Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém se zpomaleným PC. (Kontrola logu)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Radek9999
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 říj 2014 17:45

Problém se zpomaleným PC. (Kontrola logu)

#1 Příspěvek od Radek9999 »

Dobrý den,
poslední dobou jsem si všiml rapidního zpomalení PC. Mám taky problém s programem tzv: webssearch.com, který mi nejde z počítače odinstalovat. Zasílám log z RSIT a následdně z adwcleaneru:

RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Radek at 2014-10-17 19:05:07
Microsoft Windows 8.1 Service Pack 1
System drive C: has 578 GB (62%) free of 931 GB
Total RAM: 3914 MB (50% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:05:11, on 17. 10. 2014
Platform: Unknown Windows (WinNT 6.02.1008 SP1)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe
C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe
C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe
C:\Program Files\trend micro\Radek.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://istart.webssearches.com/?type=hp ... NKRJ5NKRJ5
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://istart.webssearches.com/web/?typ ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?typ ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://istart.webssearches.com/?type=hp ... NKRJ5NKRJ5
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IETabPage Class - {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - C:\Program Files (x86)\SupTab\SupTab.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: HulaToo - {ab65caf0-fc3b-40f8-8b88-6d096a48f659} - C:\Program Files (x86)\HulaToo\HulaToobho.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Device Fast-lane Service (DeviceFastLaneService) - Acer Incorporated - C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service - Flexera Software LLC - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: IePlugin Services (IePluginServices) - Cherished Technololgy LIMITED - C:\ProgramData\IePluginServices\PluginService.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: Nero Update (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: Dritek RF Button Command Service (RfButtonDriverService) - Dritek System INC. - C:\Windows\RfBtnSvc64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update HulaToo - Unknown owner - C:\Program Files (x86)\HulaToo\updateHulaToo.exe
O23 - Service: Util HulaToo - Unknown owner - C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12471 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"C:\WINDOWS\system32\nvvsvc.exe"
"dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\ProgramData\IePluginServices\PluginService.exe -service
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe"
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
dashost.exe {ab3e6c0d-a6ae-4366-b8743ba760ba3408}
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\RfBtnSvc64.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\HulaToo\updateHulaToo.exe"
"C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler64.exe"
"c:\Program Files (x86)\Nero\Update\NASvc.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
taskhostex.exe
"C:\Program Files (x86)\Launch Manager\LMutilps32.exe" --system-level --system-level-mutex="Local\{B904A927-FE6B-48fd-8C83-6B807BED1F9C}" --enable-wmi-window --enable-setforeground-window --enable-kbhook-window
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe"
"C:\WINDOWS\system32\igfxext.exe" -Embedding
C:\Windows\System32\skydrive.exe -Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Windows\System32\igfxtray.exe"
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Dolby PCEE4\pcee4.exe" -autostart
"C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe"
"C:/Users/Radek/AppData/Local/Akamai/netsession_win.exe" --client
"C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
"C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe"
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe"

"C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe"
"C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe"
"C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" http://istart.webssearches.com/?type=sc ... NKRJ5NKRJ5
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=5556.ff92890.595934877 "C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 5556 "\\.\pipe\gecko-crash-server-pipe.5556" plugin
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe" --proxy-stub-channel=Flash4840.67773FA8.18438 --host-broker-channel=Flash4840.67773FA8.25053 --host-pid=4840 --host-npapi-version=27 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_15_0_0_189.dll"
"C:\WINDOWS\SYSTEM32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe" --channel=1916.0052F4D0.1378775885 --proxy-stub-channel=Flash4840.67773FA8.18438 --plugin-path="C:\WINDOWS\SYSTEM32\Macromed\Flash\NPSWF32_15_0_0_189.dll" --host-npapi-version=27 --type=renderer
"C:\WINDOWS\system32\mspaint.exe"
taskeng.exe {2F1F3052-8423-4FF0-8227-984597C86750}
"C:\Programy\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default

prefs.js - "browser.startup.homepage" - "http://istart.webssearches.com/?type=hp ... NKRJ5NKRJ5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.189 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.189 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\extensions\
5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com
faststartff@gmail.com
iactgk-ja@p-xbyifoy.co.uk
n-zyj@ywrybi-.com
sitefinder@sitefinder.com
wle_0pl5a@ieolq-uiqg.com
yuerw@taqgsgsk.co.uk
{db615d8a-b766-4397-9ef1-0eeaf684d8da}

C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\searchplugins\
buenosearch.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63145F74-26EA-0CD6-A156-25F00B16939F}]
BlockThEAds - C:\ProgramData\BlockThEAds\MybqgOcx8.x64.dll [2014-02-12 475136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll [2013-01-28 66688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-08-18 612248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
IETabPage Class - C:\Program Files (x86)\SupTab\SupTab.dll [2014-07-10 515464]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-20 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-08-18 457712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ab65caf0-fc3b-40f8-8b88-6d096a48f659}]
HulaToo - C:\Program Files (x86)\HulaToo\HulaToobho.dll [2014-07-10 249624]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-20 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-01-30 13267016]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-01-18 1276488]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2014-07-25 1283136]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-07-25 2403104]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2014-01-25 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2014-01-25 771544]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2014-01-25 770520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [2013-01-28 132736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"=C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe [2014-04-17 4672920]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"RGSC"=C:\Program Files\Rockstar Games Social Club\RGSCLauncher.exe [2008-11-14 305064]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LManager"= []
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-08-18 4085896]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"Cisco AnyConnect Secure Mobility Agent for Windows"=C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [2013-12-13 707472]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-07-25 256896]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [2013-01-28 132736]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~2\SupTab\SEARCH~2.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2014-01-25 624640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-10-17 18:16:52 ----D---- C:\rsit
2014-10-17 18:16:52 ----D---- C:\Program Files\trend micro
2014-10-17 11:30:24 ----D---- C:\ProgramData\McAfee Security Scan
2014-10-17 11:30:22 ----D---- C:\Program Files (x86)\McAfee Security Scan
2014-10-15 11:16:43 ----D---- C:\Program Files\PyScripter
2014-10-15 10:50:38 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2014-10-15 10:50:38 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2014-10-15 10:50:35 ----A---- C:\WINDOWS\system32\winbici.dll
2014-10-15 10:50:23 ----A---- C:\WINDOWS\system32\generaltel.dll
2014-10-15 10:50:22 ----A---- C:\WINDOWS\system32\aepdu.dll
2014-10-15 10:50:21 ----A---- C:\WINDOWS\system32\aeinv.dll
2014-10-15 10:50:19 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2014-10-15 10:50:18 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-10-15 10:50:18 ----A---- C:\WINDOWS\system32\msi.dll
2014-10-15 10:50:18 ----A---- C:\WINDOWS\system32\authui.dll
2014-10-15 10:50:18 ----A---- C:\WINDOWS\system32\appinfo.dll
2014-10-15 10:50:06 ----A---- C:\WINDOWS\system32\shell32.dll
2014-10-15 10:50:04 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2014-10-15 10:50:02 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-10-15 10:50:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2014-10-15 10:50:00 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2014-10-15 10:50:00 ----A---- C:\WINDOWS\system32\mstscax.dll
2014-10-15 10:49:59 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2014-10-15 10:49:58 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-10-15 10:49:57 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2014-10-15 10:49:56 ----A---- C:\WINDOWS\system32\ntdll.dll
2014-10-15 10:49:56 ----A---- C:\WINDOWS\system32\KernelBase.dll
2014-10-15 10:49:55 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2014-10-15 10:49:55 ----A---- C:\WINDOWS\system32\propsys.dll
2014-10-15 10:49:54 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2014-10-15 10:49:54 ----A---- C:\WINDOWS\system32\WSShared.dll
2014-10-15 10:49:54 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2014-10-15 10:49:53 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2014-10-15 10:49:53 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2014-10-15 10:49:53 ----A---- C:\WINDOWS\system32\Wldap32.dll
2014-10-15 10:49:52 ----A---- C:\WINDOWS\SYSWOW64\Wldap32.dll
2014-10-15 10:49:52 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2014-10-15 10:49:52 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-10-15 10:49:50 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-10-15 10:49:50 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2014-10-15 10:49:50 ----A---- C:\WINDOWS\system32\bisrv.dll
2014-10-15 10:49:49 ----A---- C:\WINDOWS\system32\pcsvDevice.dll
2014-10-15 10:49:49 ----A---- C:\WINDOWS\system32\httpprxm.dll
2014-10-15 10:49:49 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2014-10-15 10:49:48 ----A---- C:\WINDOWS\SYSWOW64\SkyDriveShell.dll
2014-10-15 10:49:48 ----A---- C:\WINDOWS\system32\SkyDriveShell.dll
2014-10-15 10:49:48 ----A---- C:\WINDOWS\system32\ProximityService.dll
2014-10-15 10:49:48 ----A---- C:\WINDOWS\system32\adhsvc.dll
2014-10-15 10:49:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 10:49:46 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 10:48:37 ----A---- C:\WINDOWS\system32\win32k.sys
2014-10-15 10:47:37 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-10-15 10:47:34 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-10-15 10:47:15 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-10-15 10:47:11 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-10-15 10:47:08 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-10-15 10:47:06 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-10-15 10:47:04 ----A---- C:\WINDOWS\system32\wininet.dll
2014-10-15 10:47:04 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-10-15 10:47:03 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-10-15 10:47:03 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-10-15 10:47:03 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-10-15 10:47:01 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-10-15 10:47:01 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-10-15 10:46:59 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-10-15 10:46:58 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-10-15 10:46:58 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-10-15 10:46:57 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-10-15 10:46:56 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-10-15 10:46:54 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-10-15 10:46:54 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-10-15 10:46:54 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-10-15 10:46:54 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-10-15 10:46:54 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-10-15 10:46:54 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-10-15 10:46:53 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-10-15 10:46:53 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-10-15 10:46:53 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-10-15 10:46:52 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-10-15 10:43:53 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-10-15 10:43:52 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-10-15 10:43:52 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-10-15 10:43:52 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-10-15 10:43:51 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-10-15 10:43:51 ----A---- C:\WINDOWS\system32\wups2.dll
2014-10-15 10:43:51 ----A---- C:\WINDOWS\system32\wups.dll
2014-10-15 10:43:51 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-10-15 10:43:50 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2014-10-15 10:43:50 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-10-15 10:43:50 ----A---- C:\WINDOWS\system32\wuwebv.dll
2014-10-15 10:43:50 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-10-15 10:43:49 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2014-10-15 10:43:49 ----A---- C:\WINDOWS\system32\wuapp.exe
2014-10-15 10:43:07 ----A---- C:\WINDOWS\SYSWOW64\packager.dll
2014-10-15 10:43:07 ----A---- C:\WINDOWS\system32\packager.dll
2014-10-15 10:37:50 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2014-10-15 10:37:50 ----A---- C:\WINDOWS\system32\rastls.dll
2014-10-15 10:35:33 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2014-10-14 19:20:26 ----D---- C:\Program Files (x86)\PyScripter
2014-10-13 14:24:22 ----D---- C:\Users\Radek\AppData\Roaming\PyScripter
2014-10-13 13:22:35 ----A---- C:\autoexec.bat
2014-10-13 13:22:10 ----D---- C:\Program Files\Enigma Software Group
2014-10-13 13:21:12 ----D---- C:\WINDOWS\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-10-04 13:42:55 ----D---- C:\FIFA 15
2014-10-03 14:58:28 ----D---- C:\OVB
2014-10-01 12:05:56 ----D---- C:\Games
2014-09-24 23:22:00 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2014-10-17 19:02:03 ----D---- C:\WINDOWS\system32\sru
2014-10-17 18:53:43 ----D---- C:\WINDOWS\Temp
2014-10-17 18:51:29 ----D---- C:\WINDOWS\Prefetch
2014-10-17 18:39:02 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-10-17 18:36:05 ----D---- C:\Windows
2014-10-17 18:32:42 ----D---- C:\WINDOWS\Inf
2014-10-17 18:32:37 ----D---- C:\WINDOWS\SoftwareDistribution
2014-10-17 18:32:37 ----D---- C:\WINDOWS\debug
2014-10-17 18:26:37 ----D---- C:\Programy
2014-10-17 18:16:52 ----D---- C:\Program Files
2014-10-17 17:25:08 ----D---- C:\Hudba
2014-10-17 16:54:25 ----D---- C:\WINDOWS\system32\config
2014-10-17 16:52:24 ----D---- C:\WINDOWS\Microsoft.NET
2014-10-17 16:52:20 ----RSD---- C:\WINDOWS\assembly
2014-10-17 16:51:15 ----D---- C:\WINDOWS\system32\DriverStore
2014-10-17 16:39:25 ----D---- C:\Users\Radek\AppData\Roaming\Audacity
2014-10-17 14:43:01 ----D---- C:\WINDOWS\WinSxS
2014-10-17 14:38:08 ----SHD---- C:\System Volume Information
2014-10-17 11:30:24 ----HD---- C:\ProgramData
2014-10-17 11:30:22 ----RD---- C:\Program Files (x86)
2014-10-17 11:19:53 ----RD---- C:\WINDOWS\ToastData
2014-10-17 11:19:52 ----D---- C:\WINDOWS\WinStore
2014-10-17 11:19:52 ----D---- C:\WINDOWS\SysWOW64
2014-10-17 11:19:51 ----RD---- C:\WINDOWS\System32
2014-10-17 11:19:51 ----D---- C:\WINDOWS\system32\drivers
2014-10-17 11:19:50 ----D---- C:\WINDOWS\MediaViewer
2014-10-17 11:19:50 ----D---- C:\WINDOWS\FileManager
2014-10-17 11:19:50 ----D---- C:\WINDOWS\Camera
2014-10-17 11:19:49 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2014-10-17 11:19:49 ----D---- C:\Program Files\Internet Explorer
2014-10-17 11:19:49 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-17 11:19:48 ----D---- C:\WINDOWS\system32\cs-CZ
2014-10-17 00:45:16 ----D---- C:\WINDOWS\system32\catroot
2014-10-16 20:00:30 ----D---- C:\WINDOWS\CbsTemp
2014-10-16 19:56:36 ----D---- C:\WINDOWS\system32\MRT
2014-10-16 19:46:54 ----A---- C:\WINDOWS\system32\MRT.exe
2014-10-16 19:46:37 ----SD---- C:\WINDOWS\system32\CompatTel
2014-10-15 10:36:48 ----SHD---- C:\WINDOWS\Installer
2014-10-15 10:36:44 ----D---- C:\ProgramData\Microsoft Help
2014-10-15 10:11:56 ----D---- C:\WINDOWS\system32\catroot2
2014-10-14 01:04:48 ----D---- C:\WINDOWS\system32\NDF
2014-10-13 23:51:03 ----D---- C:\Hry
2014-10-13 23:50:27 ----D---- C:\WINDOWS\Tasks
2014-10-13 23:50:27 ----D---- C:\WINDOWS\system32\Tasks
2014-10-13 21:43:50 ----SD---- C:\Users\Radek\AppData\Roaming\Microsoft
2014-10-13 13:21:08 ----D---- C:\Program Files (x86)\Common Files
2014-10-13 13:01:16 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-12 16:54:06 ----D---- C:\WINDOWS\AppReadiness
2014-10-12 01:42:09 ----D---- C:\Users\Radek\AppData\Roaming\vlc
2014-10-11 21:42:09 ----D---- C:\Users\Radek\AppData\Roaming\uTorrent
2014-10-10 19:15:53 ----HD---- C:\Program Files\WindowsApps
2014-10-09 21:54:41 ----D---- C:\Filmy
2014-10-07 23:27:23 ----D---- C:\WINDOWS\Minidump
2014-10-07 19:51:09 ----D---- C:\ProgramData\Origin
2014-10-04 12:37:38 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-02 19:46:56 ----D---- C:\WINDOWS\rescache
2014-09-30 00:45:58 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2014-08-18 65776]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2014-08-18 224896]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-08-16 645952]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2014-07-02 32544]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2014-08-18 93568]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2014-08-18 1041168]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2014-08-18 427360]
R1 dtsoftbus01;@oem3.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2014-08-14 283064]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2014-08-18 29208]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2014-08-18 79184]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2014-08-18 92008]
R3 AthBTPort;@oem10.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2013-01-28 89168]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 BTATH_A2DP;@oem9.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2013-01-28 346192]
R3 btath_avdt;@oem9.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2013-01-28 115280]
R3 BTATH_BUS;@oem6.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\WINDOWS\System32\drivers\btath_bus.sys [2013-01-28 34384]
R3 BTATH_HCRP;@oem12.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2013-01-28 179432]
R3 BTATH_LWFLT;@oem21.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2013-01-28 77464]
R3 BTATH_RCP;@oem17.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2013-01-28 136424]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2013-01-28 581200]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-01-25 4221440]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-01-30 3311944]
R3 IntcDAud;@oem20.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-06-19 342528]
R3 iwdbus;@oem28.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MEIx64;@oem23.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2014-07-02 12866008]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-07-25 20256]
R3 nvvad_WaveExtensible;@oem39.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2014-03-31 40392]
R3 Ps2Kb2Hid;@oem24.inf,%Ps2Kb2Hid.SVCDESC%;PS/2 Keyboard to HID Driver; C:\WINDOWS\System32\drivers\aPs2Kb2Hid.sys [2013-10-09 26736]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2013-08-22 212224]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 acsock;acsock; C:\WINDOWS\system32\DRIVERS\acsock64.sys [2013-12-13 112496]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 dg_ssudbus;@oem36.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 esgiguard;esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys []
S3 ETD;@oem3.inf,%PS2.DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2012-12-07 331664]
S3 intaud_WaveExtensible;@oem27.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 RSPCIESTOR;@oem2.inf,%Rts5208%;Realtek PCIE CardReader Driver; C:\WINDOWS\system32\DRIVERS\RtsPStor.sys [2012-08-03 340112]
S3 ssudmdm;@oem37.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2013-08-22 33280]
S3 vpnva;@oem16.inf,%VPNVA64_Desc%;Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64; C:\WINDOWS\system32\DRIVERS\vpnva64-6.sys [2013-10-10 52080]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [2013-01-28 227456]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-08-18 50344]
R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2013-02-20 2615368]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2012-12-10 350544]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-07-24 2457232]
R2 IePluginServices;IePlugin Services; C:\ProgramData\IePluginServices\PluginService.exe [2014-07-10 759688]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-17 165760]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 276864]
R2 NAUpdate;Nero Update; c:\Program Files (x86)\Nero\Update\NASvc.exe [2012-07-14 769432]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-07-25 1720608]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-07-25 18956064]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2014-07-02 935368]
R2 RfButtonDriverService;Dritek RF Button Command Service; C:\Windows\RfBtnSvc64.exe [2013-10-09 93296]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 364416]
R2 Update HulaToo;Update HulaToo; C:\Program Files (x86)\HulaToo\updateHulaToo.exe [2014-07-10 319256]
R2 Util HulaToo;Util HulaToo; C:\Program Files (x86)\HulaToo\bin\utilHulaToo.exe [2014-07-10 319256]
R2 vpnagent;Cisco AnyConnect Secure Mobility Agent; C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe [2013-12-13 560528]
R3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2013-03-16 662088]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-21 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-17 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-01-25 279000]
S3 DeviceFastLaneService;Device Fast-lane Service; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [2012-11-16 469648]
S3 FlexNet Licensing Service;FlexNet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe [2014-03-03 1074480]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-21 116648]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [2012-09-05 234776]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-09-24 114288]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]

-----------------EOF-----------------




Adwcleaner_4.000:

# AdwCleaner v4.000 - Report created 17/10/2014 at 19:14:50
# Updated 12/10/2014 by Xplode
# Database : 2014-10-17.9
# Operating System : Windows 8.1 Service Pack 1 (64 bits)
# Username : Radek - RADEK
# Running from : C:\Programy\adwcleaner_4.000.exe
# Option : Scan

***** [ Services ] *****

Service Found : IePluginServices
Service Found : Update HulaToo
Service Found : Util HulaToo
Service Found : {2635ac50-5488-40bf-9bfd-accb158f8f3f}w64

***** [ Files / Folders ] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml
File Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\{5ebdca98-43b3-45bb-87e0-716029fb42ab}.xpi
File Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\invalidprefs.js
File Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\searchplugins\buenosearch.xml
File Found : C:\WINDOWS\System32\\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}w64.sys
File Found : C:\WINDOWS\SysWOW64\hfpapi.dll
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\GS-Enabler
Folder Found : C:\Program Files (x86)\HulaToo
Folder Found : C:\Program Files (x86)\save net
Folder Found : C:\Program Files (x86)\SimilarSites
Folder Found : C:\Program Files (x86)\SupTab
Folder Found : C:\Program Files (x86)\sw-booster
Folder Found : C:\Program Files (x86)\YoutubeAdblocker
Folder Found : C:\Program Files\Enigma Software Group
Folder Found : C:\ProgramData\IePluginServices
Folder Found : C:\ProgramData\save net
Folder Found : C:\ProgramData\SoftWarehouse
Folder Found : C:\ProgramData\WindowsMangerProtect
Folder Found : C:\ProgramData\YoutubeAdblocker
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Administrator\AppData\Local\torch
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\ASPNET\AppData\Local\torch
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Guest\AppData\Local\torch
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Found : C:\Users\Radek\AppData\Local\globalUpdate
Folder Found : C:\Users\Radek\AppData\Local\PackageAware
Folder Found : C:\Users\Radek\AppData\Local\torch
Folder Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\faststartff@gmail.com
Folder Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\iactgk-ja@p-xbyifoy.co.uk
Folder Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\n-zyj@ywrybi-.com
Folder Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\sitefinder@sitefinder.com
Folder Found : C:\Users\Radek\AppData\Roaming\OpenCandy
Folder Found : C:\Users\Radek\AppData\Roaming\SimilarSites
Folder Found : C:\Users\Radek\AppData\Roaming\webssearches

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\HulaToo
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\RegisteredApplicationsEx
Key Found : [x64] HKCU\Software\1ClickDownload
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\HulaToo
Key Found : [x64] HKCU\Software\InstallCore
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\RegisteredApplicationsEx
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{596EAA89-F3D2-4174-9BD9-F7D79C744CDA}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Found : HKLM\SOFTWARE\HulaToo
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{e81a9dc1}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webssearches uninstall
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SOFTWARE\webssearchesSoftware
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : [x64] HKLM\SOFTWARE\EnigmaSoftwareGroup
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17344

Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://istart.webssearches.com/web/?type=ds&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5&q={searchTerms}
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://istart.webssearches.com/web/?type=ds&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://istart.webssearches.com/web/?type=ds&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://istart.webssearches.com/web/?type=ds&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5&q={searchTerms}

-\\ Mozilla Firefox v32.0.3 (x86 cs)

[85ha3ezc.default] - Line Found : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
[85ha3ezc.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5");
[85ha3ezc.default] - Line Found : user_pref("extensions.KKgTE.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.n[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.KKgTE.url", "hxxp://sweetdiaryset.info/sync2/?q=hfZ9ofq7BNnMCyVUojw4rTkMg708BNmGWj8deShGheDUojw9rdnFrjwGqdrHqShIC7n0rjnEpdsFrjnGpjnEtNhVCT94tMVKhd97pdg8qHsGpdU7rdC7pjYGqHYHtNqHhd[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.RxTgcq4lW1O.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumo[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.XVSBwGaPBAt.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumo[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.admin", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.aflt", "babsst");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.autoRvrt", "false");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.bbDpng", "15");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.cntry", "CZ");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.dfltLng", "cs");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.excTlbr", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.ffxUnstlRst", true);
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.hdrMd5", "C0191BBFEF8503E9B68716A23E068B90");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.id", "ee7bec8200000000000016db303d683a");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.instlDay", "16225");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.instlRef", "sst");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.lastB", "hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5268");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.lastVrsnTs", "1.8.28.721:06:07");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.newTab", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.prdct", "buenosearch");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.prtnrId", "buenosearch");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.rvrt", "false");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.sg", "tzb");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.smplGrp", "none");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5268");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.tlbrId", "base");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5268");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.721:06:07");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
[85ha3ezc.default] - Line Found : user_pref("extensions.crossrider.bic", "146684624e7a1c7629ac6971b76bed13");
[85ha3ezc.default] - Line Found : user_pref("extensions.quick_start.enable_search1", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.tbhVhgjwWNE4.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sum[...]

-\\ Google Chrome v35.0.1916.114

Found [Search Provider] : hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5268

*************************

AdwCleaner[R0].txt - [20470 octets] - [17/10/2014 19:08:00]
AdwCleaner[R1].txt - [20293 octets] - [17/10/2014 19:14:50]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [20354 octets] ##########











Děkuji za rady. :?:
Naposledy upravil(a) Radek9999 dne 17 říj 2014 18:21, celkem upraveno 1 x.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém se zpomaleným PC. (Kontrola logu)

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Odinstalujte McAfee Security Scan

:arrow: Aplikujte Clean v AdwCleaneru a log sem dejte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Radek9999
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 říj 2014 17:45

Re: Problém se zpomaleným PC. (Kontrola logu)

#3 Příspěvek od Radek9999 »

Radeji ještě jednou: Tady je ten log z adwcleaneru.

# AdwCleaner v4.000 - Report created 17/10/2014 at 19:14:50
# Updated 12/10/2014 by Xplode
# Database : 2014-10-17.9
# Operating System : Windows 8.1 Service Pack 1 (64 bits)
# Username : Radek - RADEK
# Running from : C:\Programy\adwcleaner_4.000.exe
# Option : Scan

***** [ Services ] *****

Service Found : IePluginServices
Service Found : Update HulaToo
Service Found : Util HulaToo
Service Found : {2635ac50-5488-40bf-9bfd-accb158f8f3f}w64

***** [ Files / Folders ] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml
File Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\{5ebdca98-43b3-45bb-87e0-716029fb42ab}.xpi
File Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\invalidprefs.js
File Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\searchplugins\buenosearch.xml
File Found : C:\WINDOWS\System32\\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}w64.sys
File Found : C:\WINDOWS\SysWOW64\hfpapi.dll
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\GS-Enabler
Folder Found : C:\Program Files (x86)\HulaToo
Folder Found : C:\Program Files (x86)\save net
Folder Found : C:\Program Files (x86)\SimilarSites
Folder Found : C:\Program Files (x86)\SupTab
Folder Found : C:\Program Files (x86)\sw-booster
Folder Found : C:\Program Files (x86)\YoutubeAdblocker
Folder Found : C:\Program Files\Enigma Software Group
Folder Found : C:\ProgramData\IePluginServices
Folder Found : C:\ProgramData\save net
Folder Found : C:\ProgramData\SoftWarehouse
Folder Found : C:\ProgramData\WindowsMangerProtect
Folder Found : C:\ProgramData\YoutubeAdblocker
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Administrator\AppData\Local\torch
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\ASPNET\AppData\Local\torch
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\Guest\AppData\Local\torch
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Found : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Found : C:\Users\Radek\AppData\Local\globalUpdate
Folder Found : C:\Users\Radek\AppData\Local\PackageAware
Folder Found : C:\Users\Radek\AppData\Local\torch
Folder Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\faststartff@gmail.com
Folder Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\iactgk-ja@p-xbyifoy.co.uk
Folder Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\n-zyj@ywrybi-.com
Folder Found : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\sitefinder@sitefinder.com
Folder Found : C:\Users\Radek\AppData\Roaming\OpenCandy
Folder Found : C:\Users\Radek\AppData\Roaming\SimilarSites
Folder Found : C:\Users\Radek\AppData\Roaming\webssearches

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Data Found : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command [(Default)] - C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL
Key Found : HKCU\Software\1ClickDownload
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKCU\Software\AppDataLow\Software\Crossrider
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\HulaToo
Key Found : HKCU\Software\InstallCore
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKCU\Software\Optimizer Pro
Key Found : HKCU\Software\RegisteredApplicationsEx
Key Found : [x64] HKCU\Software\1ClickDownload
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\HulaToo
Key Found : [x64] HKCU\Software\InstallCore
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKCU\Software\Optimizer Pro
Key Found : [x64] HKCU\Software\RegisteredApplicationsEx
Key Found : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Found : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Found : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Found : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{596EAA89-F3D2-4174-9BD9-F7D79C744CDA}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Found : HKLM\SOFTWARE\HulaToo
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{e81a9dc1}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webssearches uninstall
Key Found : HKLM\SOFTWARE\SupDp
Key Found : HKLM\SOFTWARE\SupTab
Key Found : HKLM\SOFTWARE\supWindowsMangerProtect
Key Found : HKLM\SOFTWARE\supWPM
Key Found : HKLM\SOFTWARE\webssearchesSoftware
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : [x64] HKLM\SOFTWARE\EnigmaSoftwareGroup
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17344

Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://istart.webssearches.com/web/?type=ds&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5&q={searchTerms}
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Setting Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://istart.webssearches.com/web/?type=ds&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] - hxxp://istart.webssearches.com/web/?type=ds&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5&q={searchTerms}
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5
Setting Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://istart.webssearches.com/web/?type=ds&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5&q={searchTerms}

-\\ Mozilla Firefox v32.0.3 (x86 cs)

[85ha3ezc.default] - Line Found : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
[85ha3ezc.default] - Line Found : user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5");
[85ha3ezc.default] - Line Found : user_pref("extensions.KKgTE.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.n[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.KKgTE.url", "hxxp://sweetdiaryset.info/sync2/?q=hfZ9ofq7BNnMCyVUojw4rTkMg708BNmGWj8deShGheDUojw9rdnFrjwGqdrHqShIC7n0rjnEpdsFrjnGpjnEtNhVCT94tMVKhd97pdg8qHsGpdU7rdC7pjYGqHYHtNqHhd[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.RxTgcq4lW1O.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumo[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.XVSBwGaPBAt.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumo[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.admin", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.aflt", "babsst");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.autoRvrt", "false");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.bbDpng", "15");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.cntry", "CZ");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.dfltLng", "cs");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.excTlbr", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.ffxUnstlRst", true);
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.hdrMd5", "C0191BBFEF8503E9B68716A23E068B90");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.id", "ee7bec8200000000000016db303d683a");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.instlDay", "16225");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.instlRef", "sst");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.lastB", "hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5268");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.lastVrsnTs", "1.8.28.721:06:07");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.newTab", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.prdct", "buenosearch");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.prtnrId", "buenosearch");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.rvrt", "false");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.sg", "tzb");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.smplGrp", "none");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5268");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.tlbrId", "base");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5268");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.721:06:07");
[85ha3ezc.default] - Line Found : user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
[85ha3ezc.default] - Line Found : user_pref("extensions.crossrider.bic", "146684624e7a1c7629ac6971b76bed13");
[85ha3ezc.default] - Line Found : user_pref("extensions.quick_start.enable_search1", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[85ha3ezc.default] - Line Found : user_pref("extensions.tbhVhgjwWNE4.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sum[...]

-\\ Google Chrome v35.0.1916.114

Found [Search Provider] : hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5268

*************************

AdwCleaner[R0].txt - [20470 octets] - [17/10/2014 19:08:00]
AdwCleaner[R1].txt - [20293 octets] - [17/10/2014 19:14:50]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [20354 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém se zpomaleným PC. (Kontrola logu)

#4 Příspěvek od vyosek »

:arrow: Spustte znovu AdwCleaner
  • Pokud pouzivate Win Vista ci W7, kliknete na AdwCleaner pravym a dejte Run As Administrator ci Spustit jako spravce
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Radek9999
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 říj 2014 17:45

Re: Problém se zpomaleným PC. (Kontrola logu)

#5 Příspěvek od Radek9999 »

Po cleanu a následném restartu vyskočil tento soubor:

# AdwCleaner v4.000 - Report created 17/10/2014 at 19:35:58
# DB v2014-10-17.9
# Updated 12/10/2014 by Xplode
# Operating System : Windows 8.1 Service Pack 1 (64 bits)
# Username : Radek - RADEK
# Running from : C:\Programy\adwcleaner_4.000.exe
# Option : Clean

***** [ Services ] *****

Service Deleted : IePluginServices
[#] Service Deleted : Update HulaToo
[#] Service Deleted : Util HulaToo
Service Deleted : {2635ac50-5488-40bf-9bfd-accb158f8f3f}w64

***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Users\Radek\AppData\Local\globalUpdate
Folder Deleted : C:\Program Files (x86)\GS-Enabler
Folder Deleted : C:\Program Files (x86)\HulaToo
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\Users\Radek\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\Radek\AppData\Local\PackageAware
Folder Deleted : C:\Program Files (x86)\SimilarSites
Folder Deleted : C:\Users\Radek\AppData\Roaming\SimilarSites
Folder Deleted : C:\ProgramData\SoftWarehouse
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Program Files (x86)\sw-booster
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\ASPNET\AppData\Local\torch
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\Radek\AppData\Local\torch
Folder Deleted : C:\Users\Radek\AppData\Roaming\webssearches
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\Program Files\Enigma Software Group
Folder Deleted : C:\ProgramData\save net
Folder Deleted : C:\Program Files (x86)\save net
Folder Deleted : C:\ProgramData\YoutubeAdblocker
Folder Deleted : C:\Program Files (x86)\YoutubeAdblocker
Folder Deleted : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\faststartff@gmail.com
Folder Deleted : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\sitefinder@sitefinder.com
Folder Deleted : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\iactgk-ja@p-xbyifoy.co.uk
Folder Deleted : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\n-zyj@ywrybi-.com
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Deleted : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Deleted : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
File Deleted : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\{5ebdca98-43b3-45bb-87e0-716029fb42ab}.xpi
File Deleted : C:\WINDOWS\SysWOW64\hfpapi.dll
File Deleted : C:\WINDOWS\System32\\drivers\{2635ac50-5488-40bf-9bfd-accb158f8f3f}w64.sys
File Deleted : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\invalidprefs.js
File Deleted : C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\searchplugins\buenosearch.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\Public\Desktop\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Public\Desktop\Opera.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
Shortcut Disinfected : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Radek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Shortcut Disinfected : C:\Users\Radek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Shortcut Disinfected : C:\Users\Radek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Shortcut Disinfected : C:\Users\Radek\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk

***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{e81a9dc1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{596EAA89-F3D2-4174-9BD9-F7D79C744CDA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AB65CAF0-FC3B-40F8-8B88-6D096A48F659}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{32C53681-8E69-4659-8320-7422685BD486}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\HulaToo
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\HulaToo
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKLM\SOFTWARE\webssearchesSoftware
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webssearches uninstall
Key Deleted : [x64] HKLM\SOFTWARE\EnigmaSoftwareGroup
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~1.DLL
Data Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17344

Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Mozilla Firefox v32.0.3 (x86 cs)

[85ha3ezc.default] - Line Deleted : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
[85ha3ezc.default] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hp&ts=1405025363&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63NKRJ5NKRJ5");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.KKgTE.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.n[...]
[85ha3ezc.default] - Line Deleted : user_pref("extensions.KKgTE.url", "hxxp://sweetdiaryset.info/sync2/?q=hfZ9ofq7BNnMCyVUojw4rTkMg708BNmGWj8deShGheDUojw9rdnFrjwGqdrHqShIC7n0rjnEpdsFrjnGpjnEtNhVCT94tMVKhd97pdg8qHsGpdU7rdC7pjYGqHYHtNqHhd[...]
[85ha3ezc.default] - Line Deleted : user_pref("extensions.RxTgcq4lW1O.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumo[...]
[85ha3ezc.default] - Line Deleted : user_pref("extensions.XVSBwGaPBAt.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumo[...]
[85ha3ezc.default] - Line Deleted : user_pref("extensions.a5a6bf058b9784b84a2ec6f5462cfccb210120365d3c04ec986245fac2592d0dfcom51390.51390.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.admin", false);
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.aflt", "babsst");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.autoRvrt", "false");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.bbDpng", "15");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.cntry", "CZ");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.dfltLng", "cs");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.excTlbr", false);
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.ffxUnstlRst", true);
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.hdrMd5", "C0191BBFEF8503E9B68716A23E068B90");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.id", "ee7bec8200000000000016db303d683a");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.instlDay", "16225");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.instlRef", "sst");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.lastB", "hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrI ... 3&tsp=5268");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.lastVrsnTs", "1.8.28.721:06:07");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.newTab", false);
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.prdct", "buenosearch");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.prtnrId", "buenosearch");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.rvrt", "false");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.sg", "tzb");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.smplGrp", "none");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5268");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.tlbrId", "base");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&ba ... 3&tsp=5268");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.721:06:07");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.crossrider.bic", "146684624e7a1c7629ac6971b76bed13");
[85ha3ezc.default] - Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
[85ha3ezc.default] - Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[85ha3ezc.default] - Line Deleted : user_pref("extensions.tbhVhgjwWNE4.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sum[...]

-\\ Google Chrome v35.0.1916.114


*************************

AdwCleaner[R0].txt - [20470 octets] - [17/10/2014 19:08:00]
AdwCleaner[R1].txt - [20531 octets] - [17/10/2014 19:14:50]
AdwCleaner[R2].txt - [20592 octets] - [17/10/2014 19:31:03]
AdwCleaner[S0].txt - [19762 octets] - [17/10/2014 19:35:58]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19823 octets] ##########

Radek9999
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 říj 2014 17:45

Re: Problém se zpomaleným PC. (Kontrola logu)

#6 Příspěvek od Radek9999 »

webssearches už zmizl. Ale pořád mě otravujou nějake reklamy na webovem prohlížeči mozilla. Nebýt adblockeru, tak přes ty reklamy ani nevidim na monitor. Ovšem ani adblocker neřeší všechno... Počítač se mi zdá stále zpomalený. Prosím poraďte ještě jak postupovat dál...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém se zpomaleným PC. (Kontrola logu)

#7 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Radek9999
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 říj 2014 17:45

Re: Problém se zpomaleným PC. (Kontrola logu)

#8 Příspěvek od Radek9999 »

omlouvám se za zpožění, ale musel jsem už včera vypnout počítač. Zoek mi vyplivl tohle:


Zoek.exe v5.0.0.0 Updated 20-September-2014
Tool run by Radek on so 18. 10. 2014 at 13:55:06,24.
Microsoft Windows 8.1 6.3.9600 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Radek\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2014-10-17-190237.log 1207 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2255875871-1199464176-1346690243-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\prefs.js:

Added to C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\prefs.js:

ProfilePath: C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_201418.10._1419_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~3\bbmdejibkdgofkfmhjfdfmgdkfanlljf deleted
C:\PROGRA~3\BlockThEAds deleted
C:\PROGRA~3\7b7297016202a97 deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~2\COMMON~1\Config deleted
C:\Users\Radek\AppData\Roaming\CamStudio.Producer.Data.ini deleted
C:\Users\Radek\AppData\Roaming\CamStudio.Producer.ini deleted
C:\Users\Radek\AppData\Roaming\Thinstall deleted
C:\Users\Radek\DSETUP.dll deleted
C:\Users\Radek\dsetup32.dll deleted
C:\PROGRA~3\boost_interprocess deleted
C:\PROGRA~3\InstallMate deleted
C:\Users\Radek\AppData\Local\Thinstall deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\WINDOWS\SysNative\config\systemprofile\Searches deleted
C:\Users\Radek\DXSETUP.exe deleted
C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\extensions\5a6bf058-b978-4b84-a2ec-6f5462cfccb2@10120365-d3c0-4ec9-8624-5fac2592d0df.com deleted
C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\extensions\wle_0pl5a@ieolq-uiqg.com deleted
C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\extensions\yuerw@taqgsgsk.co.uk deleted
C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\extensions\{db615d8a-b766-4397-9ef1-0eeaf684d8da} deleted
"C:\windows\Installer\35f04.msi" deleted
"C:\PROGRA~3\mahgpdbijfnhmbgjgflhajngkkdecblp\mahgpdbijfnhmbgjgflhajngkkdecblp.crx" deleted
"C:\PROGRA~3\mahgpdbijfnhmbgjgflhajngkkdecblp\update.xml" deleted
"C:\PROGRA~3\mahgpdbijfnhmbgjgflhajngkkdecblp" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [18. 08. 2014 23:20]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default
63F8C13F269B10BC9363B007DAAACAE6 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll - Shockwave Flash


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[18. 08. 2014 23:19]

Angry Birds - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Angry Birds - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
Angry Birds - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Angry Birds - ASPNET\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - ASPNET\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - ASPNET\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Angry Birds - ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
Angry Birds - ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Angry Birds - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Angry Birds - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
Angry Birds - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Angry Birds - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Angry Birds - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
Angry Birds - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Angry Birds - Radek\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - Radek\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - Radek\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc
Angry Birds - Radek\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
YoutubeAdblocker - Radek\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd
save net - Radek\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc

==== Chromium Startpages ======================

C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://istart.webssearches.com/?type=hp ... NKRJ5NKRJ5",
"startup_urls": [ "http://istart.webssearches.com/?type=hp ... NKRJ5NKRJ5" ],


==== Chromium Fix ======================

C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\ASPNET\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\Radek\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\Radek\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hnidfighlohpdipkdhflalamalahpchd deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\ASPNET\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\ASPNET\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Radek\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Radek\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully
C:\Users\ASPNET\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully
C:\Users\ASPNET\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully
C:\Users\Radek\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully
C:\Users\Radek\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jhejagijiajlgolknllmipmheiemgcbc deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{56F4771B-3762-4650-8E5B-E1AA508098B8} Bing Url="http://www.bing.com/search?q={searchTer ... &pc=MAARJS"

==== Reset Google Chrome ======================

C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\203E62EEA6789D84098513925E9B9999 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\49b5a31e-d51b-4e42-9553-cdcd01222d8d deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{3582246E-8830-4FE5-AD0E-C012EE610698} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{EE26E302-876A-48D9-9058-3129E5B99999} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\203E62EEA6789D84098513925E9B9999 deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Radek\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Radek\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=422 folders=123 14839549 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Radek\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Radek\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on so 18. 10. 2014 at 14:29:40,18 ======================

:)

Radek9999
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 říj 2014 17:45

Re: Problém se zpomaleným PC. (Kontrola logu)

#9 Příspěvek od Radek9999 »

ještě tu pro jistotu jednou hodím ten log ze zoeku. Nejsem si jitý zdali jsem použil v předchozím případě ty scripty. Počítač už naštěstí vykazuje známky velkého zlepšení. pro jistotu ale ještě jednou ten log na kontrolu hodim. Teď mi to vyhodilo tohle:


Zoek.exe v5.0.0.0 Updated 17-10-2014
Tool run by Radek on so 18. 10. 2014 at 17:52:37,51.
Microsoft Windows 8.1 6.3.9600 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Radek\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2014-10-17-190237.log 1207 bytes
C:\zoek-results2014-10-18-122940.log 18955 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\prefs.js:

Added to C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default

user.js not found
---- Lines finder removed from prefs.js ----
user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"private
---- FireFox user.js and prefs.js backups ----

prefs_201418.10._1815_.backup

==== Deleting Files \ Folders ======================

C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [18. 08. 2014 23:20]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default
- avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default
63F8C13F269B10BC9363B007DAAACAE6 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll - Shockwave Flash


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[18. 08. 2014 23:19]


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{56F4771B-3762-4650-8E5B-E1AA508098B8} Bing Url="http://www.bing.com/search?q={searchTer ... &pc=MAARJS"

==== Reset Google Chrome ======================

Nothing found to reset

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Radek\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Radek\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=426 folders=125 14849625 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Radek\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Radek\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on so 18. 10. 2014 at 18:23:45,86 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém se zpomaleným PC. (Kontrola logu)

#10 Příspěvek od vyosek »

Poprosim o FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100 a docistime zbytecky
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Radek9999
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 říj 2014 17:45

Re: Problém se zpomaleným PC. (Kontrola logu)

#11 Příspěvek od Radek9999 »

log z FRST:


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-10-2014 01
Ran by Radek (administrator) on RADEK on 19-10-2014 00:49:50
Running from C:\Users\Radek\Desktop
Loaded Profile: Radek (Available profiles: Radek)
Platform: Windows 8.1 Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.5\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Akamai Technologies, Inc.) C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13267016 2013-01-30] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1276488 2013-01-18] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM-x32\...\Run: [LManager] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-18] (AVAST Software)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707472 2013-12-13] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-01-28] ( (Qualcomm Atheros Commnucations))
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\Run: [Akamai NetSession Interface] => C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\Run: [RGSC] => C:\Program Files\Rockstar Games Social Club\RGSCLauncher.exe [305064 2008-11-14] (Take-Two Interactive Software, Inc.)
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\MountPoints2: {52ee2096-b414-11e3-be93-a4db303d954e} - "E:\JetFlash220.exe"
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [166568 2014-07-02] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [146480 2014-07-02] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {56F4771B-3762-4650-8E5B-E1AA508098B8} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - {56F4771B-3762-4650-8E5B-E1AA508098B8} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {56F4771B-3762-4650-8E5B-E1AA508098B8} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
BHO: BlockThEAds -> {63145F74-26EA-0CD6-A156-25F00B16939F} -> C:\ProgramData\BlockThEAds\MybqgOcx8.x64.dll No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchUrl: http://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Adblock Plus - C:\Users\Radek\AppData\Roaming\Mozilla\Firefox\Profiles\85ha3ezc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-27]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-06]

Chrome:
=======
CHR Profile: C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Wallet) - C:\Users\Radek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-25]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-18]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227456 2013-01-28] (Qualcomm Atheros Commnucations)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-18] (AVAST Software)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-20] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-16] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-16] (Acer Incorporated)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2013-10-09] (Dritek System INC.)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-18] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-18] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-18] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-18] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-18] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-18] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-18] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-18] ()
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-28] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-08-14] (Disc Soft Ltd)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2013-10-09] (Dritek System Inc.)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-19 00:49 - 2014-10-19 00:51 - 00017420 _____ () C:\Users\Radek\Desktop\FRST.txt
2014-10-19 00:48 - 2014-10-19 00:49 - 00000000 ____D () C:\FRST
2014-10-19 00:43 - 2014-10-19 00:43 - 02112000 _____ (Farbar) C:\Users\Radek\Desktop\FRST64.exe
2014-10-19 00:42 - 2014-10-19 00:42 - 02112000 _____ (Farbar) C:\Users\Radek\Downloads\FRST64.exe
2014-10-18 18:20 - 2014-10-18 17:52 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-10-18 17:53 - 2014-10-18 14:29 - 00018955 _____ () C:\zoek-results2014-10-18-122940.log
2014-10-18 15:28 - 2014-10-18 15:28 - 00000788 _____ () C:\WINDOWS\setupact.log
2014-10-18 15:28 - 2014-10-18 15:28 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-10-18 13:58 - 2014-10-17 21:02 - 00001207 _____ () C:\zoek-results2014-10-17-190237.log
2014-10-18 13:56 - 2014-10-18 14:18 - 00032643 _____ () C:\WINDOWS\WindowsUpdate.log
2014-10-17 21:01 - 2014-10-18 18:23 - 00007195 _____ () C:\zoek-results.log
2014-10-17 20:59 - 2014-10-18 18:16 - 00000000 ____D () C:\zoek_backup
2014-10-17 20:58 - 2014-10-17 20:58 - 01290752 _____ () C:\Users\Radek\Desktop\zoek.exe
2014-10-17 19:07 - 2014-10-17 19:36 - 00000000 ____D () C:\AdwCleaner
2014-10-17 18:36 - 2014-10-18 18:21 - 00017688 _____ () C:\WINDOWS\PFRO.log
2014-10-17 18:34 - 2014-10-17 18:34 - 00326706 _____ () C:\Users\Radek\Desktop\cc_20141017_183403.reg
2014-10-17 18:31 - 2014-10-17 19:07 - 00000203 _____ () C:\Users\Radek\Desktop\pzn.txt
2014-10-17 18:16 - 2014-10-17 19:05 - 00000000 ____D () C:\Program Files\trend micro
2014-10-17 18:16 - 2014-10-17 18:17 - 00000000 ____D () C:\rsit
2014-10-15 11:16 - 2014-10-15 11:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PyScripter-x64
2014-10-15 11:16 - 2014-10-15 11:19 - 00000000 ____D () C:\Program Files\PyScripter
2014-10-15 10:50 - 2014-10-10 00:16 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-10-15 10:50 - 2014-10-09 00:09 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2014-10-15 10:50 - 2014-09-19 03:24 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-10-15 10:50 - 2014-09-13 08:02 - 02779648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-10-15 10:50 - 2014-09-13 07:30 - 03117568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-10-15 10:50 - 2014-09-04 02:10 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2014-10-15 10:50 - 2014-09-04 01:57 - 00921600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-10-15 10:50 - 2014-09-04 01:49 - 00626688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2014-10-15 10:50 - 2014-08-29 03:58 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2014-10-15 10:50 - 2014-08-29 01:56 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-10-15 10:50 - 2014-08-29 01:47 - 02321920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-10-15 10:50 - 2014-08-16 06:08 - 21195616 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-10-15 10:50 - 2014-08-16 05:16 - 18722600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-10-15 10:50 - 2014-08-16 02:17 - 08757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2014-10-15 10:50 - 2014-08-16 02:13 - 06649344 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-10-15 10:50 - 2014-08-16 02:13 - 05902848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2014-10-15 10:50 - 2014-08-16 02:08 - 05777408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-10-15 10:49 - 2014-08-16 06:08 - 01507648 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2014-10-15 10:49 - 2014-08-16 06:01 - 01710184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2014-10-15 10:49 - 2014-08-16 05:58 - 01112512 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-10-15 10:49 - 2014-08-16 05:57 - 02498880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-10-15 10:49 - 2014-08-16 05:57 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-10-15 10:49 - 2014-08-16 05:16 - 01205976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2014-10-15 10:49 - 2014-08-16 05:03 - 01467384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2014-10-15 10:49 - 2014-08-16 03:31 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-10-15 10:49 - 2014-08-16 03:04 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
2014-10-15 10:49 - 2014-08-16 02:58 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2014-10-15 10:49 - 2014-08-16 02:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
2014-10-15 10:49 - 2014-08-16 02:46 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityService.dll
2014-10-15 10:49 - 2014-08-16 02:45 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2014-10-15 10:49 - 2014-08-16 02:43 - 00321024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
2014-10-15 10:49 - 2014-08-16 02:43 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll
2014-10-15 10:49 - 2014-08-16 02:31 - 00914432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2014-10-15 10:49 - 2014-08-16 02:31 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcsvDevice.dll
2014-10-15 10:49 - 2014-08-16 02:29 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 10:49 - 2014-08-16 02:23 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2014-10-15 10:49 - 2014-08-16 02:22 - 00717824 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2014-10-15 10:49 - 2014-08-16 02:22 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveShell.dll
2014-10-15 10:49 - 2014-08-16 02:19 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-15 10:49 - 2014-08-16 02:18 - 04758528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2014-10-15 10:49 - 2014-08-16 02:14 - 00265216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SkyDriveShell.dll
2014-10-15 10:49 - 2014-08-16 02:13 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2014-10-15 10:49 - 2014-08-16 02:11 - 00920064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-10-15 10:49 - 2014-08-16 02:10 - 01120768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2014-10-15 10:49 - 2014-08-16 02:07 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-10-15 10:49 - 2014-08-01 01:22 - 00388729 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-10-15 10:48 - 2014-09-28 00:25 - 04183040 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-10-15 10:47 - 2014-09-26 00:50 - 13619200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-10-15 10:47 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-10-15 10:47 - 2014-09-26 00:31 - 02108416 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-10-15 10:47 - 2014-09-19 04:25 - 23631360 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-10-15 10:47 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-10-15 10:47 - 2014-09-19 03:41 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-10-15 10:47 - 2014-09-19 03:36 - 05829632 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-10-15 10:47 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-10-15 10:47 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-10-15 10:47 - 2014-09-19 02:42 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-10-15 10:47 - 2014-09-19 02:33 - 02309632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-10-15 10:47 - 2014-09-19 02:14 - 01447936 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-10-15 10:47 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-10-15 10:47 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-10-15 10:46 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-10-15 10:46 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-10-15 10:46 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-10-15 10:46 - 2014-09-19 03:40 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-10-15 10:46 - 2014-09-19 03:38 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-10-15 10:46 - 2014-09-19 03:25 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-10-15 10:46 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-10-15 10:46 - 2014-09-19 03:00 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-10-15 10:46 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-10-15 10:46 - 2014-09-19 02:58 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-10-15 10:46 - 2014-09-19 02:42 - 00710656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-10-15 10:46 - 2014-09-19 02:42 - 00363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-10-15 10:46 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-10-15 10:46 - 2014-09-19 02:20 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-10-15 10:46 - 2014-09-19 01:59 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-10-15 10:46 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-10-15 10:43 - 2014-09-13 08:29 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll
2014-10-15 10:43 - 2014-09-13 07:49 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll
2014-10-15 10:43 - 2014-09-08 05:15 - 00054752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-10-15 10:43 - 2014-09-08 03:46 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-10-15 10:43 - 2014-09-08 03:46 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2014-10-15 10:43 - 2014-09-08 02:08 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-10-15 10:43 - 2014-09-08 02:07 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-10-15 10:43 - 2014-09-08 02:05 - 03448320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-10-15 10:43 - 2014-09-08 02:04 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-10-15 10:43 - 2014-09-08 02:04 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-10-15 10:43 - 2014-09-08 02:03 - 01702400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-10-15 10:43 - 2014-09-08 02:03 - 00839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-10-15 10:43 - 2014-09-08 01:59 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2014-10-15 10:43 - 2014-09-08 01:59 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2014-10-15 10:43 - 2014-09-08 01:56 - 00672256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-10-15 10:43 - 2014-09-08 01:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-10-15 10:37 - 2014-09-04 02:12 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2014-10-15 10:37 - 2014-09-04 02:01 - 00514048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2014-10-15 10:35 - 2014-10-15 10:35 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2014-10-14 19:20 - 2014-10-14 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PyScripter
2014-10-14 19:20 - 2014-10-14 19:20 - 00000000 ____D () C:\Program Files (x86)\PyScripter
2014-10-13 14:24 - 2014-10-14 16:25 - 00000000 ____D () C:\Users\Radek\AppData\Roaming\PyScripter
2014-10-13 13:22 - 2014-10-13 13:22 - 00000000 _____ () C:\autoexec.bat
2014-10-13 13:21 - 2014-10-13 21:43 - 00000000 ____D () C:\WINDOWS\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-10-04 13:42 - 2014-10-04 13:46 - 00000000 ____D () C:\FIFA 15
2014-10-03 14:58 - 2014-10-03 15:00 - 00000000 ____D () C:\OVB
2014-10-01 12:05 - 2014-10-01 12:05 - 00000000 ____D () C:\Games
2014-09-24 23:22 - 2014-09-24 23:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-19 00:39 - 2014-03-02 18:45 - 00003958 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C14F67F8-2F2F-47EE-AE71-94F39D10661E}
2014-10-19 00:38 - 2014-01-21 03:22 - 00000968 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-19 00:37 - 2014-04-11 12:35 - 00000000 ___RD () C:\Users\Radek\OneDrive
2014-10-19 00:36 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-10-18 19:30 - 2014-01-21 03:22 - 00000972 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-18 19:04 - 2014-01-06 14:50 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-10-18 18:47 - 2014-01-06 16:52 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2255875871-1199464176-1346690243-1002
2014-10-18 18:31 - 2014-02-25 12:31 - 00002207 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-18 18:25 - 2014-01-21 03:22 - 00003944 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-18 18:25 - 2014-01-21 03:22 - 00003708 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-18 18:22 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-10-18 18:16 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy
2014-10-18 18:16 - 2012-07-26 10:12 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy
2014-10-18 17:26 - 2014-01-06 23:02 - 04105216 ___SH () C:\Users\Radek\Desktop\Thumbs.db
2014-10-18 15:29 - 2014-05-15 20:55 - 01771646 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-10-18 15:29 - 2013-11-14 14:24 - 00748236 _____ () C:\WINDOWS\system32\perfh005.dat
2014-10-18 15:29 - 2013-11-14 14:24 - 00156200 _____ () C:\WINDOWS\system32\perfc005.dat
2014-10-18 14:28 - 2014-02-25 19:22 - 00000000 ____D () C:\Users\Radek
2014-10-17 20:17 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-10-17 19:41 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-10-17 19:36 - 2014-02-25 19:48 - 00000945 _____ () C:\Users\Radek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-10-17 19:36 - 2014-02-25 12:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-10-17 19:36 - 2014-01-08 01:38 - 00000788 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-10-17 19:36 - 2014-01-08 01:38 - 00000776 _____ () C:\Users\Public\Desktop\Opera.lnk
2014-10-17 19:36 - 2014-01-07 05:14 - 00001081 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-10-17 18:26 - 2014-01-07 04:59 - 00000000 ____D () C:\Programy
2014-10-17 17:25 - 2014-01-14 00:04 - 00000000 ____D () C:\Hudba
2014-10-17 17:18 - 2014-03-04 17:45 - 00000000 ____D () C:\Users\Radek\AppData\Local\Deployment
2014-10-17 16:39 - 2014-01-25 21:23 - 00000000 ____D () C:\Users\Radek\AppData\Roaming\Audacity
2014-10-17 11:31 - 2014-08-25 22:55 - 00000000 ____D () C:\Users\Radek\AppData\Local\Adobe
2014-10-17 11:30 - 2014-01-06 14:50 - 00003802 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-10-17 11:23 - 2013-08-22 16:44 - 00533312 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-10-17 11:19 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-10-17 11:19 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-10-17 11:19 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2014-10-17 11:19 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\FileManager
2014-10-17 11:19 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Camera
2014-10-16 20:00 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-10-16 19:56 - 2014-01-08 14:37 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-16 19:46 - 2014-07-10 14:01 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-10-16 19:46 - 2014-01-08 14:37 - 103265616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-10-15 10:36 - 2014-01-07 17:29 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-14 00:02 - 2014-01-07 05:14 - 00001115 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-10-13 23:51 - 2014-03-14 02:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hry
2014-10-13 23:51 - 2014-01-06 22:30 - 00000000 ____D () C:\Hry
2014-10-13 22:32 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-10-12 16:54 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-10-12 01:42 - 2014-01-24 14:59 - 00000000 ____D () C:\Users\Radek\AppData\Roaming\vlc
2014-10-11 21:42 - 2014-01-06 14:31 - 00000000 ____D () C:\Users\Radek\AppData\Roaming\uTorrent
2014-10-09 21:54 - 2014-02-18 13:20 - 00000000 ____D () C:\Filmy
2014-10-08 13:56 - 2014-09-10 21:24 - 00011267 _____ () C:\Users\Radek\Desktop\rozvrh.xlsx
2014-10-07 23:27 - 2014-03-12 10:04 - 00000000 ____D () C:\WINDOWS\Minidump
2014-10-07 19:51 - 2014-01-09 20:02 - 00000000 ____D () C:\ProgramData\Origin
2014-10-04 12:37 - 2014-01-07 05:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-01 10:11 - 2014-02-25 19:50 - 00000000 ____D () C:\Users\Radek\Documents\Bluetooth Folder
2014-09-30 00:45 - 2014-03-01 12:32 - 00706016 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-09-30 00:45 - 2014-03-01 12:32 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-19 12:10 - 2014-01-10 14:26 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-18 18:47

==================== End Of Log ============================

:)
Přílohy
Addition.zip
(10.68 KiB) Staženo 52 x

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém se zpomaleným PC. (Kontrola logu)

#12 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    
    HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
    HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\Run: [Akamai NetSession Interface] => C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
    HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
    HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\Run: [RGSC] => C:\Program Files\Rockstar Games Social Club\RGSCLauncher.exe [305064 2008-11-14] (Take-Two Interactive Software, Inc.)
    HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\MountPoints2: {52ee2096-b414-11e3-be93-a4db303d954e} - "E:\JetFlash220.exe" 
    
    SearchScopes: HKLM - {56F4771B-3762-4650-8E5B-E1AA508098B8} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
    SearchScopes: HKLM-x32 - {56F4771B-3762-4650-8E5B-E1AA508098B8} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
    BHO: BlockThEAds -> {63145F74-26EA-0CD6-A156-25F00B16939F} -> C:\ProgramData\BlockThEAds\MybqgOcx8.x64.dll No File
    Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
    Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
    
    S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
    
    C:\Program Files\Enigma Software Group
    2014-10-19 00:49 - 2014-10-19 00:51 - 00017420 _____ () C:\Users\Radek\Desktop\FRST.txt
    2014-10-19 00:42 - 2014-10-19 00:42 - 02112000 _____ (Farbar) C:\Users\Radek\Downloads\FRST64.exe
    2014-10-18 18:20 - 2014-10-18 17:52 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
    2014-10-18 17:53 - 2014-10-18 14:29 - 00018955 _____ () C:\zoek-results2014-10-18-122940.log
    2014-10-18 15:28 - 2014-10-18 15:28 - 00000788 _____ () C:\WINDOWS\setupact.log
    2014-10-18 15:28 - 2014-10-18 15:28 - 00000000 _____ () C:\WINDOWS\setuperr.log
    2014-10-18 13:58 - 2014-10-17 21:02 - 00001207 _____ () C:\zoek-results2014-10-17-190237.log
    2014-10-17 21:01 - 2014-10-18 18:23 - 00007195 _____ () C:\zoek-results.log
    2014-10-17 20:59 - 2014-10-18 18:16 - 00000000 ____D () C:\zoek_backup
    2014-10-17 20:58 - 2014-10-17 20:58 - 01290752 _____ () C:\Users\Radek\Desktop\zoek.exe
    2014-10-17 19:07 - 2014-10-17 19:36 - 00000000 ____D () C:\AdwCleaner
    2014-10-17 18:16 - 2014-10-17 19:05 - 00000000 ____D () C:\Program Files\trend micro
    2014-10-17 18:16 - 2014-10-17 18:17 - 00000000 ____D () C:\rsit
    
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Radek9999
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 říj 2014 17:45

Re: Problém se zpomaleným PC. (Kontrola logu)

#13 Příspěvek od Radek9999 »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 18-10-2014 01
Ran by Radek at 2014-10-19 11:42:48 Run:1
Running from C:\Users\Radek\Desktop
Loaded Profile: Radek (Available profiles: Radek)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:

HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\Run: [Akamai NetSession Interface] => C:\Users\Radek\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\Run: [RGSC] => C:\Program Files\Rockstar Games Social Club\RGSCLauncher.exe [305064 2008-11-14] (Take-Two Interactive Software, Inc.)
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\...\MountPoints2: {52ee2096-b414-11e3-be93-a4db303d954e} - "E:\JetFlash220.exe"

SearchScopes: HKLM - {56F4771B-3762-4650-8E5B-E1AA508098B8} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - {56F4771B-3762-4650-8E5B-E1AA508098B8} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
BHO: BlockThEAds -> {63145F74-26EA-0CD6-A156-25F00B16939F} -> C:\ProgramData\BlockThEAds\MybqgOcx8.x64.dll No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File

S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]

C:\Program Files\Enigma Software Group
2014-10-19 00:49 - 2014-10-19 00:51 - 00017420 _____ () C:\Users\Radek\Desktop\FRST.txt
2014-10-19 00:42 - 2014-10-19 00:42 - 02112000 _____ (Farbar) C:\Users\Radek\Downloads\FRST64.exe
2014-10-18 18:20 - 2014-10-18 17:52 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-10-18 17:53 - 2014-10-18 14:29 - 00018955 _____ () C:\zoek-results2014-10-18-122940.log
2014-10-18 15:28 - 2014-10-18 15:28 - 00000788 _____ () C:\WINDOWS\setupact.log
2014-10-18 15:28 - 2014-10-18 15:28 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-10-18 13:58 - 2014-10-17 21:02 - 00001207 _____ () C:\zoek-results2014-10-17-190237.log
2014-10-17 21:01 - 2014-10-18 18:23 - 00007195 _____ () C:\zoek-results.log
2014-10-17 20:59 - 2014-10-18 18:16 - 00000000 ____D () C:\zoek_backup
2014-10-17 20:58 - 2014-10-17 20:58 - 01290752 _____ () C:\Users\Radek\Desktop\zoek.exe
2014-10-17 19:07 - 2014-10-17 19:36 - 00000000 ____D () C:\AdwCleaner
2014-10-17 18:16 - 2014-10-17 19:05 - 00000000 ____D () C:\Program Files\trend micro
2014-10-17 18:16 - 2014-10-17 18:17 - 00000000 ____D () C:\rsit

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface => value deleted successfully.
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\Software\Microsoft\Windows\CurrentVersion\Run\\RGSC => value deleted successfully.
"HKU\S-1-5-21-2255875871-1199464176-1346690243-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{52ee2096-b414-11e3-be93-a4db303d954e}" => Key deleted successfully.
"HKCR\CLSID\{52ee2096-b414-11e3-be93-a4db303d954e}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56F4771B-3762-4650-8E5B-E1AA508098B8}" => Key deleted successfully.
"HKCR\CLSID\{56F4771B-3762-4650-8E5B-E1AA508098B8}" => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{56F4771B-3762-4650-8E5B-E1AA508098B8}" => Key Deleted successfully.
"HKCR\Wow6432Node\CLSID\{56F4771B-3762-4650-8E5B-E1AA508098B8}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63145F74-26EA-0CD6-A156-25F00B16939F}" => Key deleted successfully.
"HKCR\CLSID\{63145F74-26EA-0CD6-A156-25F00B16939F}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
"HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found.
esgiguard => Service deleted successfully.
"C:\Program Files\Enigma Software Group" => File/Directory not found.
C:\Users\Radek\Desktop\FRST.txt => Moved successfully.
C:\Users\Radek\Downloads\FRST64.exe => Moved successfully.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results2014-10-18-122940.log => Moved successfully.
C:\WINDOWS\setupact.log => Moved successfully.
C:\WINDOWS\setuperr.log => Moved successfully.
C:\zoek-results2014-10-17-190237.log => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Radek\Desktop\zoek.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 635.8 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Problém se zpomaleným PC. (Kontrola logu)

#14 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.tym.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Radek9999
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 říj 2014 17:45

Re: Problém se zpomaleným PC. (Kontrola logu)

#15 Příspěvek od Radek9999 »

Děkuji moc,
velice mi to pomohlo. Noťas běží jako po másle.
:idea: :idea: :idea:

Zamčeno