-10 16:12 - 00000000 ____D () C:\AdwCleaner
2014-09-21 20:29 - 2014-06-03 16:40 - 00000902 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322501825-3049014203-3362302476-1000Core.job
2014-09-21 20:20 - 2014-09-21 20:20 - 00009013 _____ () C:\Users\HoP\Downloads\attach.xsp
2014-09-20 21:41 - 2012-12-24 17:55 - 00000000 ____D () C:\Users\HoP\AppData\Roaming\VMware
2014-09-20 21:29 - 2012-12-24 17:55 - 00000000 ____D () C:\Users\HoP\AppData\Local\VMware
2014-09-18 14:59 - 2014-09-18 14:59 - 00023014 _____ () C:\Users\HoP\Downloads\00099168 (1).odt
2014-09-18 14:53 - 2014-09-18 14:53 - 00023003 _____ () C:\Users\HoP\Downloads\00099213.odt
2014-09-18 14:49 - 2014-09-18 14:49 - 00023014 _____ () C:\Users\HoP\Downloads\00099168.odt
2014-09-18 06:03 - 2008-02-18 10:53 - 00000730 _____ () C:\Users\HoP\Desktop\tmp.txt
2014-09-15 01:47 - 2013-01-29 01:32 - 00000000 ____D () C:\Users\HoP\Downloads\source
2014-09-14 12:42 - 2014-09-14 12:42 - 01503538 _____ () C:\Users\HoP\Downloads\Silo---Hugh-Howey.mobi
2014-09-14 12:40 - 2014-09-14 12:39 - 00579241 _____ () C:\Users\HoP\Downloads\Grzedowicz_Popel_a_prach.rar
2014-09-12 22:52 - 2014-03-09 13:35 - 00000000 ____D () C:\Users\HoP\Downloads\capture
2014-09-11 22:36 - 2014-09-11 22:45 - 20957453 _____ () C:\Users\HoP\Desktop\uni.zip
2014-09-09 21:51 - 2014-09-09 21:41 - 71109440 _____ () C:\Users\HoP\Downloads\Ge-D.zip
2014-09-07 09:29 - 2014-09-07 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aplikace společnosti IBM
2014-09-07 09:29 - 2014-09-07 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aplikace spolecnosti IBM
2014-09-07 09:29 - 2014-09-07 09:20 - 00245525 _____ () C:\Users\HoP\Documents\IBMNotesInstall.log
2014-09-07 09:25 - 2014-09-07 09:25 - 00000000 ____D () C:\Users\HoP\AppData\Local\Lotus
2014-09-07 09:25 - 2012-12-24 04:03 - 01324099 _____ () C:\Users\HoP\Documents\LotusInstall.log
2014-09-07 09:23 - 2012-12-24 04:15 - 00059518 _____ () C:\Users\HoP\install.xml
2014-09-07 09:23 - 2012-12-23 16:46 - 00000000 ____D () C:\Users\HoP
2014-09-06 16:29 - 2009-07-14 06:45 - 00344288 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-03 00:19 - 2014-01-25 10:24 - 00663552 _____ () C:\Users\HoP\Desktop\Zkouska.nsf
2014-09-01 23:17 - 2014-09-01 23:15 - 12938084 _____ () C:\Users\HoP\Downloads\ilka.rar
2014-08-27 15:30 - 2013-07-11 10:23 - 00000000 ____D () C:\Users\HoP\Downloads\texty
2014-08-27 09:25 - 2014-08-26 23:30 - 00020080 _____ () C:\Users\HoP\Desktop\výsledky.xlsx
2014-08-27 02:01 - 2014-08-26 22:44 - 1467938816 _____ () C:\Users\HoP\Downloads\Sherlock-03x02-Znameni-tri.avi
2014-08-26 23:55 - 2014-08-26 22:33 - 1467924480 _____ () C:\Users\HoP\Downloads\Sherlock-03x01-Prázdný-katafalk.avi
2014-08-26 07:18 - 2014-08-26 07:18 - 00864018 _____ () C:\Users\HoP\Downloads\25838-4-40540.zip
2014-08-23 21:37 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-23 19:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-23 17:49 - 2013-07-22 01:16 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-23 17:46 - 2012-12-23 17:34 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-23 04:07 - 2014-08-27 22:06 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-27 22:06 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-27 22:06 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-16 00:25
==================== End Of Log ============================
Ran by HoP (administrator) on GRAYLATITUDE on 21-09-2014 23:50:57
Running from C:\Users\HoP\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
(Broadcom Corporation) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
() C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe
() C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe
(EMC Corporation) C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebCaptureService.exe
(UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(IBM) C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe
(IBM Corp) C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe
(IBM Corp) C:\Program Files (x86)\IBM\Lotus\Notes\ntmulti.exe
(O2Micro International) C:\Windows\System32\drivers\o2flash.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(EMC Corporation) C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebToolkitHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
() C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\5429c7d215901eb.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe
() C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
() C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe
(OLYMPUS IMAGING CORP.) C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe
(Gemfor s.r.o.) C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe
(Nokia) C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe
(Codegeeks) C:\Program Files (x86)\Microsoft\DarkSetup\Dark.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(PFU LIMITED) C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(PFU LIMITED) C:\Windows\twain_32\fjscan32\SOP\FtLnSOP.exe
(Suunto Oy) C:\Program Files (x86)\Suunto\Moveslink for Movestick Mini\Moveslink.exe
(PFU LIMITED) C:\Windows\PIXTRAN\fujitsu\FiWiaChecker.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Windows\ehome\mcGlidHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NVHotkey] => rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [1692264 2011-05-05] ()
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [TdmNotify] => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [381296 2011-12-08] (Wave Systems Corp.)
HKLM-x32\...\Run: [RUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [FtLnSOP_setup] => C:\Windows\Twain_32\Fjscan32\SOP\FtLnSOP.exe [233472 2012-04-05] (PFU LIMITED)
HKLM-x32\...\Run: [“FjISIS WIA Service Checker] => C:\Windows\pixtran\fujitsu\FiWiaChecker.exe [86016 2009-10-21] (PFU LIMITED)
HKLM-x32\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe [55656 2013-01-25] (OLYMPUS IMAGING CORP.)
HKLM-x32\...\Run: [NSU_agent] => C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [190768 2012-02-28] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [OscarEditor] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] ()
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [supertintin_skype] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] ()
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe [420200 2013-01-25] (OLYMPUS IMAGING CORP.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PC Suite Tray] => C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [T-Mobile CManager] => C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\Manager.exe [2166552 2013-10-31] (Gemfor s.r.o.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [NokiaPCInternetAccess] => C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [651264 2009-05-26] (Nokia)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Dark] => C:\Program Files (x86)\Microsoft\DarkSetup\Dark.exe [88576 2009-11-25] (Codegeeks)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [13323608 2014-02-13] (NTeWORKS)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Google Update] => C:\Users\HoP\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-06-03] (Google Inc.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21648480 2014-07-02] (Skype Technologies S.A.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\MountPoints2: {f59d3bdf-93c0-11e2-947c-60d819f83ef5} - E:\NokiaPCIA_Autorun.exe
Lsa: [Authentication Packages] msv1_0 wvauth
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Error Recovery Guide.lnk
ShortcutTarget: Error Recovery Guide.lnk -> C:\Windows\twain_32\fjscan32\ERG\FTErGuid.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Moveslink for Movestick Mini.lnk
ShortcutTarget: Moveslink for Movestick Mini.lnk -> C:\Windows\Installer\{4D036ACA-DFDF-41B2-A680-E0D736F3E947}\_22A9010B636AF7A61D8E03.exe ()
ShellIconOverlayIdentifiers: EnabledUnlockedFDEIconOverlay -> {30D3C2AF-9709-4D05-9CF4-13335F3C1E4A} => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll (Wave Systems Corp.)
ShellIconOverlayIdentifiers: UninitializedFdeIconOverlay -> {CF08DA3E-C97D-4891-A66B-E39B28DD270F} => C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmIconOverlay.dll (Wave Systems Corp.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:17132
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/s ... wflash.cab
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin -> C:\Users\HoP\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin -> C:\Users\HoP\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\HoP\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\HoP\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\HoP\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Users\HoP\AppData\Roaming\mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\HoP\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\HoP\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
Chrome:
=======
CHR Profile: C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-21]
CHR Extension: (Google Docs) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-21]
CHR Extension: (Google Drive) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-12-23]
CHR Extension: (YouTube) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-23]
CHR Extension: (Google Search) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-23]
CHR Extension: (Video Viewer) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\dejgnnjohnpljeijfendiiafgpaenbip [2012-12-23]
CHR Extension: (Tennis) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekkomjfglgnfeeachhdckcbgjhfiahco [2012-12-23]
CHR Extension: (Google Sheets) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-21]
CHR Extension: (Hit The Jackpot 2) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgjacmakiifbpglpcogkbenamalgaoei [2012-12-23]
CHR Extension: (Apple Shooter) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbcjjgkapdombcilbfbjapkbpnocbkcf [2012-12-23]
CHR Extension: (Google Wallet) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
CHR Extension: (Gmail) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-12-23]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 068f03c44bb6a6c.exe; C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe [93696 2014-05-27] () [File not signed]
R2 EmbassyService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [218504 2012-01-17] ()
R2 Emc.Captiva.WebCaptureService; C:\Program Files (x86)\EMC Captiva\Captiva Cloud Runtime\Emc.Captiva.WebCaptureService.exe [39936 2012-04-04] (EMC Corporation) [File not signed]
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [100864 2012-09-07] (Freemake) [File not signed]
R2 IBM Notes Diagnostics; C:\Program Files (x86)\IBM\Lotus\Notes\nsd.exe [5164136 2013-10-15] (IBM)
R2 LNSUSvc; C:\Program Files (x86)\IBM\Lotus\Notes\SUService.exe [1654376 2013-10-15] (IBM Corp)
R2 MbnExt; C:\Program Files (x86)\T-Mobile\T-Mobile Internet Manager\MbnExt.dll [417128 2013-12-02] (Gemfor s.r.o.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1637888 2011-10-08] () [File not signed]
R2 VMAuthdService; C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe [79872 2012-11-01] (VMware, Inc.) [File not signed]
R2 Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [1679872 2012-01-05] (Wave Systems Corp.) [File not signed]
S3 WvPCR; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [198144 2012-01-16] (Wave Systems Corp.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-12-24] (DT Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 RegFltrX64; C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\RegFltrX64.sys [18064 2014-05-27] ()
R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [101376 2011-11-21] (Renesas Electronics Corporation)
R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [217088 2011-11-21] (Renesas Electronics Corporation)
R2 VMparport; C:\Windows\system32\drivers\VMparport.sys [31384 2012-11-01] (VMware, Inc.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [70296 2012-10-24] (VMware, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 23:50 - 2014-09-21 23:51 - 00019625 _____ () C:\Users\HoP\Desktop\FRST.txt
2014-09-21 23:50 - 2014-09-21 23:50 - 00029696 _____ () C:\Users\HoP\AppData\Local\MSGBOX.EXE
2014-09-21 23:50 - 2014-09-21 23:50 - 00015327 _____ () C:\Users\HoP\Desktop\LM.bat
2014-09-21 23:47 - 2014-09-21 23:49 - 00112640 _____ (forum.viry.cz) C:\Users\HoP\Desktop\FRSTLauncher.exe
2014-09-21 23:47 - 2014-09-21 23:47 - 02105856 _____ (Farbar) C:\Users\HoP\Desktop\FRST64.exe
2014-09-21 23:34 - 2014-09-21 23:25 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 23:27 - 2014-09-21 23:37 - 00008876 _____ () C:\zoek-results.log
2014-09-21 23:25 - 2014-09-21 23:33 - 00000000 ____D () C:\zoek_backup
2014-09-21 23:24 - 2014-09-21 23:25 - 01290752 _____ () C:\Users\HoP\Desktop\zoek.exe
2014-09-21 21:31 - 2014-09-21 21:41 - 00000000 ____D () C:\Program Files\trend micro
2014-09-21 21:31 - 2014-09-21 21:31 - 00000000 ____D () C:\rsit
2014-09-21 20:20 - 2014-09-21 20:20 - 00009013 _____ () C:\Users\HoP\Downloads\attach.xsp
2014-09-18 14:59 - 2014-09-18 14:59 - 00023014 _____ () C:\Users\HoP\Downloads\00099168 (1).odt
2014-09-18 14:53 - 2014-09-18 14:53 - 00023003 _____ () C:\Users\HoP\Downloads\00099213.odt
2014-09-18 14:49 - 2014-09-18 14:49 - 00023014 _____ () C:\Users\HoP\Downloads\00099168.odt
2014-09-14 12:42 - 2014-09-14 12:42 - 01503538 _____ () C:\Users\HoP\Downloads\Silo---Hugh-Howey.mobi
2014-09-14 12:39 - 2014-09-14 12:40 - 00579241 _____ () C:\Users\HoP\Downloads\Grzedowicz_Popel_a_prach.rar
2014-09-11 22:45 - 2014-09-11 22:36 - 20957453 _____ () C:\Users\HoP\Desktop\uni.zip
2014-09-09 21:41 - 2014-09-09 21:51 - 71109440 _____ () C:\Users\HoP\Downloads\Ge-D.zip
2014-09-07 09:29 - 2014-09-07 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aplikace společnosti IBM
2014-09-07 09:29 - 2014-09-07 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aplikace spolecnosti IBM
2014-09-07 09:25 - 2014-09-07 09:25 - 00000000 ____D () C:\Users\HoP\AppData\Local\Lotus
2014-09-07 09:20 - 2014-09-07 09:29 - 00245525 _____ () C:\Users\HoP\Documents\IBMNotesInstall.log
2014-09-01 23:15 - 2014-09-01 23:17 - 12938084 _____ () C:\Users\HoP\Downloads\ilka.rar
2014-08-27 22:06 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-27 22:06 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-27 22:06 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-26 23:30 - 2014-08-27 09:25 - 00020080 _____ () C:\Users\HoP\Desktop\výsledky.xlsx
2014-08-26 22:44 - 2014-08-27 02:01 - 1467938816 _____ () C:\Users\HoP\Downloads\Sherlock-03x02-Znameni-tri.avi
2014-08-26 22:33 - 2014-08-26 23:55 - 1467924480 _____ () C:\Users\HoP\Downloads\Sherlock-03x01-Prázdný-katafalk.avi
2014-08-26 07:18 - 2014-08-26 07:18 - 00864018 _____ () C:\Users\HoP\Downloads\25838-4-40540.zip
2014-08-23 17:45 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-23 17:45 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-23 17:45 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-23 17:45 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-23 17:45 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-23 17:45 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-23 17:45 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-23 17:45 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-21 23:51 - 2014-09-21 23:50 - 00019625 _____ () C:\Users\HoP\Desktop\FRST.txt
2014-09-21 23:50 - 2014-09-21 23:50 - 00029696 _____ () C:\Users\HoP\AppData\Local\MSGBOX.EXE
2014-09-21 23:50 - 2014-09-21 23:50 - 00015327 _____ () C:\Users\HoP\Desktop\LM.bat
2014-09-21 23:50 - 2014-06-03 16:40 - 00000954 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322501825-3049014203-3362302476-1000UA.job
2014-09-21 23:50 - 2014-03-10 07:11 - 00000000 ____D () C:\FRST
2014-09-21 23:49 - 2014-09-21 23:47 - 00112640 _____ (forum.viry.cz) C:\Users\HoP\Desktop\FRSTLauncher.exe
2014-09-21 23:47 - 2014-09-21 23:47 - 02105856 _____ (Farbar) C:\Users\HoP\Desktop\FRST64.exe
2014-09-21 23:44 - 2009-07-14 06:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-21 23:44 - 2009-07-14 06:45 - 00021312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-21 23:40 - 2012-12-24 01:41 - 00669340 _____ () C:\Windows\system32\perfh005.dat
2014-09-21 23:40 - 2012-12-24 01:41 - 00141530 _____ () C:\Windows\system32\perfc005.dat
2014-09-21 23:40 - 2012-12-23 16:46 - 01842877 _____ () C:\Windows\WindowsUpdate.log
2014-09-21 23:40 - 2009-07-14 07:13 - 01585528 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-21 23:38 - 2012-12-24 16:34 - 00000000 ____D () C:\Users\HoP\AppData\Roaming\Skype
2014-09-21 23:37 - 2014-09-21 23:27 - 00008876 _____ () C:\zoek-results.log
2014-09-21 23:36 - 2012-12-23 17:51 - 00000942 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-21 23:35 - 2014-05-31 23:34 - 00002276 _____ () C:\Windows\PFRO.log
2014-09-21 23:35 - 2014-03-10 16:15 - 00045339 _____ () C:\Windows\setupact.log
2014-09-21 23:35 - 2012-12-24 13:57 - 00000000 ____D () C:\ProgramData\VMware
2014-09-21 23:35 - 2012-12-24 04:17 - 00055928 _____ () C:\SUService.log
2014-09-21 23:35 - 2012-12-23 17:16 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-21 23:35 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-21 23:33 - 2014-09-21 23:25 - 00000000 ____D () C:\zoek_backup
2014-09-21 23:33 - 2012-12-23 17:51 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-21 23:25 - 2014-09-21 23:34 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 23:25 - 2014-09-21 23:24 - 01290752 _____ () C:\Users\HoP\Desktop\zoek.exe
2014-09-21 22:05 - 2012-12-25 14:28 - 00000000 ____D () C:\Users\HoP\Downloads\obr
2014-09-21 22:04 - 2014-03-10 19:13 - 00000000 ____D () C:\Users\HoP\Desktop\Anti
2014-09-21 21:41 - 2014-09-21 21:31 - 00000000 ____D () C:\Program Files\trend micro
2014-09-21 21:31 - 2014-09-21 21:31 - 00000000 ____D () C:\rsit
2014-09-21 21:13 - 2014-03-10 16:12 - 00000000 ____D () C:\AdwCleaner
2014-09-21 20:29 - 2014-06-03 16:40 - 00000902 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3322501825-3049014203-3362302476-1000Core.job
2014-09-21 20:20 - 2014-09-21 20:20 - 00009013 _____ () C:\Users\HoP\Downloads\attach.xsp
2014-09-20 21:41 - 2012-12-24 17:55 - 00000000 ____D () C:\Users\HoP\AppData\Roaming\VMware
2014-09-20 21:29 - 2012-12-24 17:55 - 00000000 ____D () C:\Users\HoP\AppData\Local\VMware
2014-09-18 14:59 - 2014-09-18 14:59 - 00023014 _____ () C:\Users\HoP\Downloads\00099168 (1).odt
2014-09-18 14:53 - 2014-09-18 14:53 - 00023003 _____ () C:\Users\HoP\Downloads\00099213.odt
2014-09-18 14:49 - 2014-09-18 14:49 - 00023014 _____ () C:\Users\HoP\Downloads\00099168.odt
2014-09-18 06:03 - 2008-02-18 10:53 - 00000730 _____ () C:\Users\HoP\Desktop\tmp.txt
2014-09-15 01:47 - 2013-01-29 01:32 - 00000000 ____D () C:\Users\HoP\Downloads\source
2014-09-14 12:42 - 2014-09-14 12:42 - 01503538 _____ () C:\Users\HoP\Downloads\Silo---Hugh-Howey.mobi
2014-09-14 12:40 - 2014-09-14 12:39 - 00579241 _____ () C:\Users\HoP\Downloads\Grzedowicz_Popel_a_prach.rar
2014-09-12 22:52 - 2014-03-09 13:35 - 00000000 ____D () C:\Users\HoP\Downloads\capture
2014-09-11 22:36 - 2014-09-11 22:45 - 20957453 _____ () C:\Users\HoP\Desktop\uni.zip
2014-09-09 21:51 - 2014-09-09 21:41 - 71109440 _____ () C:\Users\HoP\Downloads\Ge-D.zip
2014-09-07 09:29 - 2014-09-07 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aplikace společnosti IBM
2014-09-07 09:29 - 2014-09-07 09:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aplikace spolecnosti IBM
2014-09-07 09:29 - 2014-09-07 09:20 - 00245525 _____ () C:\Users\HoP\Documents\IBMNotesInstall.log
2014-09-07 09:25 - 2014-09-07 09:25 - 00000000 ____D () C:\Users\HoP\AppData\Local\Lotus
2014-09-07 09:25 - 2012-12-24 04:03 - 01324099 _____ () C:\Users\HoP\Documents\LotusInstall.log
2014-09-07 09:23 - 2012-12-24 04:15 - 00059518 _____ () C:\Users\HoP\install.xml
2014-09-07 09:23 - 2012-12-23 16:46 - 00000000 ____D () C:\Users\HoP
2014-09-06 16:29 - 2009-07-14 06:45 - 00344288 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-09-03 00:19 - 2014-01-25 10:24 - 00663552 _____ () C:\Users\HoP\Desktop\Zkouska.nsf
2014-09-01 23:17 - 2014-09-01 23:15 - 12938084 _____ () C:\Users\HoP\Downloads\ilka.rar
2014-08-27 15:30 - 2013-07-11 10:23 - 00000000 ____D () C:\Users\HoP\Downloads\texty
2014-08-27 09:25 - 2014-08-26 23:30 - 00020080 _____ () C:\Users\HoP\Desktop\výsledky.xlsx
2014-08-27 02:01 - 2014-08-26 22:44 - 1467938816 _____ () C:\Users\HoP\Downloads\Sherlock-03x02-Znameni-tri.avi
2014-08-26 23:55 - 2014-08-26 22:33 - 1467924480 _____ () C:\Users\HoP\Downloads\Sherlock-03x01-Prázdný-katafalk.avi
2014-08-26 07:18 - 2014-08-26 07:18 - 00864018 _____ () C:\Users\HoP\Downloads\25838-4-40540.zip
2014-08-23 21:37 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-23 19:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-23 17:49 - 2013-07-22 01:16 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-23 17:46 - 2012-12-23 17:34 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-23 04:07 - 2014-08-27 22:06 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-27 22:06 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-27 22:06 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-16 00:25
==================== End Of Log ============================
Re: prosba o kontrolu logu - vyskakují okna
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start CloseProcesses: HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated) HKLM-x32\...\Run: [NSU_agent] => C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [190768 2012-02-28] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation) HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd) HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [OscarEditor] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] () HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [supertintin_skype] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] () HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PC Suite Tray] => C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia) HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [NokiaPCInternetAccess] => C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [651264 2009-05-26] (Nokia) HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [13323608 2014-02-13] (NTeWORKS) HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Google Update] => C:\Users\HoP\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-06-03] (Google Inc.) HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21648480 2014-07-02] (Skype Technologies S.A.) HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\MountPoints2: {f59d3bdf-93c0-11e2-947c-60d819f83ef5} - E:\NokiaPCIA_Autorun.exe ProxyEnable: Internet Explorer proxy is enabled. ProxyServer: http=127.0.0.1:17132 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File CHR Extension: (Hit The Jackpot 2) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgjacmakiifbpglpcogkbenamalgaoei [2012-12-23] R2 068f03c44bb6a6c.exe; C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe [93696 2014-05-27] () [File not signed] C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd 2014-09-21 23:50 - 2014-09-21 23:51 - 00019625 _____ () C:\Users\HoP\Desktop\FRST.txt 2014-09-21 23:50 - 2014-09-21 23:50 - 00029696 _____ () C:\Users\HoP\AppData\Local\MSGBOX.EXE 2014-09-21 23:50 - 2014-09-21 23:50 - 00015327 _____ () C:\Users\HoP\Desktop\LM.bat 2014-09-21 23:47 - 2014-09-21 23:49 - 00112640 _____ (forum.viry.cz) C:\Users\HoP\Desktop\FRSTLauncher.exe 2014-09-21 23:34 - 2014-09-21 23:25 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-09-21 23:27 - 2014-09-21 23:37 - 00008876 _____ () C:\zoek-results.log 2014-09-21 23:25 - 2014-09-21 23:33 - 00000000 ____D () C:\zoek_backup 2014-09-21 23:24 - 2014-09-21 23:25 - 01290752 _____ () C:\Users\HoP\Desktop\zoek.exe 2014-09-21 21:31 - 2014-09-21 21:41 - 00000000 ____D () C:\Program Files\trend micro 2014-09-21 21:31 - 2014-09-21 21:31 - 00000000 ____D () C:\rsit C:\Windows\tasks\GoogleUpdateTaskMachineCore.job Hosts: EmptyTemp: Reboot: End- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
Re: prosba o kontrolu logu - vyskakují okna
Provedeno, jen teď nenabíhá chrome, prý mám nastaveno proxy, které ale v nastavení nevidím
vkládám tedy pomocí IE
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-09-2014 01
Ran by HoP at 2014-09-22 00:24:40 Run:1
Running from C:\Users\HoP\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NSU_agent] => C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [190768 2012-02-28] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [OscarEditor] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] ()
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [supertintin_skype] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] ()
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PC Suite Tray] => C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [NokiaPCInternetAccess] => C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [651264 2009-05-26] (Nokia)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [13323608 2014-02-13] (NTeWORKS)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Google Update] => C:\Users\HoP\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-06-03] (Google Inc.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21648480 2014-07-02] (Skype Technologies S.A.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\MountPoints2: {f59d3bdf-93c0-11e2-947c-60d819f83ef5} - E:\NokiaPCIA_Autorun.exe
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:17132
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File
CHR Extension: (Hit The JACKPOT 2) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgjacmakiifbpglpcogkbenamalgaoei [2012-12-23]
R2 068f03c44bb6a6c.exe; C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe [93696 2014-05-27] () [File not signed]
C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd
2014-09-21 23:50 - 2014-09-21 23:51 - 00019625 _____ () C:\Users\HoP\Desktop\FRST.txt
2014-09-21 23:50 - 2014-09-21 23:50 - 00029696 _____ () C:\Users\HoP\AppData\Local\MSGBOX.EXE
2014-09-21 23:50 - 2014-09-21 23:50 - 00015327 _____ () C:\Users\HoP\Desktop\LM.bat
2014-09-21 23:47 - 2014-09-21 23:49 - 00112640 _____ (forum.viry.cz) C:\Users\HoP\Desktop\FRSTLauncher.exe
2014-09-21 23:34 - 2014-09-21 23:25 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 23:27 - 2014-09-21 23:37 - 00008876 _____ () C:\zoek-results.log
2014-09-21 23:25 - 2014-09-21 23:33 - 00000000 ____D () C:\zoek_backup
2014-09-21 23:24 - 2014-09-21 23:25 - 01290752 _____ () C:\Users\HoP\Desktop\zoek.exe
2014-09-21 21:31 - 2014-09-21 21:41 - 00000000 ____D () C:\Program Files\trend micro
2014-09-21 21:31 - 2014-09-21 21:31 - 00000000 ____D () C:\rsit
C:\Windows\tasks\GoogleUpdateTaskMachineCore.JOB
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NSU_agent => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\OscarEditor => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\supertintin_skype => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\PC Suite Tray => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NokiaPCInternetAccess => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\PicPick Start => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => value deleted successfully.
"HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f59d3bdf-93c0-11e2-947c-60d819f83ef5}" => Key deleted successfully.
"HKCR\CLSID\{f59d3bdf-93c0-11e2-947c-60d819f83ef5}" => Key not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
"HKCR\PROTOCOLS\Handler\ipp\0x00000001" => Key deleted successfully.
"HKCR\CLSID\{E1D2BF42-A96B-11D1-9C6B-0000F875AC61}" => Key not found.
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgjacmakiifbpglpcogkbenamalgaoei => Moved successfully.
068f03c44bb6a6c.exe => Service deleted successfully.
C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd => Moved successfully.
"C:\Users\HoP\Desktop\FRST.txt" => File/Directory not found.
C:\Users\HoP\AppData\Local\MSGBOX.EXE => Moved successfully.
C:\Users\HoP\Desktop\LM.bat => Moved successfully.
C:\Users\HoP\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\HoP\Desktop\zoek.exe => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.JOB => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 298.2 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
vkládám tedy pomocí IE
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-09-2014 01
Ran by HoP at 2014-09-22 00:24:40 Run:1
Running from C:\Users\HoP\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NSU_agent] => C:\Program Files (x86)\Nokia\Nokia Software Updater\nsu3ui_agent.exe [190768 2012-02-28] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [OscarEditor] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] ()
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [supertintin_skype] => C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe [3340288 2012-03-20] ()
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PC Suite Tray] => C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe [1516632 2012-06-26] (Nokia)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [NokiaPCInternetAccess] => C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe [651264 2009-05-26] (Nokia)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [13323608 2014-02-13] (NTeWORKS)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Google Update] => C:\Users\HoP\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-06-03] (Google Inc.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21648480 2014-07-02] (Skype Technologies S.A.)
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\...\MountPoints2: {f59d3bdf-93c0-11e2-947c-60d819f83ef5} - E:\NokiaPCIA_Autorun.exe
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:17132
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File
CHR Extension: (Hit The JACKPOT 2) - C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgjacmakiifbpglpcogkbenamalgaoei [2012-12-23]
R2 068f03c44bb6a6c.exe; C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd\068f03c44bb6a6c.exe [93696 2014-05-27] () [File not signed]
C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd
2014-09-21 23:50 - 2014-09-21 23:51 - 00019625 _____ () C:\Users\HoP\Desktop\FRST.txt
2014-09-21 23:50 - 2014-09-21 23:50 - 00029696 _____ () C:\Users\HoP\AppData\Local\MSGBOX.EXE
2014-09-21 23:50 - 2014-09-21 23:50 - 00015327 _____ () C:\Users\HoP\Desktop\LM.bat
2014-09-21 23:47 - 2014-09-21 23:49 - 00112640 _____ (forum.viry.cz) C:\Users\HoP\Desktop\FRSTLauncher.exe
2014-09-21 23:34 - 2014-09-21 23:25 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-09-21 23:27 - 2014-09-21 23:37 - 00008876 _____ () C:\zoek-results.log
2014-09-21 23:25 - 2014-09-21 23:33 - 00000000 ____D () C:\zoek_backup
2014-09-21 23:24 - 2014-09-21 23:25 - 01290752 _____ () C:\Users\HoP\Desktop\zoek.exe
2014-09-21 21:31 - 2014-09-21 21:41 - 00000000 ____D () C:\Program Files\trend micro
2014-09-21 21:31 - 2014-09-21 21:31 - 00000000 ____D () C:\rsit
C:\Windows\tasks\GoogleUpdateTaskMachineCore.JOB
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\NSU_agent => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\OscarEditor => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\supertintin_skype => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\PC Suite Tray => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NokiaPCInternetAccess => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\PicPick Start => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully.
HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => value deleted successfully.
"HKU\S-1-5-21-3322501825-3049014203-3362302476-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f59d3bdf-93c0-11e2-947c-60d819f83ef5}" => Key deleted successfully.
"HKCR\CLSID\{f59d3bdf-93c0-11e2-947c-60d819f83ef5}" => Key not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
"HKCR\PROTOCOLS\Handler\ipp\0x00000001" => Key deleted successfully.
"HKCR\CLSID\{E1D2BF42-A96B-11D1-9C6B-0000F875AC61}" => Key not found.
C:\Users\HoP\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgjacmakiifbpglpcogkbenamalgaoei => Moved successfully.
068f03c44bb6a6c.exe => Service deleted successfully.
C:\Users\HoP\AppData\Local\38c67b3cd336487f17de5a11b85fb8dd => Moved successfully.
"C:\Users\HoP\Desktop\FRST.txt" => File/Directory not found.
C:\Users\HoP\AppData\Local\MSGBOX.EXE => Moved successfully.
C:\Users\HoP\Desktop\LM.bat => Moved successfully.
C:\Users\HoP\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\HoP\Desktop\zoek.exe => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
C:\Windows\tasks\GoogleUpdateTaskMachineCore.JOB => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 298.2 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: prosba o kontrolu logu - vyskakují okna
a už běží i Chrome, nic jsem neudělal, jen to zkusil po chvíli znovu
Re: prosba o kontrolu logu - vyskakují okna
Tak jeste uklidime
T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse 
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: prosba o kontrolu logu - vyskakují okna
Děkuji, podpora odeslána 
Re: prosba o kontrolu logu - vyskakují okna
Nemate zac, rad jsem pomohl
Zase nekdy 
Za podporu fora jmenem celeho tymu dekuji
A na zaklade Pravidla o zamykani temat

Za podporu fora jmenem celeho tymu dekuji
A na zaklade Pravidla o zamykani temat



Přispějete na provoz fóra?