
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu logu
Ahoj,
prosím o kontrolu logu. Jedna se o domácí notebook kolegyne, bylo tu nekolik trial verzi ruznych antiviru. Nainstaloval jsem zkusebni verzi ESETu, nasel a vymazal asi 40 polozek ruzne haveti. Jeste pro jistotu radeji prosim o kontrolu. Diky.
_
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-11-2014
Ran by Jirka (administrator) on JIRKA-HP on 06-11-2014 00:29:46
Running from C:\Users\Jirka\Desktop
Loaded Profile: Jirka (Available profiles: Jirka)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\stacsv64.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\AESTSr64.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\audiosrv.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-29] (IDT, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595336 2014-10-01] (ESET)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2010-01-12] (PDF Complete Inc)
HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-01-22] (Hewlett-Packard Company)
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\MountPoints2: {d8c5e845-3de4-11e1-88e6-806e6f6e6963} - D:\start.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [301568 2013-03-20] (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1383 ... 117JJEVBEX
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {F5D99D81-EA76-435F-B064-F6A5D55306DA} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
BHO: TrustMediaViewerV1alpha3921 -> {0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} -> C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ie\TrustMediaViewerV1alpha3921x64.dll No File
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Media Viewer -> {0a74a958-9ba5-4663-b474-688986924314} -> C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1587\ie\MediaViewerV1alpha1587.dll No File
BHO-x32: Media View -> {0d99d40d-fe35-4430-8f62-e8d2c347013a} -> C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ie\MediaViewV1alpha3668.dll No File
BHO-x32: Rich Media View -> {2d653a6f-c495-4903-b611-7cd6e55be5a0} -> C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ie\RichMediaViewV1release705.dll No File
BHO-x32: Media View -> {30f3ab79-0021-414d-96fb-b0e2fa302ed9} -> C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ie\MediaViewV1alpha1481.dll No File
BHO-x32: Rich Media View -> {7e64cb3d-3e32-4040-9e73-2db063cb28c8} -> C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ie\RichMediaViewV1release3516.dll No File
BHO-x32: Media Buzz -> {7fccb39f-cf1a-4c88-9afd-a29589db907e} -> C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ie\MediaBuzzV1mode8294.dll No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Media Watch -> {b6a54cf1-c7da-4b41-a4be-96668eac30f3} -> C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ie\MediaWatchV1home1.dll No File
BHO-x32: Webexp Enhanced -> {bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} -> C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ie\WebexpEnhancedV1alpha651.dll No File
BHO-x32: Video Player -> {c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} -> C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ie\VideoPlayerV3beta134.dll No File
BHO-x32: Media Player -> {d0a25cea-8071-43d8-b79a-5e38799346e3} -> C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha351\ie\MediaPlayerV1alpha351.dll No File
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 172.16.42.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [12x3q4@3244516.com] - C:\Program Files (x86)\Better-Surf\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha651.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta134.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha351.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha351\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha1587.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1587\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1481.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha3668.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home1.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaBuzzV1mode8294.net] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@RichMediaViewV1release705.net] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@TrustMediaViewerV1alpha3921.net] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@RichMediaViewV1release3516.net] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ff
FF Extension: No Name - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha351\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ff [Not Found]
Chrome:
=======
CHR DefaultSearchKeyword: Default -> seznam.cz
CHR DefaultSearchURL: Default -> http://search.seznam.cz/?q={searchTerms}
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Profile: C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-29]
CHR Extension: (Dokumenty Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-30]
CHR Extension: (Disk Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-29]
CHR Extension: (YouTube) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-29]
CHR Extension: (Vyhledávání Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-29]
CHR Extension: (Tabulky Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-29]
CHR Extension: (Peněženka Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-29]
CHR Extension: (Gmail) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-29]
CHR HKLM-x32\...\Chrome\Extension: [caphpmfackmpbchefdbohpjkjgekpcgo] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ch\VideoPlayerV3beta134.crx []
CHR HKLM-x32\...\Chrome\Extension: [emfiolpndjiobhaigieckjhchlocadbm] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ch\MediaViewV1alpha3668.crx []
CHR HKLM-x32\...\Chrome\Extension: [janpofkchcegjcafimgongjdcgmikipg] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ch\MediaWatchV1home1.crx []
CHR HKLM-x32\...\Chrome\Extension: [jggifkmlclgncoggjhcijfafadgcoamn] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ch\MediaViewV1alpha1481.crx []
CHR HKLM-x32\...\Chrome\Extension: [jjokaddkhgfbfcmlaehgcddgalighpln] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ch\RichMediaViewV1release3516.crx []
CHR HKLM-x32\...\Chrome\Extension: [kadgahhelapmhhjnmhnmnojfcnlhhoij] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ch\WebexpEnhancedV1alpha651.crx []
CHR HKLM-x32\...\Chrome\Extension: [lpemnobkfgfknkoaelaidcodbmaapemm] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ch\TrustMediaViewerV1alpha3921.crx []
CHR HKLM-x32\...\Chrome\Extension: [mchgekplgpbgbalnlnajnepeninajado] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ch\MediaBuzzV1mode8294.crx []
CHR HKLM-x32\...\Chrome\Extension: [ogoiliccpcefgmiafhjcoagnmkddagof] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ch\RichMediaViewV1release705.crx []
CHR HKLM-x32\...\Chrome\Extension: [ojofdhpfcjmjpgnolamolmihoompckbm] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1587\ch\MediaViewerV1alpha1587.crx []
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1349576 2014-10-01] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2010-10-06] (Macrovision Europe Ltd.) [File not signed]
R3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1028096 2010-10-06] (Macrovision Europe Ltd.) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4233088 2013-04-29] (Symantec Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2010-01-12] (PDF Complete Inc)
R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\STacSV64.exe [244736 2010-01-29] (IDT, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [241368 2014-10-10] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1803904 2010-04-27] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 00:29 - 2014-11-06 00:30 - 00018402 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-11-06 00:29 - 2014-11-06 00:29 - 00000000 ____D () C:\FRST
2014-11-06 00:27 - 2014-11-06 00:27 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-11-06 00:26 - 2014-11-06 00:26 - 02114560 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2014-11-06 00:22 - 2014-11-06 00:22 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-11-06 00:05 - 2014-11-06 00:05 - 00896048 _____ () C:\Users\Jirka\Downloads\Norton_Removal_Tool.exe
2014-11-06 00:05 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2014-11-06 00:05 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-11-06 00:05 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-11-06 00:05 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2014-11-06 00:05 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2014-11-06 00:05 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-11-06 00:05 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2014-11-06 00:05 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-11-06 00:05 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2014-11-06 00:05 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2014-11-06 00:05 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-11-06 00:05 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2014-11-06 00:05 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2014-11-06 00:05 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-11-06 00:05 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2014-11-06 00:05 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-11-06 00:05 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-11-06 00:05 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-11-06 00:03 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2014-11-06 00:03 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2014-11-06 00:03 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2014-11-06 00:03 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2014-11-06 00:03 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2014-11-06 00:03 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-11-05 23:59 - 2014-11-06 00:02 - 00000000 ____D () C:\windows\system32\MRT
2014-11-05 23:59 - 2014-10-03 10:02 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-11-05 22:14 - 2014-10-28 05:34 - 00275080 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-11-05 22:01 - 2014-11-05 22:01 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\ESET
2014-11-05 22:01 - 2014-11-05 22:01 - 00000000 ____D () C:\Users\Jirka\AppData\Local\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\ProgramData\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\Program Files\ESET
2014-11-05 21:48 - 2010-02-10 15:09 - 00000384 _____ () C:\windows\myClean.bat
2014-11-05 21:24 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-11-05 21:23 - 2014-11-05 21:25 - 00000000 ____D () C:\AdwCleaner
2014-11-05 21:22 - 2014-11-05 21:21 - 01375089 _____ () C:\Users\Jirka\Desktop\adwcleaner_3.311.exe
2014-11-05 21:21 - 2014-11-05 21:21 - 01375089 _____ () C:\Users\Jirka\Downloads\adwcleaner_3.311.exe
2014-11-05 21:09 - 2014-11-05 21:09 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Mozilla
2014-11-05 20:46 - 2014-11-05 20:46 - 00000687 _____ () C:\awh1297.tmp
2014-11-05 20:44 - 2014-11-05 20:44 - 01660616 _____ (ESET) C:\Users\Jirka\Downloads\eset_smart_security_live_installer_.exe
2014-11-02 19:30 - 2014-11-02 19:30 - 00000687 _____ () C:\awhC8F.tmp
2014-11-02 10:58 - 2014-11-02 10:58 - 00000687 _____ () C:\awh144A.tmp
2014-11-02 08:31 - 2014-11-02 08:31 - 00000687 _____ () C:\awh190C.tmp
2014-11-01 16:19 - 2014-11-01 16:19 - 00000687 _____ () C:\awhD0B.tmp
2014-11-01 13:28 - 2014-11-01 13:28 - 00000687 _____ () C:\awh11CC.tmp
2014-10-31 18:22 - 2014-10-31 18:22 - 00000687 _____ () C:\awh1AA1.tmp
2014-10-30 17:52 - 2014-10-30 17:52 - 00000687 _____ () C:\awh203C.tmp
2014-10-29 15:28 - 2014-10-29 15:28 - 00000687 _____ () C:\awh1FBF.tmp
2014-10-29 13:10 - 2014-10-29 13:10 - 00000687 _____ () C:\awh3E95.tmp
2014-10-29 12:28 - 2014-10-29 12:28 - 00002259 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-29 12:28 - 2014-10-29 12:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-10-29 12:27 - 2014-11-06 00:19 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-29 12:27 - 2014-11-05 23:32 - 00000950 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-29 12:27 - 2014-10-29 12:27 - 00003946 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-29 12:27 - 2014-10-29 12:27 - 00003694 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-29 12:23 - 2014-10-29 12:23 - 00000000 __SHD () C:\Users\Jirka\AppData\Local\EmieUserList
2014-10-29 12:23 - 2014-10-29 12:23 - 00000000 __SHD () C:\Users\Jirka\AppData\Local\EmieSiteList
2014-10-29 06:45 - 2014-10-29 06:45 - 00000687 _____ () C:\awh1554.tmp
2014-10-28 22:27 - 2014-10-28 22:27 - 00000687 _____ () C:\awh1BF8.tmp
2014-10-28 20:00 - 2014-10-28 20:00 - 00000687 _____ () C:\awh8A7.tmp
2014-10-28 15:49 - 2014-10-28 15:49 - 00000687 _____ () C:\awhA5C.tmp
2014-10-28 14:38 - 2014-10-28 14:38 - 00000687 _____ () C:\awh943.tmp
2014-10-28 08:00 - 2014-10-28 08:00 - 00000687 _____ () C:\awh1095.tmp
2014-10-27 17:32 - 2014-10-27 17:32 - 00000687 _____ () C:\awh878.tmp
2014-10-27 15:55 - 2014-10-27 15:55 - 00000687 _____ () C:\awhBA3.tmp
2014-10-27 11:33 - 2014-10-27 11:33 - 00000687 _____ () C:\awh2471.tmp
2014-10-26 12:34 - 2014-10-26 12:34 - 00000687 _____ () C:\awh16AB.tmp
2014-10-26 07:18 - 2014-10-26 07:18 - 00000687 _____ () C:\awh160F.tmp
2014-10-25 10:11 - 2014-10-25 10:11 - 00000687 _____ () C:\awh1390.tmp
2014-10-25 07:29 - 2014-10-25 07:29 - 00000687 _____ () C:\awh1E2A.tmp
2014-10-24 14:43 - 2014-10-24 14:43 - 00000687 _____ () C:\awh1C94.tmp
2014-10-23 23:18 - 2014-10-23 23:18 - 00000687 _____ () C:\awh147F.tmp
2014-10-22 14:12 - 2014-10-22 14:12 - 00000687 _____ () C:\awhF6A.tmp
2014-10-21 22:04 - 2014-10-21 22:04 - 00000687 _____ () C:\awhCDB.tmp
2014-10-20 21:18 - 2014-10-20 21:18 - 00000687 _____ () C:\awh115F.tmp
2014-10-20 16:56 - 2014-10-20 16:56 - 00000687 _____ () C:\awh2200.tmp
2014-10-20 11:49 - 2014-10-20 11:49 - 00000687 _____ () C:\awh195C.tmp
2014-10-19 21:27 - 2014-10-19 21:27 - 00000687 _____ () C:\awhF3C.tmp
2014-10-19 15:48 - 2014-10-19 15:48 - 00000687 _____ () C:\awh1006.tmp
2014-10-19 09:48 - 2014-10-19 09:48 - 00000687 _____ () C:\awhF7A.tmp
2014-10-19 07:50 - 2014-10-19 07:50 - 00000687 _____ () C:\awh1370.tmp
2014-10-18 21:03 - 2014-10-18 21:03 - 00000687 _____ () C:\awh1F71.tmp
2014-10-18 17:03 - 2014-10-18 17:03 - 00000687 _____ () C:\awh8B6.tmp
2014-10-18 13:10 - 2014-10-18 13:10 - 00000687 _____ () C:\awh4A1.tmp
2014-10-18 10:20 - 2014-10-18 10:20 - 00000687 _____ () C:\awh6B4.tmp
2014-10-17 16:54 - 2014-10-17 16:54 - 00000687 _____ () C:\awh1074.tmp
2014-10-17 13:41 - 2014-10-17 13:41 - 00000687 _____ () C:\awh241.tmp
2014-10-16 21:38 - 2014-10-16 21:38 - 00000687 _____ () C:\awh914.tmp
2014-10-16 16:55 - 2014-10-16 16:55 - 00000687 _____ () C:\awh2E50.tmp
2014-10-16 06:18 - 2014-10-16 06:18 - 00000687 _____ () C:\awh43C3.tmp
2014-10-16 05:50 - 2014-10-16 05:50 - 00000687 _____ () C:\awh278C.tmp
2014-10-15 20:54 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-15 20:54 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-15 20:54 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-15 20:54 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-15 20:54 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-15 20:54 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-15 20:54 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-15 20:54 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-10-15 20:54 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-10-15 20:54 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-15 20:54 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-15 20:54 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-15 20:54 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-10-15 20:54 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-10-15 20:54 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-15 20:54 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-15 20:54 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-10-15 20:54 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-10-15 20:54 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-10-15 20:54 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-10-15 20:54 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-15 20:54 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-15 20:54 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-10-15 20:54 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-15 20:54 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-10-15 20:54 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-10-15 20:54 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 20:54 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-10-15 20:54 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-15 20:54 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-15 20:54 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-15 20:54 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-15 20:54 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-10-15 20:54 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-10-15 20:54 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-10-15 20:54 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-10-15 20:54 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-10-15 20:54 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-15 20:54 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-15 20:54 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-10-15 20:54 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 20:54 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-15 20:54 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-10-15 20:54 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-15 20:54 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-10-15 20:54 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-15 20:54 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-15 20:54 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-15 20:54 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-15 20:54 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-15 20:30 - 2014-08-19 04:11 - 00693176 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2014-10-15 20:30 - 2014-08-19 04:10 - 00616352 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2014-10-15 20:30 - 2014-08-19 04:08 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2014-10-15 20:30 - 2014-08-19 04:08 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2014-10-15 20:30 - 2014-08-19 04:08 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2014-10-15 20:30 - 2014-08-19 04:07 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2014-10-15 20:30 - 2014-08-19 04:07 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2014-10-15 20:30 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2014-10-15 20:30 - 2014-08-19 03:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2014-10-15 20:30 - 2014-08-19 03:06 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2014-10-15 20:30 - 2014-07-07 03:07 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2014-10-15 20:30 - 2014-07-07 03:07 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2014-10-15 20:30 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 05551032 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 04120576 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01574400 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01069056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00188416 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2014-10-15 20:30 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2014-10-15 20:30 - 2014-07-07 03:05 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2014-10-15 20:30 - 2014-07-07 03:05 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2014-10-15 20:30 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2014-10-15 20:30 - 2014-07-07 02:52 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2014-10-15 20:30 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2014-10-15 20:30 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2014-10-15 20:30 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2014-10-15 20:30 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2014-10-15 20:30 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2014-10-15 20:30 - 2014-06-28 01:21 - 00619056 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2014-10-15 20:30 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2014-10-15 20:30 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2014-10-15 20:25 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-15 20:25 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2014-10-15 20:20 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-10-15 20:20 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2014-10-15 20:20 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-10-15 20:15 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2014-10-15 20:15 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2014-10-15 20:15 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-15 20:15 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-10-15 20:15 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-10-15 20:15 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2014-10-15 20:15 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-10-15 20:15 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-10-15 20:15 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2014-10-15 20:15 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2014-10-15 20:14 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-15 20:14 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2014-10-15 20:04 - 2014-10-15 20:04 - 00000687 _____ () C:\awh8D04.tmp
2014-10-15 11:59 - 2014-10-15 11:59 - 00000687 _____ () C:\awh13ED.tmp
2014-10-15 08:03 - 2014-10-15 08:03 - 00000687 _____ () C:\awh195B.tmp
2014-10-14 16:52 - 2014-10-14 16:52 - 00000687 _____ () C:\awh118E.tmp
2014-10-14 12:21 - 2014-10-14 12:21 - 00000687 _____ () C:\awh369.tmp
2014-10-14 10:32 - 2014-10-14 10:32 - 00000687 _____ () C:\awh206B.tmp
2014-10-14 06:22 - 2014-10-14 06:22 - 00000687 _____ () C:\awh229C.tmp
2014-10-13 15:39 - 2014-10-13 15:39 - 00000687 _____ () C:\awh12B6.tmp
2014-10-12 10:59 - 2014-10-12 10:59 - 00000687 _____ () C:\awh1766.tmp
2014-10-12 07:04 - 2014-10-12 07:04 - 00000687 _____ () C:\awh740.tmp
2014-10-11 17:05 - 2014-10-11 17:05 - 00000687 _____ () C:\awh116F.tmp
2014-10-11 11:32 - 2014-10-11 11:32 - 00000687 _____ () C:\awh12B5.tmp
2014-10-10 22:30 - 2014-10-10 22:30 - 00000687 _____ () C:\awhC4F.tmp
2014-10-10 16:48 - 2014-10-10 16:48 - 00000687 _____ () C:\awhD0A.tmp
2014-10-10 08:59 - 2014-10-10 08:59 - 00243440 _____ (ESET) C:\windows\system32\Drivers\eamonm.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00241368 _____ (ESET) C:\windows\system32\Drivers\edevmon.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00222280 _____ (ESET) C:\windows\system32\Drivers\epfw.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00169280 _____ (ESET) C:\windows\system32\Drivers\ehdrv.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00063160 _____ (ESET) C:\windows\system32\Drivers\epfwwfp.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00044632 _____ (ESET) C:\windows\system32\Drivers\EpfwLWF.sys
2014-10-10 00:41 - 2014-10-10 00:41 - 00000687 _____ () C:\awh435.tmp
2014-10-09 22:08 - 2014-10-09 22:08 - 00000687 _____ () C:\awhA2D.tmp
2014-10-09 20:10 - 2014-10-09 20:10 - 00000687 _____ () C:\awhE80.tmp
2014-10-09 16:15 - 2014-10-09 16:15 - 00000687 _____ () C:\awhB85.tmp
2014-10-08 21:47 - 2014-10-08 21:47 - 00000687 _____ () C:\awh11BD.tmp
2014-10-08 18:08 - 2014-10-08 18:08 - 00000687 _____ () C:\awh1BE8.tmp
2014-10-08 15:12 - 2014-10-08 15:12 - 00000687 _____ () C:\awh4D0.tmp
2014-10-07 15:35 - 2014-10-07 15:35 - 00000687 _____ () C:\awh675.tmp
2014-10-07 00:31 - 2014-10-07 00:31 - 00000687 _____ () C:\awh9C1.tmp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 00:27 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 00:27 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 00:20 - 2011-02-25 10:48 - 00058016 _____ () C:\Users\Jirka\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-06 00:19 - 2014-01-29 16:43 - 00000270 __RSH () C:\ProgramData\ntuser.pol
2014-11-06 00:19 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-11-06 00:19 - 2009-07-14 05:51 - 00256218 _____ () C:\windows\setupact.log
2014-11-06 00:19 - 2009-07-14 05:45 - 00268800 _____ () C:\windows\system32\FNTCACHE.DAT
2014-11-06 00:18 - 2010-10-06 00:20 - 01111379 _____ () C:\windows\WindowsUpdate.log
2014-11-06 00:18 - 2010-09-09 22:57 - 00926304 _____ () C:\windows\PFRO.log
2014-11-06 00:17 - 2012-05-16 15:52 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Skype
2014-11-06 00:09 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-06 00:07 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-11-06 00:06 - 2011-03-03 14:32 - 00000000 ____D () C:\ProgramData\Norton
2014-11-06 00:06 - 2010-10-06 00:22 - 00008391 _____ () C:\windows\system32\RaCoInst.log
2014-11-05 23:35 - 2013-11-02 17:59 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Seznam.cz
2014-11-05 21:54 - 2010-09-09 22:51 - 00000000 ____D () C:\Program Files\Common Files\McAfee
2014-11-05 21:51 - 2011-02-25 10:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
2014-11-05 21:40 - 2010-09-09 21:56 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-11-05 21:33 - 2011-02-28 17:05 - 00000000 ____D () C:\Program Files\DivX
2014-11-05 21:33 - 2011-02-28 17:02 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-11-05 21:33 - 2011-02-28 16:58 - 00000000 ____D () C:\ProgramData\DivX
2014-11-05 21:25 - 2011-02-25 10:47 - 00000969 _____ () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-05 21:11 - 2010-09-09 22:52 - 00008727 _____ () C:\windows\system32\Config.MPF
2014-11-05 20:51 - 2010-09-09 22:18 - 00669576 _____ () C:\windows\system32\perfh005.dat
2014-11-05 20:51 - 2010-09-09 22:18 - 00141946 _____ () C:\windows\system32\perfc005.dat
2014-11-05 20:51 - 2009-07-14 06:13 - 01586138 _____ () C:\windows\system32\PerfStringBackup.INI
2014-11-03 01:53 - 2011-04-08 07:58 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\SoftGrid Client
2014-11-02 20:44 - 2013-04-12 13:02 - 00010590 _____ () C:\Users\Jirka\Desktop\debug.log
2014-10-29 12:28 - 2013-11-02 18:27 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-29 12:27 - 2011-02-28 16:45 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Deployment
2014-10-28 19:55 - 2009-07-14 06:08 - 00032568 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-10-27 11:31 - 2013-12-10 15:54 - 00000836 _____ () C:\extensions.ini
2014-10-19 20:25 - 2011-02-25 18:28 - 00000000 ____D () C:\windows\rescache
2014-10-16 05:47 - 2009-07-14 06:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2014-10-16 05:43 - 2014-05-06 10:41 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-10-16 05:43 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2014-10-16 05:43 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\Dism
2014-10-07 16:34 - 2011-02-28 16:46 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForJirka
2014-10-07 16:34 - 2011-02-28 16:46 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForJirka.job
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForJirka.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Jirka\Desktop" je 3029 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisorDock
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackup
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
prosím o kontrolu logu. Jedna se o domácí notebook kolegyne, bylo tu nekolik trial verzi ruznych antiviru. Nainstaloval jsem zkusebni verzi ESETu, nasel a vymazal asi 40 polozek ruzne haveti. Jeste pro jistotu radeji prosim o kontrolu. Diky.
_
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-11-2014
Ran by Jirka (administrator) on JIRKA-HP on 06-11-2014 00:29:46
Running from C:\Users\Jirka\Desktop
Loaded Profile: Jirka (Available profiles: Jirka)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\stacsv64.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\AESTSr64.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\audiosrv.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-29] (IDT, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595336 2014-10-01] (ESET)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2010-01-12] (PDF Complete Inc)
HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-01-22] (Hewlett-Packard Company)
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\MountPoints2: {d8c5e845-3de4-11e1-88e6-806e6f6e6963} - D:\start.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [301568 2013-03-20] (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.qone8.com/?type=hp&ts=1383 ... 117JJEVBEX
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {F5D99D81-EA76-435F-B064-F6A5D55306DA} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
BHO: TrustMediaViewerV1alpha3921 -> {0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} -> C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ie\TrustMediaViewerV1alpha3921x64.dll No File
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Media Viewer -> {0a74a958-9ba5-4663-b474-688986924314} -> C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1587\ie\MediaViewerV1alpha1587.dll No File
BHO-x32: Media View -> {0d99d40d-fe35-4430-8f62-e8d2c347013a} -> C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ie\MediaViewV1alpha3668.dll No File
BHO-x32: Rich Media View -> {2d653a6f-c495-4903-b611-7cd6e55be5a0} -> C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ie\RichMediaViewV1release705.dll No File
BHO-x32: Media View -> {30f3ab79-0021-414d-96fb-b0e2fa302ed9} -> C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ie\MediaViewV1alpha1481.dll No File
BHO-x32: Rich Media View -> {7e64cb3d-3e32-4040-9e73-2db063cb28c8} -> C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ie\RichMediaViewV1release3516.dll No File
BHO-x32: Media Buzz -> {7fccb39f-cf1a-4c88-9afd-a29589db907e} -> C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ie\MediaBuzzV1mode8294.dll No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Media Watch -> {b6a54cf1-c7da-4b41-a4be-96668eac30f3} -> C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ie\MediaWatchV1home1.dll No File
BHO-x32: Webexp Enhanced -> {bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} -> C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ie\WebexpEnhancedV1alpha651.dll No File
BHO-x32: Video Player -> {c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} -> C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ie\VideoPlayerV3beta134.dll No File
BHO-x32: Media Player -> {d0a25cea-8071-43d8-b79a-5e38799346e3} -> C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha351\ie\MediaPlayerV1alpha351.dll No File
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 172.16.42.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [12x3q4@3244516.com] - C:\Program Files (x86)\Better-Surf\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha651.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@VideoPlayerV3beta134.net] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaPlayerV1alpha351.net] - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha351\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewerV1alpha1587.net] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1587\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha1481.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaViewV1alpha3668.net] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home1.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@MediaBuzzV1mode8294.net] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@RichMediaViewV1release705.net] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@TrustMediaViewerV1alpha3921.net] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ff
FF HKLM-x32\...\Firefox\Extensions: [ext@RichMediaViewV1release3516.net] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ff
FF Extension: No Name - C:\Program Files (x86)\BetterSurf\BetterSurfPlus\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaPlayerV1\MediaPlayerV1alpha351\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ff [Not Found]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ff [Not Found]
Chrome:
=======
CHR DefaultSearchKeyword: Default -> seznam.cz
CHR DefaultSearchURL: Default -> http://search.seznam.cz/?q={searchTerms}
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Profile: C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-29]
CHR Extension: (Dokumenty Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-30]
CHR Extension: (Disk Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-29]
CHR Extension: (YouTube) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-29]
CHR Extension: (Vyhledávání Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-29]
CHR Extension: (Tabulky Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-29]
CHR Extension: (Peněženka Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-29]
CHR Extension: (Gmail) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-29]
CHR HKLM-x32\...\Chrome\Extension: [caphpmfackmpbchefdbohpjkjgekpcgo] - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ch\VideoPlayerV3beta134.crx []
CHR HKLM-x32\...\Chrome\Extension: [emfiolpndjiobhaigieckjhchlocadbm] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ch\MediaViewV1alpha3668.crx []
CHR HKLM-x32\...\Chrome\Extension: [janpofkchcegjcafimgongjdcgmikipg] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ch\MediaWatchV1home1.crx []
CHR HKLM-x32\...\Chrome\Extension: [jggifkmlclgncoggjhcijfafadgcoamn] - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ch\MediaViewV1alpha1481.crx []
CHR HKLM-x32\...\Chrome\Extension: [jjokaddkhgfbfcmlaehgcddgalighpln] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ch\RichMediaViewV1release3516.crx []
CHR HKLM-x32\...\Chrome\Extension: [kadgahhelapmhhjnmhnmnojfcnlhhoij] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ch\WebexpEnhancedV1alpha651.crx []
CHR HKLM-x32\...\Chrome\Extension: [lpemnobkfgfknkoaelaidcodbmaapemm] - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ch\TrustMediaViewerV1alpha3921.crx []
CHR HKLM-x32\...\Chrome\Extension: [mchgekplgpbgbalnlnajnepeninajado] - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ch\MediaBuzzV1mode8294.crx []
CHR HKLM-x32\...\Chrome\Extension: [ogoiliccpcefgmiafhjcoagnmkddagof] - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ch\RichMediaViewV1release705.crx []
CHR HKLM-x32\...\Chrome\Extension: [ojofdhpfcjmjpgnolamolmihoompckbm] - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1587\ch\MediaViewerV1alpha1587.crx []
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1349576 2014-10-01] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2010-10-06] (Macrovision Europe Ltd.) [File not signed]
R3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1028096 2010-10-06] (Macrovision Europe Ltd.) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4233088 2013-04-29] (Symantec Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2010-01-12] (PDF Complete Inc)
R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\STacSV64.exe [244736 2010-01-29] (IDT, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [241368 2014-10-10] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1803904 2010-04-27] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 00:29 - 2014-11-06 00:30 - 00018402 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-11-06 00:29 - 2014-11-06 00:29 - 00000000 ____D () C:\FRST
2014-11-06 00:27 - 2014-11-06 00:27 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-11-06 00:26 - 2014-11-06 00:26 - 02114560 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2014-11-06 00:22 - 2014-11-06 00:22 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-11-06 00:05 - 2014-11-06 00:05 - 00896048 _____ () C:\Users\Jirka\Downloads\Norton_Removal_Tool.exe
2014-11-06 00:05 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2014-11-06 00:05 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-11-06 00:05 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-11-06 00:05 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2014-11-06 00:05 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2014-11-06 00:05 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-11-06 00:05 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2014-11-06 00:05 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-11-06 00:05 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2014-11-06 00:05 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2014-11-06 00:05 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-11-06 00:05 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2014-11-06 00:05 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2014-11-06 00:05 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-11-06 00:05 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2014-11-06 00:05 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-11-06 00:05 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-11-06 00:05 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-11-06 00:03 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2014-11-06 00:03 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2014-11-06 00:03 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2014-11-06 00:03 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2014-11-06 00:03 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2014-11-06 00:03 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-11-05 23:59 - 2014-11-06 00:02 - 00000000 ____D () C:\windows\system32\MRT
2014-11-05 23:59 - 2014-10-03 10:02 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-11-05 22:14 - 2014-10-28 05:34 - 00275080 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-11-05 22:01 - 2014-11-05 22:01 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\ESET
2014-11-05 22:01 - 2014-11-05 22:01 - 00000000 ____D () C:\Users\Jirka\AppData\Local\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\ProgramData\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\Program Files\ESET
2014-11-05 21:48 - 2010-02-10 15:09 - 00000384 _____ () C:\windows\myClean.bat
2014-11-05 21:24 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-11-05 21:23 - 2014-11-05 21:25 - 00000000 ____D () C:\AdwCleaner
2014-11-05 21:22 - 2014-11-05 21:21 - 01375089 _____ () C:\Users\Jirka\Desktop\adwcleaner_3.311.exe
2014-11-05 21:21 - 2014-11-05 21:21 - 01375089 _____ () C:\Users\Jirka\Downloads\adwcleaner_3.311.exe
2014-11-05 21:09 - 2014-11-05 21:09 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Mozilla
2014-11-05 20:46 - 2014-11-05 20:46 - 00000687 _____ () C:\awh1297.tmp
2014-11-05 20:44 - 2014-11-05 20:44 - 01660616 _____ (ESET) C:\Users\Jirka\Downloads\eset_smart_security_live_installer_.exe
2014-11-02 19:30 - 2014-11-02 19:30 - 00000687 _____ () C:\awhC8F.tmp
2014-11-02 10:58 - 2014-11-02 10:58 - 00000687 _____ () C:\awh144A.tmp
2014-11-02 08:31 - 2014-11-02 08:31 - 00000687 _____ () C:\awh190C.tmp
2014-11-01 16:19 - 2014-11-01 16:19 - 00000687 _____ () C:\awhD0B.tmp
2014-11-01 13:28 - 2014-11-01 13:28 - 00000687 _____ () C:\awh11CC.tmp
2014-10-31 18:22 - 2014-10-31 18:22 - 00000687 _____ () C:\awh1AA1.tmp
2014-10-30 17:52 - 2014-10-30 17:52 - 00000687 _____ () C:\awh203C.tmp
2014-10-29 15:28 - 2014-10-29 15:28 - 00000687 _____ () C:\awh1FBF.tmp
2014-10-29 13:10 - 2014-10-29 13:10 - 00000687 _____ () C:\awh3E95.tmp
2014-10-29 12:28 - 2014-10-29 12:28 - 00002259 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-29 12:28 - 2014-10-29 12:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-10-29 12:27 - 2014-11-06 00:19 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-29 12:27 - 2014-11-05 23:32 - 00000950 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-29 12:27 - 2014-10-29 12:27 - 00003946 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-29 12:27 - 2014-10-29 12:27 - 00003694 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-29 12:23 - 2014-10-29 12:23 - 00000000 __SHD () C:\Users\Jirka\AppData\Local\EmieUserList
2014-10-29 12:23 - 2014-10-29 12:23 - 00000000 __SHD () C:\Users\Jirka\AppData\Local\EmieSiteList
2014-10-29 06:45 - 2014-10-29 06:45 - 00000687 _____ () C:\awh1554.tmp
2014-10-28 22:27 - 2014-10-28 22:27 - 00000687 _____ () C:\awh1BF8.tmp
2014-10-28 20:00 - 2014-10-28 20:00 - 00000687 _____ () C:\awh8A7.tmp
2014-10-28 15:49 - 2014-10-28 15:49 - 00000687 _____ () C:\awhA5C.tmp
2014-10-28 14:38 - 2014-10-28 14:38 - 00000687 _____ () C:\awh943.tmp
2014-10-28 08:00 - 2014-10-28 08:00 - 00000687 _____ () C:\awh1095.tmp
2014-10-27 17:32 - 2014-10-27 17:32 - 00000687 _____ () C:\awh878.tmp
2014-10-27 15:55 - 2014-10-27 15:55 - 00000687 _____ () C:\awhBA3.tmp
2014-10-27 11:33 - 2014-10-27 11:33 - 00000687 _____ () C:\awh2471.tmp
2014-10-26 12:34 - 2014-10-26 12:34 - 00000687 _____ () C:\awh16AB.tmp
2014-10-26 07:18 - 2014-10-26 07:18 - 00000687 _____ () C:\awh160F.tmp
2014-10-25 10:11 - 2014-10-25 10:11 - 00000687 _____ () C:\awh1390.tmp
2014-10-25 07:29 - 2014-10-25 07:29 - 00000687 _____ () C:\awh1E2A.tmp
2014-10-24 14:43 - 2014-10-24 14:43 - 00000687 _____ () C:\awh1C94.tmp
2014-10-23 23:18 - 2014-10-23 23:18 - 00000687 _____ () C:\awh147F.tmp
2014-10-22 14:12 - 2014-10-22 14:12 - 00000687 _____ () C:\awhF6A.tmp
2014-10-21 22:04 - 2014-10-21 22:04 - 00000687 _____ () C:\awhCDB.tmp
2014-10-20 21:18 - 2014-10-20 21:18 - 00000687 _____ () C:\awh115F.tmp
2014-10-20 16:56 - 2014-10-20 16:56 - 00000687 _____ () C:\awh2200.tmp
2014-10-20 11:49 - 2014-10-20 11:49 - 00000687 _____ () C:\awh195C.tmp
2014-10-19 21:27 - 2014-10-19 21:27 - 00000687 _____ () C:\awhF3C.tmp
2014-10-19 15:48 - 2014-10-19 15:48 - 00000687 _____ () C:\awh1006.tmp
2014-10-19 09:48 - 2014-10-19 09:48 - 00000687 _____ () C:\awhF7A.tmp
2014-10-19 07:50 - 2014-10-19 07:50 - 00000687 _____ () C:\awh1370.tmp
2014-10-18 21:03 - 2014-10-18 21:03 - 00000687 _____ () C:\awh1F71.tmp
2014-10-18 17:03 - 2014-10-18 17:03 - 00000687 _____ () C:\awh8B6.tmp
2014-10-18 13:10 - 2014-10-18 13:10 - 00000687 _____ () C:\awh4A1.tmp
2014-10-18 10:20 - 2014-10-18 10:20 - 00000687 _____ () C:\awh6B4.tmp
2014-10-17 16:54 - 2014-10-17 16:54 - 00000687 _____ () C:\awh1074.tmp
2014-10-17 13:41 - 2014-10-17 13:41 - 00000687 _____ () C:\awh241.tmp
2014-10-16 21:38 - 2014-10-16 21:38 - 00000687 _____ () C:\awh914.tmp
2014-10-16 16:55 - 2014-10-16 16:55 - 00000687 _____ () C:\awh2E50.tmp
2014-10-16 06:18 - 2014-10-16 06:18 - 00000687 _____ () C:\awh43C3.tmp
2014-10-16 05:50 - 2014-10-16 05:50 - 00000687 _____ () C:\awh278C.tmp
2014-10-15 20:54 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-15 20:54 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-15 20:54 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-15 20:54 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-15 20:54 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-15 20:54 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-15 20:54 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-15 20:54 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-10-15 20:54 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-10-15 20:54 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-15 20:54 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-15 20:54 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-15 20:54 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-10-15 20:54 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-10-15 20:54 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-15 20:54 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-15 20:54 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-10-15 20:54 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-10-15 20:54 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-10-15 20:54 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-10-15 20:54 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-15 20:54 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-15 20:54 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-10-15 20:54 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-15 20:54 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-10-15 20:54 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-10-15 20:54 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 20:54 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-10-15 20:54 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-15 20:54 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-15 20:54 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-15 20:54 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-15 20:54 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-10-15 20:54 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-10-15 20:54 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-10-15 20:54 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-10-15 20:54 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-10-15 20:54 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-15 20:54 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-15 20:54 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-10-15 20:54 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 20:54 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-15 20:54 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-10-15 20:54 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-15 20:54 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-10-15 20:54 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-15 20:54 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-15 20:54 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-15 20:54 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-15 20:54 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-15 20:30 - 2014-08-19 04:11 - 00693176 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2014-10-15 20:30 - 2014-08-19 04:10 - 00616352 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2014-10-15 20:30 - 2014-08-19 04:08 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2014-10-15 20:30 - 2014-08-19 04:08 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2014-10-15 20:30 - 2014-08-19 04:08 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2014-10-15 20:30 - 2014-08-19 04:07 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2014-10-15 20:30 - 2014-08-19 04:07 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2014-10-15 20:30 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2014-10-15 20:30 - 2014-08-19 03:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2014-10-15 20:30 - 2014-08-19 03:06 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2014-10-15 20:30 - 2014-07-07 03:07 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2014-10-15 20:30 - 2014-07-07 03:07 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2014-10-15 20:30 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 05551032 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 04120576 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01574400 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01069056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00188416 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2014-10-15 20:30 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2014-10-15 20:30 - 2014-07-07 03:05 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2014-10-15 20:30 - 2014-07-07 03:05 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2014-10-15 20:30 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2014-10-15 20:30 - 2014-07-07 02:52 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2014-10-15 20:30 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2014-10-15 20:30 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2014-10-15 20:30 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2014-10-15 20:30 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2014-10-15 20:30 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2014-10-15 20:30 - 2014-06-28 01:21 - 00619056 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2014-10-15 20:30 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2014-10-15 20:30 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2014-10-15 20:25 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-15 20:25 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2014-10-15 20:20 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-10-15 20:20 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2014-10-15 20:20 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-10-15 20:15 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2014-10-15 20:15 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2014-10-15 20:15 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-15 20:15 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-10-15 20:15 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-10-15 20:15 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2014-10-15 20:15 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-10-15 20:15 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-10-15 20:15 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2014-10-15 20:15 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2014-10-15 20:14 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-15 20:14 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2014-10-15 20:04 - 2014-10-15 20:04 - 00000687 _____ () C:\awh8D04.tmp
2014-10-15 11:59 - 2014-10-15 11:59 - 00000687 _____ () C:\awh13ED.tmp
2014-10-15 08:03 - 2014-10-15 08:03 - 00000687 _____ () C:\awh195B.tmp
2014-10-14 16:52 - 2014-10-14 16:52 - 00000687 _____ () C:\awh118E.tmp
2014-10-14 12:21 - 2014-10-14 12:21 - 00000687 _____ () C:\awh369.tmp
2014-10-14 10:32 - 2014-10-14 10:32 - 00000687 _____ () C:\awh206B.tmp
2014-10-14 06:22 - 2014-10-14 06:22 - 00000687 _____ () C:\awh229C.tmp
2014-10-13 15:39 - 2014-10-13 15:39 - 00000687 _____ () C:\awh12B6.tmp
2014-10-12 10:59 - 2014-10-12 10:59 - 00000687 _____ () C:\awh1766.tmp
2014-10-12 07:04 - 2014-10-12 07:04 - 00000687 _____ () C:\awh740.tmp
2014-10-11 17:05 - 2014-10-11 17:05 - 00000687 _____ () C:\awh116F.tmp
2014-10-11 11:32 - 2014-10-11 11:32 - 00000687 _____ () C:\awh12B5.tmp
2014-10-10 22:30 - 2014-10-10 22:30 - 00000687 _____ () C:\awhC4F.tmp
2014-10-10 16:48 - 2014-10-10 16:48 - 00000687 _____ () C:\awhD0A.tmp
2014-10-10 08:59 - 2014-10-10 08:59 - 00243440 _____ (ESET) C:\windows\system32\Drivers\eamonm.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00241368 _____ (ESET) C:\windows\system32\Drivers\edevmon.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00222280 _____ (ESET) C:\windows\system32\Drivers\epfw.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00169280 _____ (ESET) C:\windows\system32\Drivers\ehdrv.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00063160 _____ (ESET) C:\windows\system32\Drivers\epfwwfp.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00044632 _____ (ESET) C:\windows\system32\Drivers\EpfwLWF.sys
2014-10-10 00:41 - 2014-10-10 00:41 - 00000687 _____ () C:\awh435.tmp
2014-10-09 22:08 - 2014-10-09 22:08 - 00000687 _____ () C:\awhA2D.tmp
2014-10-09 20:10 - 2014-10-09 20:10 - 00000687 _____ () C:\awhE80.tmp
2014-10-09 16:15 - 2014-10-09 16:15 - 00000687 _____ () C:\awhB85.tmp
2014-10-08 21:47 - 2014-10-08 21:47 - 00000687 _____ () C:\awh11BD.tmp
2014-10-08 18:08 - 2014-10-08 18:08 - 00000687 _____ () C:\awh1BE8.tmp
2014-10-08 15:12 - 2014-10-08 15:12 - 00000687 _____ () C:\awh4D0.tmp
2014-10-07 15:35 - 2014-10-07 15:35 - 00000687 _____ () C:\awh675.tmp
2014-10-07 00:31 - 2014-10-07 00:31 - 00000687 _____ () C:\awh9C1.tmp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 00:27 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 00:27 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 00:20 - 2011-02-25 10:48 - 00058016 _____ () C:\Users\Jirka\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-06 00:19 - 2014-01-29 16:43 - 00000270 __RSH () C:\ProgramData\ntuser.pol
2014-11-06 00:19 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-11-06 00:19 - 2009-07-14 05:51 - 00256218 _____ () C:\windows\setupact.log
2014-11-06 00:19 - 2009-07-14 05:45 - 00268800 _____ () C:\windows\system32\FNTCACHE.DAT
2014-11-06 00:18 - 2010-10-06 00:20 - 01111379 _____ () C:\windows\WindowsUpdate.log
2014-11-06 00:18 - 2010-09-09 22:57 - 00926304 _____ () C:\windows\PFRO.log
2014-11-06 00:17 - 2012-05-16 15:52 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Skype
2014-11-06 00:09 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-06 00:07 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-11-06 00:06 - 2011-03-03 14:32 - 00000000 ____D () C:\ProgramData\Norton
2014-11-06 00:06 - 2010-10-06 00:22 - 00008391 _____ () C:\windows\system32\RaCoInst.log
2014-11-05 23:35 - 2013-11-02 17:59 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Seznam.cz
2014-11-05 21:54 - 2010-09-09 22:51 - 00000000 ____D () C:\Program Files\Common Files\McAfee
2014-11-05 21:51 - 2011-02-25 10:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
2014-11-05 21:40 - 2010-09-09 21:56 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-11-05 21:33 - 2011-02-28 17:05 - 00000000 ____D () C:\Program Files\DivX
2014-11-05 21:33 - 2011-02-28 17:02 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-11-05 21:33 - 2011-02-28 16:58 - 00000000 ____D () C:\ProgramData\DivX
2014-11-05 21:25 - 2011-02-25 10:47 - 00000969 _____ () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-05 21:11 - 2010-09-09 22:52 - 00008727 _____ () C:\windows\system32\Config.MPF
2014-11-05 20:51 - 2010-09-09 22:18 - 00669576 _____ () C:\windows\system32\perfh005.dat
2014-11-05 20:51 - 2010-09-09 22:18 - 00141946 _____ () C:\windows\system32\perfc005.dat
2014-11-05 20:51 - 2009-07-14 06:13 - 01586138 _____ () C:\windows\system32\PerfStringBackup.INI
2014-11-03 01:53 - 2011-04-08 07:58 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\SoftGrid Client
2014-11-02 20:44 - 2013-04-12 13:02 - 00010590 _____ () C:\Users\Jirka\Desktop\debug.log
2014-10-29 12:28 - 2013-11-02 18:27 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-29 12:27 - 2011-02-28 16:45 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Deployment
2014-10-28 19:55 - 2009-07-14 06:08 - 00032568 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-10-27 11:31 - 2013-12-10 15:54 - 00000836 _____ () C:\extensions.ini
2014-10-19 20:25 - 2011-02-25 18:28 - 00000000 ____D () C:\windows\rescache
2014-10-16 05:47 - 2009-07-14 06:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2014-10-16 05:43 - 2014-05-06 10:41 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-10-16 05:43 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2014-10-16 05:43 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\Dism
2014-10-07 16:34 - 2011-02-28 16:46 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForJirka
2014-10-07 16:34 - 2011-02-28 16:46 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForJirka.job
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForJirka.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Jirka\Desktop" je 3029 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisorDock
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackup
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
- Přílohy
-
- Addition.zip
- (4.87 KiB) Staženo 51 x
Re: Prosím o kontrolu logu
Dobre rano
Vcera vecer jste skenoval AdwCleanerem. Pouzil jste i moznost clean?
Ulozte na plochu zoek.exe http://hijackthis.nl/smeenk/zoek.htm



- spustte jako spravce
- do velkeho okna zkopirujte script uvedeny nize
- kliknete na Run script
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\zoek-results.log) - vlozte mi jej do pristi odpovedi
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Dobrý den,
jj AdwCleaner jsem použil, i možnost Clean.
Přikládám Zoek log:
Zoek.exe v5.0.0.0 Updated 05-November-2014
Tool run by Jirka on źt 06.11.2014 at 10:57:10,03.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Jirka\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
6.11.2014 10:58:20 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d0a25cea-8071-43d8-b79a-5e38799346e3} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d0a25cea-8071-43d8-b79a-5e38799346e3} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0a74a958-9ba5-4663-b474-688986924314} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0a74a958-9ba5-4663-b474-688986924314} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30f3ab79-0021-414d-96fb-b0e2fa302ed9} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30f3ab79-0021-414d-96fb-b0e2fa302ed9} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0d99d40d-fe35-4430-8f62-e8d2c347013a} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0d99d40d-fe35-4430-8f62-e8d2c347013a} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{b6a54cf1-c7da-4b41-a4be-96668eac30f3} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{b6a54cf1-c7da-4b41-a4be-96668eac30f3} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7fccb39f-cf1a-4c88-9afd-a29589db907e} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7fccb39f-cf1a-4c88-9afd-a29589db907e} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d653a6f-c495-4903-b611-7cd6e55be5a0} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2d653a6f-c495-4903-b611-7cd6e55be5a0} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7e64cb3d-3e32-4040-9e73-2db063cb28c8} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7e64cb3d-3e32-4040-9e73-2db063cb28c8} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d0a25cea-8071-43d8-b79a-5e38799346e3} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d0a25cea-8071-43d8-b79a-5e38799346e3} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{0a74a958-9ba5-4663-b474-688986924314} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0a74a958-9ba5-4663-b474-688986924314} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{30f3ab79-0021-414d-96fb-b0e2fa302ed9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30f3ab79-0021-414d-96fb-b0e2fa302ed9} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{0d99d40d-fe35-4430-8f62-e8d2c347013a} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0d99d40d-fe35-4430-8f62-e8d2c347013a} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{b6a54cf1-c7da-4b41-a4be-96668eac30f3} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b6a54cf1-c7da-4b41-a4be-96668eac30f3} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{7fccb39f-cf1a-4c88-9afd-a29589db907e} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7fccb39f-cf1a-4c88-9afd-a29589db907e} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2d653a6f-c495-4903-b611-7cd6e55be5a0} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2d653a6f-c495-4903-b611-7cd6e55be5a0} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{7e64cb3d-3e32-4040-9e73-2db063cb28c8} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e64cb3d-3e32-4040-9e73-2db063cb28c8} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\12x3q4@3244516.com deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@WebexpEnhancedV1alpha651.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@VideoPlayerV3beta134.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaPlayerV1alpha351.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewerV1alpha1587.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha1481.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha3668.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaWatchV1home1.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaBuzzV1mode8294.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@RichMediaViewV1release705.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@TrustMediaViewerV1alpha3921.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@RichMediaViewV1release3516.net deleted successfully
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\PROGRA~2\COMMON~1\Config\uninstinethnfd.exe deleted
C:\PROGRA~2\COMMON~1\Config deleted
C:\extensions.sqlite deleted
C:\extensions.ini deleted
C:\awh1006.tmp deleted
C:\awh1026.tmp deleted
C:\awh1045.tmp deleted
C:\awh1054.tmp deleted
C:\awh1055.tmp deleted
C:\awh1064.tmp deleted
C:\awh1074.tmp deleted
C:\awh1083.tmp deleted
C:\awh1084.tmp deleted
C:\awh1093.tmp deleted
C:\awh1094.tmp deleted
C:\awh1095.tmp deleted
C:\awh10E1.tmp deleted
C:\awh111F.tmp deleted
C:\awh113E.tmp deleted
C:\awh114E.tmp deleted
C:\awh115E.tmp deleted
C:\awh115F.tmp deleted
C:\awh116D.tmp deleted
C:\awh116E.tmp deleted
C:\awh116F.tmp deleted
C:\awh118C.tmp deleted
C:\awh118D.tmp deleted
C:\awh118E.tmp deleted
C:\awh11BB.tmp deleted
C:\awh11BC.tmp deleted
C:\awh11BD.tmp deleted
C:\awh11CB.tmp deleted
C:\awh11CC.tmp deleted
C:\awh11FA.tmp deleted
C:\awh1228.tmp deleted
C:\awh1248.tmp deleted
C:\awh1267.tmp deleted
C:\awh1268.tmp deleted
C:\awh1286.tmp deleted
C:\awh1296.tmp deleted
C:\awh1297.tmp deleted
C:\awh12A5.tmp deleted
C:\awh12B5.tmp deleted
C:\awh12B6.tmp deleted
C:\awh12E4.tmp deleted
C:\awh12F3.tmp deleted
C:\awh12F4.tmp deleted
C:\awh1312.tmp deleted
C:\awh1322.tmp deleted
C:\awh1323.tmp deleted
C:\awh1332.tmp deleted
C:\awh1341.tmp deleted
C:\awh1370.tmp deleted
C:\awh138F.tmp deleted
C:\awh1390.tmp deleted
C:\awh13CE.tmp deleted
C:\awh13ED.tmp deleted
C:\awh140C.tmp deleted
C:\awh142B.tmp deleted
C:\awh144A.tmp deleted
C:\awh147F.tmp deleted
C:\awh1489.tmp deleted
C:\awh14B8.tmp deleted
C:\awh1506.tmp deleted
C:\awh1534.tmp deleted
C:\awh1554.tmp deleted
C:\awh1563.tmp deleted
C:\awh1564.tmp deleted
C:\awh1582.tmp deleted
C:\awh1583.tmp deleted
C:\awh15A2.tmp deleted
C:\awh15D0.tmp deleted
C:\awh160F.tmp deleted
C:\awh161E.tmp deleted
C:\awh162E.tmp deleted
C:\awh163E.tmp deleted
C:\awh163F.tmp deleted
C:\awh165D.tmp deleted
C:\awh165E.tmp deleted
C:\awh166C.tmp deleted
C:\awh16AB.tmp deleted
C:\awh16E9.tmp deleted
C:\awh1728.tmp deleted
C:\awh1756.tmp deleted
C:\awh1766.tmp deleted
C:\awh1795.tmp deleted
C:\awh186.tmp deleted
C:\awh187F.tmp deleted
C:\awh18AE.tmp deleted
C:\awh18BD.tmp deleted
C:\awh18CD.tmp deleted
C:\awh18FC.tmp deleted
C:\awh18FD.tmp deleted
C:\awh190B.tmp deleted
C:\awh190C.tmp deleted
C:\awh191B.tmp deleted
C:\awh192A.tmp deleted
C:\awh1959.tmp deleted
C:\awh195A.tmp deleted
C:\awh195B.tmp deleted
C:\awh195C.tmp deleted
C:\awh1978.tmp deleted
C:\awh19A7.tmp deleted
C:\awh19C6.tmp deleted
C:\awh1A43.tmp deleted
C:\awh1A62.tmp deleted
C:\awh1AA1.tmp deleted
C:\awh1AB0.tmp deleted
C:\awh1ADF.tmp deleted
C:\awh1B0E.tmp deleted
C:\awh1B2D.tmp deleted
C:\awh1B7B.tmp deleted
C:\awh1BE8.tmp deleted
C:\awh1BF8.tmp deleted
C:\awh1C56.tmp deleted
C:\awh1C84.tmp deleted
C:\awh1C94.tmp deleted
C:\awh1CF2.tmp deleted
C:\awh1D5F.tmp deleted
C:\awh1DDC.tmp deleted
C:\awh1E2A.tmp deleted
C:\awh1E97.tmp deleted
C:\awh1F42.tmp deleted
C:\awh1F71.tmp deleted
C:\awh1F81.tmp deleted
C:\awh1FBF.tmp deleted
C:\awh200D.tmp deleted
C:\awh203C.tmp deleted
C:\awh206B.tmp deleted
C:\awh20A9.tmp deleted
C:\awh2200.tmp deleted
C:\awh222.tmp deleted
C:\awh229C.tmp deleted
C:\awh230A.tmp deleted
C:\awh2319.tmp deleted
C:\awh241.tmp deleted
C:\awh2461.tmp deleted
C:\awh2470.tmp deleted
C:\awh2471.tmp deleted
C:\awh252C.tmp deleted
C:\awh2700.tmp deleted
C:\awh278C.tmp deleted
C:\awh2876.tmp deleted
C:\awh28F.tmp deleted
C:\awh29EC.tmp deleted
C:\awh2AE.tmp deleted
C:\awh2AF.tmp deleted
C:\awh2C8B.tmp deleted
C:\awh2CAA.tmp deleted
C:\awh2E50.tmp deleted
C:\awh2E6F.tmp deleted
C:\awh2F2A.tmp deleted
C:\awh3284.tmp deleted
C:\awh33FA.tmp deleted
C:\awh3458.tmp deleted
C:\awh34E4.tmp deleted
C:\awh3504.tmp deleted
C:\awh3523.tmp deleted
C:\awh3571.tmp deleted
C:\awh369.tmp deleted
C:\awh3699.tmp deleted
C:\awh36B8.tmp deleted
C:\awh379.tmp deleted
C:\awh37A2.tmp deleted
C:\awh3800.tmp deleted
C:\awh3909.tmp deleted
C:\awh3957.tmp deleted
C:\awh398.tmp deleted
C:\awh3A8.tmp deleted
C:\awh3A80.tmp deleted
C:\awh3B79.tmp deleted
C:\awh3B7A.tmp deleted
C:\awh3D6.tmp deleted
C:\awh3E95.tmp deleted
C:\awh3F12.tmp deleted
C:\awh3F6F.tmp deleted
C:\awh4163.tmp deleted
C:\awh434.tmp deleted
C:\awh435.tmp deleted
C:\awh4356.tmp deleted
C:\awh43A4.tmp deleted
C:\awh43C3.tmp deleted
C:\awh4411.tmp deleted
C:\awh451A.tmp deleted
C:\awh4539.tmp deleted
C:\awh46CF.tmp deleted
C:\awh475B.tmp deleted
C:\awh482.tmp deleted
C:\awh483.tmp deleted
C:\awh492.tmp deleted
C:\awh4A1.tmp deleted
C:\awh4A77.tmp deleted
C:\awh4B1.tmp deleted
C:\awh4BFD.tmp deleted
C:\awh4D0.tmp deleted
C:\awh4EF.tmp deleted
C:\awh4F95.tmp deleted
C:\awh4FE3.tmp deleted
C:\awh50AE.tmp deleted
C:\awh50E.tmp deleted
C:\awh5205.tmp deleted
C:\awh54D.tmp deleted
C:\awh54E.tmp deleted
C:\awh559E.tmp deleted
C:\awh56C.tmp deleted
C:\awh56D.tmp deleted
C:\awh57B0.tmp deleted
C:\awh57C.tmp deleted
C:\awh583D.tmp deleted
C:\awh5AA.tmp deleted
C:\awh5B58.tmp deleted
C:\awh5CCF.tmp deleted
C:\awh5D0D.tmp deleted
C:\awh5D4B.tmp deleted
C:\awh5D9.tmp deleted
C:\awh5E9.tmp deleted
C:\awh5F8.tmp deleted
C:\awh618.tmp deleted
C:\awh627.tmp deleted
C:\awh666.tmp deleted
C:\awh675.tmp deleted
C:\awh6AE2.tmp deleted
C:\awh6B4.tmp deleted
C:\awh6C3.tmp deleted
C:\awh6CC6.tmp deleted
C:\awh6E2.tmp deleted
C:\awh6F2.tmp deleted
C:\awh711.tmp deleted
C:\awh712.tmp deleted
C:\awh730.tmp deleted
C:\awh740.tmp deleted
C:\awh750.tmp deleted
C:\awh75BB.tmp deleted
C:\awh7BF2.tmp deleted
C:\awh7CC.tmp deleted
C:\awh7CD.tmp deleted
C:\awh843C.tmp deleted
C:\awh849.tmp deleted
C:\awh868.tmp deleted
C:\awh869.tmp deleted
C:\awh878.tmp deleted
C:\awh888.tmp deleted
C:\awh8A7.tmp deleted
C:\awh8B6.tmp deleted
C:\awh8C6.tmp deleted
C:\awh8D04.tmp deleted
C:\awh8F5.tmp deleted
C:\awh904.tmp deleted
C:\awh905.tmp deleted
C:\awh906.tmp deleted
C:\awh907.tmp deleted
C:\awh914.tmp deleted
C:\awh924.tmp deleted
C:\awh925.tmp deleted
C:\awh933.tmp deleted
C:\awh943.tmp deleted
C:\awh962.tmp deleted
C:\awh972.tmp deleted
C:\awh981.tmp deleted
C:\awh9B4F.tmp deleted
C:\awh9C.tmp deleted
C:\awh9C0.tmp deleted
C:\awh9C1.tmp deleted
C:\awh9EE.tmp deleted
C:\awh9EF.tmp deleted
C:\awhA2D.tmp deleted
C:\awhA5C.tmp deleted
C:\awhA6B.tmp deleted
C:\awhA6C.tmp deleted
C:\awhA929.tmp deleted
C:\awhAB9.tmp deleted
C:\awhABA.tmp deleted
C:\awhABB.tmp deleted
C:\awhAC9.tmp deleted
C:\awhACA.tmp deleted
C:\awhACE1.tmp deleted
C:\awhADAC.tmp deleted
C:\awhAF8.tmp deleted
C:\awhB05A.tmp deleted
C:\awhB26.tmp deleted
C:\awhB2DA.tmp deleted
C:\awhB2E9.tmp deleted
C:\awhB36.tmp deleted
C:\awhB65.tmp deleted
C:\awhB66.tmp deleted
C:\awhB84.tmp deleted
C:\awhB85.tmp deleted
C:\awhBA3.tmp deleted
C:\awhBC5A.tmp deleted
C:\awhBD2.tmp deleted
C:\awhBE2.tmp deleted
C:\awhC20.tmp deleted
C:\awhC30.tmp deleted
C:\awhC3F.tmp deleted
C:\awhC40.tmp deleted
C:\awhC4F.tmp deleted
C:\awhC5E.tmp deleted
C:\awhC8D.tmp deleted
C:\awhC8E.tmp deleted
C:\awhC8F.tmp deleted
C:\awhC9D.tmp deleted
C:\awhC9E.tmp deleted
C:\awhCCC.tmp deleted
C:\awhCCD.tmp deleted
C:\awhCCE.tmp deleted
C:\awhCDB.tmp deleted
C:\awhCFA.tmp deleted
C:\awhD0A.tmp deleted
C:\awhD0B.tmp deleted
C:\awhD1A.tmp deleted
C:\awhD29.tmp deleted
C:\awhD368.tmp deleted
C:\awhD39.tmp deleted
C:\awhD48.tmp deleted
C:\awhD58.tmp deleted
C:\awhD59.tmp deleted
C:\awhD68.tmp deleted
C:\awhD69.tmp deleted
C:\awhD87.tmp deleted
C:\awhDB6.tmp deleted
C:\awhDC5.tmp deleted
C:\awhDC6.tmp deleted
C:\awhDD5.tmp deleted
C:\awhE32.tmp deleted
C:\awhE61.tmp deleted
C:\awhE71.tmp deleted
C:\awhE80.tmp deleted
C:\awhEA0.tmp deleted
C:\awhEAF.tmp deleted
C:\awhEBF.tmp deleted
C:\awhECE.tmp deleted
C:\awhEEE.tmp deleted
C:\awhEEF.tmp deleted
C:\awhEFD.tmp deleted
C:\awhEFE.tmp deleted
C:\awhF0D.tmp deleted
C:\awhF0E.tmp deleted
C:\awhF1C.tmp deleted
C:\awhF1F5.tmp deleted
C:\awhF2C.tmp deleted
C:\awhF3C.tmp deleted
C:\awhF6A.tmp deleted
C:\awhF759.tmp deleted
C:\awhF7A.tmp deleted
C:\awhF93C.tmp deleted
C:\awhFA9.tmp deleted
C:\awhFAA.tmp deleted
C:\awhFCE4.tmp deleted
C:\awhFFE0.tmp deleted
C:\windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\windows\Syswow64\GroupPolicy\gpt.ini deleted
"C:\PROGRA~3\boost_interprocess\20141106103015.359599\Nobu64AgentService2.7.2.25" deleted
"C:\PROGRA~3\boost_interprocess\20141106103015.359599\Nobu64TrayIcon2.7.2.25" deleted
"C:\PROGRA~3\boost_interprocess" not deleted
"C:\PROGRA~3\boost_interprocess\20141106103015.359599" not deleted
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
caphpmfackmpbchefdbohpjkjgekpcgo - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ch\VideoPlayerV3beta134.crx[]
emfiolpndjiobhaigieckjhchlocadbm - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ch\MediaViewV1alpha3668.crx[]
janpofkchcegjcafimgongjdcgmikipg - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ch\MediaWatchV1home1.crx[]
jggifkmlclgncoggjhcijfafadgcoamn - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ch\MediaViewV1alpha1481.crx[]
jjokaddkhgfbfcmlaehgcddgalighpln - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ch\RichMediaViewV1release3516.crx[]
kadgahhelapmhhjnmhnmnojfcnlhhoij - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ch\WebexpEnhancedV1alpha651.crx[]
lpemnobkfgfknkoaelaidcodbmaapemm - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ch\TrustMediaViewerV1alpha3921.crx[]
mchgekplgpbgbalnlnajnepeninajado - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ch\MediaBuzzV1mode8294.crx[]
ogoiliccpcefgmiafhjcoagnmkddagof - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ch\RichMediaViewV1release705.crx[]
ojofdhpfcjmjpgnolamolmihoompckbm - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1587\ch\MediaViewerV1alpha1587.crx[]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://start.qone8.com/?type=hp&ts=1383 ... 117JJEVBEX"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{EFD90A5C-C40F-45D9-92AB-A3DAE671237A} Bing Url="http://www.bing.com/search?q={searchTer ... -SearchBox"
{F5D99D81-EA76-435F-B064-F6A5D55306DA} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_16194"
==== Reset Google Chrome ======================
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\caphpmfackmpbchefdbohpjkjgekpcgo deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\emfiolpndjiobhaigieckjhchlocadbm deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\janpofkchcegjcafimgongjdcgmikipg deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jggifkmlclgncoggjhcijfafadgcoamn deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jjokaddkhgfbfcmlaehgcddgalighpln deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kadgahhelapmhhjnmhnmnojfcnlhhoij deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lpemnobkfgfknkoaelaidcodbmaapemm deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mchgekplgpbgbalnlnajnepeninajado deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ogoiliccpcefgmiafhjcoagnmkddagof deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ojofdhpfcjmjpgnolamolmihoompckbm deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisorDock deleted successfully
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=359 folders=6 388874 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Jirka\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\Jirka\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\PROGRA~3\boost_interprocess" not found
==== EOF on źt 06.11.2014 at 11:27:32,93 ======================
jj AdwCleaner jsem použil, i možnost Clean.
Přikládám Zoek log:
Zoek.exe v5.0.0.0 Updated 05-November-2014
Tool run by Jirka on źt 06.11.2014 at 10:57:10,03.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Jirka\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
6.11.2014 10:58:20 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d0a25cea-8071-43d8-b79a-5e38799346e3} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d0a25cea-8071-43d8-b79a-5e38799346e3} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0a74a958-9ba5-4663-b474-688986924314} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0a74a958-9ba5-4663-b474-688986924314} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30f3ab79-0021-414d-96fb-b0e2fa302ed9} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30f3ab79-0021-414d-96fb-b0e2fa302ed9} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0d99d40d-fe35-4430-8f62-e8d2c347013a} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0d99d40d-fe35-4430-8f62-e8d2c347013a} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{b6a54cf1-c7da-4b41-a4be-96668eac30f3} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{b6a54cf1-c7da-4b41-a4be-96668eac30f3} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7fccb39f-cf1a-4c88-9afd-a29589db907e} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7fccb39f-cf1a-4c88-9afd-a29589db907e} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d653a6f-c495-4903-b611-7cd6e55be5a0} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2d653a6f-c495-4903-b611-7cd6e55be5a0} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7e64cb3d-3e32-4040-9e73-2db063cb28c8} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7e64cb3d-3e32-4040-9e73-2db063cb28c8} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bc5ec4ac-de8e-4aa0-9d03-78f369bd7fa2} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5d6eba3-25c6-423f-9bd4-9e7cf130e40b} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d0a25cea-8071-43d8-b79a-5e38799346e3} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d0a25cea-8071-43d8-b79a-5e38799346e3} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{0a74a958-9ba5-4663-b474-688986924314} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0a74a958-9ba5-4663-b474-688986924314} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{30f3ab79-0021-414d-96fb-b0e2fa302ed9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30f3ab79-0021-414d-96fb-b0e2fa302ed9} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{0d99d40d-fe35-4430-8f62-e8d2c347013a} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0d99d40d-fe35-4430-8f62-e8d2c347013a} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{b6a54cf1-c7da-4b41-a4be-96668eac30f3} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b6a54cf1-c7da-4b41-a4be-96668eac30f3} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{7fccb39f-cf1a-4c88-9afd-a29589db907e} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7fccb39f-cf1a-4c88-9afd-a29589db907e} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2d653a6f-c495-4903-b611-7cd6e55be5a0} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2d653a6f-c495-4903-b611-7cd6e55be5a0} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ac09750-dd5e-43bb-9a39-3279ac3f5ec7} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{7e64cb3d-3e32-4040-9e73-2db063cb28c8} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7e64cb3d-3e32-4040-9e73-2db063cb28c8} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_USERS\S-1-5-21-1582745763-2883292187-2515674152-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Approved Extensions\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\12x3q4@3244516.com deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@WebexpEnhancedV1alpha651.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@VideoPlayerV3beta134.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaPlayerV1alpha351.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewerV1alpha1587.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha1481.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha3668.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaWatchV1home1.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaBuzzV1mode8294.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@RichMediaViewV1release705.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@TrustMediaViewerV1alpha3921.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@RichMediaViewV1release3516.net deleted successfully
==== Deleting Services ======================
==== Deleting Files \ Folders ======================
C:\PROGRA~2\COMMON~1\Config\uninstinethnfd.exe deleted
C:\PROGRA~2\COMMON~1\Config deleted
C:\extensions.sqlite deleted
C:\extensions.ini deleted
C:\awh1006.tmp deleted
C:\awh1026.tmp deleted
C:\awh1045.tmp deleted
C:\awh1054.tmp deleted
C:\awh1055.tmp deleted
C:\awh1064.tmp deleted
C:\awh1074.tmp deleted
C:\awh1083.tmp deleted
C:\awh1084.tmp deleted
C:\awh1093.tmp deleted
C:\awh1094.tmp deleted
C:\awh1095.tmp deleted
C:\awh10E1.tmp deleted
C:\awh111F.tmp deleted
C:\awh113E.tmp deleted
C:\awh114E.tmp deleted
C:\awh115E.tmp deleted
C:\awh115F.tmp deleted
C:\awh116D.tmp deleted
C:\awh116E.tmp deleted
C:\awh116F.tmp deleted
C:\awh118C.tmp deleted
C:\awh118D.tmp deleted
C:\awh118E.tmp deleted
C:\awh11BB.tmp deleted
C:\awh11BC.tmp deleted
C:\awh11BD.tmp deleted
C:\awh11CB.tmp deleted
C:\awh11CC.tmp deleted
C:\awh11FA.tmp deleted
C:\awh1228.tmp deleted
C:\awh1248.tmp deleted
C:\awh1267.tmp deleted
C:\awh1268.tmp deleted
C:\awh1286.tmp deleted
C:\awh1296.tmp deleted
C:\awh1297.tmp deleted
C:\awh12A5.tmp deleted
C:\awh12B5.tmp deleted
C:\awh12B6.tmp deleted
C:\awh12E4.tmp deleted
C:\awh12F3.tmp deleted
C:\awh12F4.tmp deleted
C:\awh1312.tmp deleted
C:\awh1322.tmp deleted
C:\awh1323.tmp deleted
C:\awh1332.tmp deleted
C:\awh1341.tmp deleted
C:\awh1370.tmp deleted
C:\awh138F.tmp deleted
C:\awh1390.tmp deleted
C:\awh13CE.tmp deleted
C:\awh13ED.tmp deleted
C:\awh140C.tmp deleted
C:\awh142B.tmp deleted
C:\awh144A.tmp deleted
C:\awh147F.tmp deleted
C:\awh1489.tmp deleted
C:\awh14B8.tmp deleted
C:\awh1506.tmp deleted
C:\awh1534.tmp deleted
C:\awh1554.tmp deleted
C:\awh1563.tmp deleted
C:\awh1564.tmp deleted
C:\awh1582.tmp deleted
C:\awh1583.tmp deleted
C:\awh15A2.tmp deleted
C:\awh15D0.tmp deleted
C:\awh160F.tmp deleted
C:\awh161E.tmp deleted
C:\awh162E.tmp deleted
C:\awh163E.tmp deleted
C:\awh163F.tmp deleted
C:\awh165D.tmp deleted
C:\awh165E.tmp deleted
C:\awh166C.tmp deleted
C:\awh16AB.tmp deleted
C:\awh16E9.tmp deleted
C:\awh1728.tmp deleted
C:\awh1756.tmp deleted
C:\awh1766.tmp deleted
C:\awh1795.tmp deleted
C:\awh186.tmp deleted
C:\awh187F.tmp deleted
C:\awh18AE.tmp deleted
C:\awh18BD.tmp deleted
C:\awh18CD.tmp deleted
C:\awh18FC.tmp deleted
C:\awh18FD.tmp deleted
C:\awh190B.tmp deleted
C:\awh190C.tmp deleted
C:\awh191B.tmp deleted
C:\awh192A.tmp deleted
C:\awh1959.tmp deleted
C:\awh195A.tmp deleted
C:\awh195B.tmp deleted
C:\awh195C.tmp deleted
C:\awh1978.tmp deleted
C:\awh19A7.tmp deleted
C:\awh19C6.tmp deleted
C:\awh1A43.tmp deleted
C:\awh1A62.tmp deleted
C:\awh1AA1.tmp deleted
C:\awh1AB0.tmp deleted
C:\awh1ADF.tmp deleted
C:\awh1B0E.tmp deleted
C:\awh1B2D.tmp deleted
C:\awh1B7B.tmp deleted
C:\awh1BE8.tmp deleted
C:\awh1BF8.tmp deleted
C:\awh1C56.tmp deleted
C:\awh1C84.tmp deleted
C:\awh1C94.tmp deleted
C:\awh1CF2.tmp deleted
C:\awh1D5F.tmp deleted
C:\awh1DDC.tmp deleted
C:\awh1E2A.tmp deleted
C:\awh1E97.tmp deleted
C:\awh1F42.tmp deleted
C:\awh1F71.tmp deleted
C:\awh1F81.tmp deleted
C:\awh1FBF.tmp deleted
C:\awh200D.tmp deleted
C:\awh203C.tmp deleted
C:\awh206B.tmp deleted
C:\awh20A9.tmp deleted
C:\awh2200.tmp deleted
C:\awh222.tmp deleted
C:\awh229C.tmp deleted
C:\awh230A.tmp deleted
C:\awh2319.tmp deleted
C:\awh241.tmp deleted
C:\awh2461.tmp deleted
C:\awh2470.tmp deleted
C:\awh2471.tmp deleted
C:\awh252C.tmp deleted
C:\awh2700.tmp deleted
C:\awh278C.tmp deleted
C:\awh2876.tmp deleted
C:\awh28F.tmp deleted
C:\awh29EC.tmp deleted
C:\awh2AE.tmp deleted
C:\awh2AF.tmp deleted
C:\awh2C8B.tmp deleted
C:\awh2CAA.tmp deleted
C:\awh2E50.tmp deleted
C:\awh2E6F.tmp deleted
C:\awh2F2A.tmp deleted
C:\awh3284.tmp deleted
C:\awh33FA.tmp deleted
C:\awh3458.tmp deleted
C:\awh34E4.tmp deleted
C:\awh3504.tmp deleted
C:\awh3523.tmp deleted
C:\awh3571.tmp deleted
C:\awh369.tmp deleted
C:\awh3699.tmp deleted
C:\awh36B8.tmp deleted
C:\awh379.tmp deleted
C:\awh37A2.tmp deleted
C:\awh3800.tmp deleted
C:\awh3909.tmp deleted
C:\awh3957.tmp deleted
C:\awh398.tmp deleted
C:\awh3A8.tmp deleted
C:\awh3A80.tmp deleted
C:\awh3B79.tmp deleted
C:\awh3B7A.tmp deleted
C:\awh3D6.tmp deleted
C:\awh3E95.tmp deleted
C:\awh3F12.tmp deleted
C:\awh3F6F.tmp deleted
C:\awh4163.tmp deleted
C:\awh434.tmp deleted
C:\awh435.tmp deleted
C:\awh4356.tmp deleted
C:\awh43A4.tmp deleted
C:\awh43C3.tmp deleted
C:\awh4411.tmp deleted
C:\awh451A.tmp deleted
C:\awh4539.tmp deleted
C:\awh46CF.tmp deleted
C:\awh475B.tmp deleted
C:\awh482.tmp deleted
C:\awh483.tmp deleted
C:\awh492.tmp deleted
C:\awh4A1.tmp deleted
C:\awh4A77.tmp deleted
C:\awh4B1.tmp deleted
C:\awh4BFD.tmp deleted
C:\awh4D0.tmp deleted
C:\awh4EF.tmp deleted
C:\awh4F95.tmp deleted
C:\awh4FE3.tmp deleted
C:\awh50AE.tmp deleted
C:\awh50E.tmp deleted
C:\awh5205.tmp deleted
C:\awh54D.tmp deleted
C:\awh54E.tmp deleted
C:\awh559E.tmp deleted
C:\awh56C.tmp deleted
C:\awh56D.tmp deleted
C:\awh57B0.tmp deleted
C:\awh57C.tmp deleted
C:\awh583D.tmp deleted
C:\awh5AA.tmp deleted
C:\awh5B58.tmp deleted
C:\awh5CCF.tmp deleted
C:\awh5D0D.tmp deleted
C:\awh5D4B.tmp deleted
C:\awh5D9.tmp deleted
C:\awh5E9.tmp deleted
C:\awh5F8.tmp deleted
C:\awh618.tmp deleted
C:\awh627.tmp deleted
C:\awh666.tmp deleted
C:\awh675.tmp deleted
C:\awh6AE2.tmp deleted
C:\awh6B4.tmp deleted
C:\awh6C3.tmp deleted
C:\awh6CC6.tmp deleted
C:\awh6E2.tmp deleted
C:\awh6F2.tmp deleted
C:\awh711.tmp deleted
C:\awh712.tmp deleted
C:\awh730.tmp deleted
C:\awh740.tmp deleted
C:\awh750.tmp deleted
C:\awh75BB.tmp deleted
C:\awh7BF2.tmp deleted
C:\awh7CC.tmp deleted
C:\awh7CD.tmp deleted
C:\awh843C.tmp deleted
C:\awh849.tmp deleted
C:\awh868.tmp deleted
C:\awh869.tmp deleted
C:\awh878.tmp deleted
C:\awh888.tmp deleted
C:\awh8A7.tmp deleted
C:\awh8B6.tmp deleted
C:\awh8C6.tmp deleted
C:\awh8D04.tmp deleted
C:\awh8F5.tmp deleted
C:\awh904.tmp deleted
C:\awh905.tmp deleted
C:\awh906.tmp deleted
C:\awh907.tmp deleted
C:\awh914.tmp deleted
C:\awh924.tmp deleted
C:\awh925.tmp deleted
C:\awh933.tmp deleted
C:\awh943.tmp deleted
C:\awh962.tmp deleted
C:\awh972.tmp deleted
C:\awh981.tmp deleted
C:\awh9B4F.tmp deleted
C:\awh9C.tmp deleted
C:\awh9C0.tmp deleted
C:\awh9C1.tmp deleted
C:\awh9EE.tmp deleted
C:\awh9EF.tmp deleted
C:\awhA2D.tmp deleted
C:\awhA5C.tmp deleted
C:\awhA6B.tmp deleted
C:\awhA6C.tmp deleted
C:\awhA929.tmp deleted
C:\awhAB9.tmp deleted
C:\awhABA.tmp deleted
C:\awhABB.tmp deleted
C:\awhAC9.tmp deleted
C:\awhACA.tmp deleted
C:\awhACE1.tmp deleted
C:\awhADAC.tmp deleted
C:\awhAF8.tmp deleted
C:\awhB05A.tmp deleted
C:\awhB26.tmp deleted
C:\awhB2DA.tmp deleted
C:\awhB2E9.tmp deleted
C:\awhB36.tmp deleted
C:\awhB65.tmp deleted
C:\awhB66.tmp deleted
C:\awhB84.tmp deleted
C:\awhB85.tmp deleted
C:\awhBA3.tmp deleted
C:\awhBC5A.tmp deleted
C:\awhBD2.tmp deleted
C:\awhBE2.tmp deleted
C:\awhC20.tmp deleted
C:\awhC30.tmp deleted
C:\awhC3F.tmp deleted
C:\awhC40.tmp deleted
C:\awhC4F.tmp deleted
C:\awhC5E.tmp deleted
C:\awhC8D.tmp deleted
C:\awhC8E.tmp deleted
C:\awhC8F.tmp deleted
C:\awhC9D.tmp deleted
C:\awhC9E.tmp deleted
C:\awhCCC.tmp deleted
C:\awhCCD.tmp deleted
C:\awhCCE.tmp deleted
C:\awhCDB.tmp deleted
C:\awhCFA.tmp deleted
C:\awhD0A.tmp deleted
C:\awhD0B.tmp deleted
C:\awhD1A.tmp deleted
C:\awhD29.tmp deleted
C:\awhD368.tmp deleted
C:\awhD39.tmp deleted
C:\awhD48.tmp deleted
C:\awhD58.tmp deleted
C:\awhD59.tmp deleted
C:\awhD68.tmp deleted
C:\awhD69.tmp deleted
C:\awhD87.tmp deleted
C:\awhDB6.tmp deleted
C:\awhDC5.tmp deleted
C:\awhDC6.tmp deleted
C:\awhDD5.tmp deleted
C:\awhE32.tmp deleted
C:\awhE61.tmp deleted
C:\awhE71.tmp deleted
C:\awhE80.tmp deleted
C:\awhEA0.tmp deleted
C:\awhEAF.tmp deleted
C:\awhEBF.tmp deleted
C:\awhECE.tmp deleted
C:\awhEEE.tmp deleted
C:\awhEEF.tmp deleted
C:\awhEFD.tmp deleted
C:\awhEFE.tmp deleted
C:\awhF0D.tmp deleted
C:\awhF0E.tmp deleted
C:\awhF1C.tmp deleted
C:\awhF1F5.tmp deleted
C:\awhF2C.tmp deleted
C:\awhF3C.tmp deleted
C:\awhF6A.tmp deleted
C:\awhF759.tmp deleted
C:\awhF7A.tmp deleted
C:\awhF93C.tmp deleted
C:\awhFA9.tmp deleted
C:\awhFAA.tmp deleted
C:\awhFCE4.tmp deleted
C:\awhFFE0.tmp deleted
C:\windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\windows\Syswow64\GroupPolicy\gpt.ini deleted
"C:\PROGRA~3\boost_interprocess\20141106103015.359599\Nobu64AgentService2.7.2.25" deleted
"C:\PROGRA~3\boost_interprocess\20141106103015.359599\Nobu64TrayIcon2.7.2.25" deleted
"C:\PROGRA~3\boost_interprocess" not deleted
"C:\PROGRA~3\boost_interprocess\20141106103015.359599" not deleted
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
caphpmfackmpbchefdbohpjkjgekpcgo - C:\Program Files (x86)\VideoPlayerV3\VideoPlayerV3beta134\ch\VideoPlayerV3beta134.crx[]
emfiolpndjiobhaigieckjhchlocadbm - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3668\ch\MediaViewV1alpha3668.crx[]
janpofkchcegjcafimgongjdcgmikipg - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home1\ch\MediaWatchV1home1.crx[]
jggifkmlclgncoggjhcijfafadgcoamn - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha1481\ch\MediaViewV1alpha1481.crx[]
jjokaddkhgfbfcmlaehgcddgalighpln - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release3516\ch\RichMediaViewV1release3516.crx[]
kadgahhelapmhhjnmhnmnojfcnlhhoij - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha651\ch\WebexpEnhancedV1alpha651.crx[]
lpemnobkfgfknkoaelaidcodbmaapemm - C:\Program Files (x86)\TrustMediaViewerV1\TrustMediaViewerV1alpha3921\ch\TrustMediaViewerV1alpha3921.crx[]
mchgekplgpbgbalnlnajnepeninajado - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode8294\ch\MediaBuzzV1mode8294.crx[]
ogoiliccpcefgmiafhjcoagnmkddagof - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release705\ch\RichMediaViewV1release705.crx[]
ojofdhpfcjmjpgnolamolmihoompckbm - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1587\ch\MediaViewerV1alpha1587.crx[]
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://start.qone8.com/?type=hp&ts=1383 ... 117JJEVBEX"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{EFD90A5C-C40F-45D9-92AB-A3DAE671237A} Bing Url="http://www.bing.com/search?q={searchTer ... -SearchBox"
{F5D99D81-EA76-435F-B064-F6A5D55306DA} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_16194"
==== Reset Google Chrome ======================
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\caphpmfackmpbchefdbohpjkjgekpcgo deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\emfiolpndjiobhaigieckjhchlocadbm deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\janpofkchcegjcafimgongjdcgmikipg deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jggifkmlclgncoggjhcijfafadgcoamn deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jjokaddkhgfbfcmlaehgcddgalighpln deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kadgahhelapmhhjnmhnmnojfcnlhhoij deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lpemnobkfgfknkoaelaidcodbmaapemm deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\mchgekplgpbgbalnlnajnepeninajado deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ogoiliccpcefgmiafhjcoagnmkddagof deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ojofdhpfcjmjpgnolamolmihoompckbm deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisorDock deleted successfully
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
No FireFox Profiles found
==== Empty Chrome Cache ======================
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=359 folders=6 388874 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Jirka\AppData\Local\Temp will be emptied at reboot
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\Jirka\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\PROGRA~3\boost_interprocess" not found
==== EOF on źt 06.11.2014 at 11:27:32,93 ======================
Re: Prosím o kontrolu logu
Nainstalujte MBAM a pouzijte vlastni sken na kontrolu vsech disku - http://forum.viry.cz/viewtopic.php?f=29&t=137928
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Přidávám log z MBAM
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 6.11.2014
Čas skenování: 12:47:02
Protokol:
Správce: Ano
Verze: 2.00.3.1025
Databáze malwaru: v2014.11.06.05
Databáze rootkitů: v2014.11.01.02
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Sebeobrany: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Jirka
Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 463065
Uplynulý čas: 1 hod, 37 min, 5 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Žádné zákerné zjištěny položek)
Moduly: 0
(Žádné zákerné zjištěny položek)
Klíče registru: 9
PUP.Optional.MediaBuzz.A, HKLM\SOFTWARE\WOW6432NODE\MediaBuzzV1mode8294, Do karantény, [2b6248f08bf18bab141667ec0ef530d0],
PUP.Optional.MediaPlayerAlpha.A, HKLM\SOFTWARE\WOW6432NODE\MediaPlayerV1alpha351, Do karantény, [eba2ff39ea922f0778b5d98b0cf7af51],
PUP.Optional.MediaViewer.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewerV1alpha1587, Do karantény, [414c48f09ddf0c2a2382bba46d967b85],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewV1alpha1481, Do karantény, [48452315cdaf55e1a35aa1bd38cbd22e],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewV1alpha3668, Do karantény, [f9941127156737ff6697332b4ab9de22],
PUP.Optional.MediaWatch.A, HKLM\SOFTWARE\WOW6432NODE\MediaWatchV1home1, Do karantény, [eba29b9db2ca3afc7c9f395e2cd8fa06],
PUP.Optional.RichMediaView.A, HKLM\SOFTWARE\WOW6432NODE\RichMediaViewV1release3516, Do karantény, [414c43f5a0dc82b42c31a8a5ac57758b],
PUP.Optional.RichMediaView.A, HKLM\SOFTWARE\WOW6432NODE\RichMediaViewV1release705, Do karantény, [7914f4447efedd59d48960ed50b3916f],
PUP.Optional.TrustMediaViewer.A, HKLM\SOFTWARE\WOW6432NODE\TrustMediaViewerV1alpha3921, Do karantény, [a8e515237dff4ee8750d2220a95ab24e],
Hodnoty registru: 0
(Žádné zákerné zjištěny položek)
Data registru: 0
(Žádné zákerné zjištěny položek)
Složky: 0
(Žádné zákerné zjištěny položek)
Soubory: 0
(Žádné zákerné zjištěny položek)
Fyzické sektory: 0
(Žádné zákerné zjištěny položek)
(end)
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 6.11.2014
Čas skenování: 12:47:02
Protokol:
Správce: Ano
Verze: 2.00.3.1025
Databáze malwaru: v2014.11.06.05
Databáze rootkitů: v2014.11.01.02
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Sebeobrany: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Jirka
Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 463065
Uplynulý čas: 1 hod, 37 min, 5 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Žádné zákerné zjištěny položek)
Moduly: 0
(Žádné zákerné zjištěny položek)
Klíče registru: 9
PUP.Optional.MediaBuzz.A, HKLM\SOFTWARE\WOW6432NODE\MediaBuzzV1mode8294, Do karantény, [2b6248f08bf18bab141667ec0ef530d0],
PUP.Optional.MediaPlayerAlpha.A, HKLM\SOFTWARE\WOW6432NODE\MediaPlayerV1alpha351, Do karantény, [eba2ff39ea922f0778b5d98b0cf7af51],
PUP.Optional.MediaViewer.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewerV1alpha1587, Do karantény, [414c48f09ddf0c2a2382bba46d967b85],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewV1alpha1481, Do karantény, [48452315cdaf55e1a35aa1bd38cbd22e],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewV1alpha3668, Do karantény, [f9941127156737ff6697332b4ab9de22],
PUP.Optional.MediaWatch.A, HKLM\SOFTWARE\WOW6432NODE\MediaWatchV1home1, Do karantény, [eba29b9db2ca3afc7c9f395e2cd8fa06],
PUP.Optional.RichMediaView.A, HKLM\SOFTWARE\WOW6432NODE\RichMediaViewV1release3516, Do karantény, [414c43f5a0dc82b42c31a8a5ac57758b],
PUP.Optional.RichMediaView.A, HKLM\SOFTWARE\WOW6432NODE\RichMediaViewV1release705, Do karantény, [7914f4447efedd59d48960ed50b3916f],
PUP.Optional.TrustMediaViewer.A, HKLM\SOFTWARE\WOW6432NODE\TrustMediaViewerV1alpha3921, Do karantény, [a8e515237dff4ee8750d2220a95ab24e],
Hodnoty registru: 0
(Žádné zákerné zjištěny položek)
Data registru: 0
(Žádné zákerné zjištěny položek)
Složky: 0
(Žádné zákerné zjištěny položek)
Soubory: 0
(Žádné zákerné zjištěny položek)
Fyzické sektory: 0
(Žádné zákerné zjištěny položek)
(end)
Re: Prosím o kontrolu logu
Vsechny nalezy smazte/presunte do karanteny.
Dejte log FRST, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=13&t=133100
Dejte log FRST, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=13&t=133100
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-11-2014
Ran by Jirka (administrator) on JIRKA-HP on 06-11-2014 18:28:18
Running from C:\Users\Jirka\Desktop
Loaded Profile: Jirka (Available profiles: Jirka)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\stacsv64.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\AESTSr64.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\audiosrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-29] (IDT, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595336 2014-10-01] (ESET)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2010-01-12] (PDF Complete Inc)
HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-01-22] (Hewlett-Packard Company)
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\MountPoints2: {d8c5e845-3de4-11e1-88e6-806e6f6e6963} - D:\start.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [301568 2013-03-20] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {F5D99D81-EA76-435F-B064-F6A5D55306DA} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 172.16.42.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR DefaultSearchKeyword: Default -> seznam.cz
CHR DefaultSearchURL: Default -> http://search.seznam.cz/?q={searchTerms}
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Profile: C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-29]
CHR Extension: (Dokumenty Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-30]
CHR Extension: (Disk Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-29]
CHR Extension: (YouTube) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-29]
CHR Extension: (Vyhledávání Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-29]
CHR Extension: (Tabulky Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-29]
CHR Extension: (Peněženka Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-29]
CHR Extension: (Gmail) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-29]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1349576 2014-10-01] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2010-10-06] (Macrovision Europe Ltd.) [File not signed]
R3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1028096 2010-10-06] (Macrovision Europe Ltd.) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4233088 2013-04-29] (Symantec Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2010-01-12] (PDF Complete Inc)
R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\STacSV64.exe [244736 2010-01-29] (IDT, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [241368 2014-10-10] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1803904 2010-04-27] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 11:47 - 2014-11-06 12:47 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-06 11:45 - 2014-11-06 11:45 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-06 11:45 - 2014-11-06 11:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-06 11:45 - 2014-11-06 11:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-06 11:45 - 2014-11-06 11:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-06 11:45 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-11-06 11:45 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-11-06 11:45 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-11-06 11:41 - 2014-11-06 11:42 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Jirka\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-06 11:29 - 2014-11-06 12:45 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-11-06 11:14 - 2014-11-06 10:57 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-11-06 10:57 - 2014-11-06 11:27 - 00027367 _____ () C:\zoek-results.log
2014-11-06 10:57 - 2014-11-06 11:11 - 00000000 ____D () C:\zoek_backup
2014-11-06 10:55 - 2014-11-06 10:55 - 01292800 _____ () C:\Users\Jirka\Desktop\zoek.exe
2014-11-06 10:54 - 2014-11-06 10:55 - 00000000 ____D () C:\Users\Jirka\Downloads\zoek
2014-11-06 10:54 - 2014-11-06 10:54 - 04123237 _____ () C:\Users\Jirka\Downloads\zoek.zip
2014-11-06 00:39 - 2014-11-06 00:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-11-06 00:39 - 2014-11-06 00:39 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-11-06 00:38 - 2014-11-06 00:38 - 01110476 _____ () C:\Users\Jirka\Downloads\7zip+Setup.exe
2014-11-06 00:29 - 2014-11-06 18:28 - 00012190 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-11-06 00:29 - 2014-11-06 18:28 - 00000000 ____D () C:\FRST
2014-11-06 00:27 - 2014-11-06 00:27 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-11-06 00:26 - 2014-11-06 00:26 - 02114560 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2014-11-06 00:05 - 2014-11-06 00:05 - 00896048 _____ () C:\Users\Jirka\Downloads\Norton_Removal_Tool.exe
2014-11-06 00:05 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2014-11-06 00:05 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-11-06 00:05 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-11-06 00:05 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2014-11-06 00:05 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2014-11-06 00:05 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-11-06 00:05 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2014-11-06 00:05 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-11-06 00:05 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2014-11-06 00:05 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2014-11-06 00:05 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-11-06 00:05 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2014-11-06 00:05 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2014-11-06 00:05 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-11-06 00:05 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2014-11-06 00:05 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-11-06 00:05 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-11-06 00:05 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-11-06 00:03 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2014-11-06 00:03 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2014-11-06 00:03 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2014-11-06 00:03 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2014-11-06 00:03 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2014-11-06 00:03 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-11-05 23:59 - 2014-11-06 00:02 - 00000000 ____D () C:\windows\system32\MRT
2014-11-05 23:59 - 2014-10-03 10:02 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-11-05 22:14 - 2014-10-28 05:34 - 00275080 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-11-05 22:01 - 2014-11-05 22:01 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\ESET
2014-11-05 22:01 - 2014-11-05 22:01 - 00000000 ____D () C:\Users\Jirka\AppData\Local\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\ProgramData\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\Program Files\ESET
2014-11-05 21:48 - 2010-02-10 15:09 - 00000384 _____ () C:\windows\myClean.bat
2014-11-05 21:24 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-11-05 21:23 - 2014-11-05 21:25 - 00000000 ____D () C:\AdwCleaner
2014-11-05 21:22 - 2014-11-05 21:21 - 01375089 _____ () C:\Users\Jirka\Desktop\adwcleaner_3.311.exe
2014-11-05 21:21 - 2014-11-05 21:21 - 01375089 _____ () C:\Users\Jirka\Downloads\adwcleaner_3.311.exe
2014-11-05 21:09 - 2014-11-05 21:09 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Mozilla
2014-11-05 20:44 - 2014-11-05 20:44 - 01660616 _____ (ESET) C:\Users\Jirka\Downloads\eset_smart_security_live_installer_.exe
2014-10-29 12:28 - 2014-10-29 12:28 - 00002259 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-29 12:28 - 2014-10-29 12:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-10-29 12:27 - 2014-11-06 18:23 - 00000950 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-29 12:27 - 2014-11-06 12:43 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-29 12:27 - 2014-10-29 12:27 - 00003946 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-29 12:27 - 2014-10-29 12:27 - 00003694 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-29 12:23 - 2014-10-29 12:23 - 00000000 __SHD () C:\Users\Jirka\AppData\Local\EmieUserList
2014-10-29 12:23 - 2014-10-29 12:23 - 00000000 __SHD () C:\Users\Jirka\AppData\Local\EmieSiteList
2014-10-15 20:54 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-15 20:54 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-15 20:54 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-15 20:54 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-15 20:54 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-15 20:54 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-15 20:54 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-15 20:54 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-10-15 20:54 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-10-15 20:54 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-15 20:54 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-15 20:54 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-15 20:54 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-10-15 20:54 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-10-15 20:54 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-15 20:54 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-15 20:54 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-10-15 20:54 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-10-15 20:54 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-10-15 20:54 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-10-15 20:54 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-15 20:54 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-15 20:54 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-10-15 20:54 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-15 20:54 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-10-15 20:54 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-10-15 20:54 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 20:54 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-10-15 20:54 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-15 20:54 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-15 20:54 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-15 20:54 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-15 20:54 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-10-15 20:54 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-10-15 20:54 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-10-15 20:54 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-10-15 20:54 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-10-15 20:54 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-15 20:54 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-15 20:54 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-10-15 20:54 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 20:54 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-15 20:54 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-10-15 20:54 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-15 20:54 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-10-15 20:54 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-15 20:54 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-15 20:54 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-15 20:54 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-15 20:54 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-15 20:30 - 2014-08-19 04:11 - 00693176 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2014-10-15 20:30 - 2014-08-19 04:10 - 00616352 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2014-10-15 20:30 - 2014-08-19 04:08 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2014-10-15 20:30 - 2014-08-19 04:08 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2014-10-15 20:30 - 2014-08-19 04:08 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2014-10-15 20:30 - 2014-08-19 04:07 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2014-10-15 20:30 - 2014-08-19 04:07 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2014-10-15 20:30 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2014-10-15 20:30 - 2014-08-19 03:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2014-10-15 20:30 - 2014-08-19 03:06 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2014-10-15 20:30 - 2014-07-07 03:07 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2014-10-15 20:30 - 2014-07-07 03:07 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2014-10-15 20:30 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 05551032 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 04120576 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01574400 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01069056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00188416 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2014-10-15 20:30 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2014-10-15 20:30 - 2014-07-07 03:05 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2014-10-15 20:30 - 2014-07-07 03:05 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2014-10-15 20:30 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2014-10-15 20:30 - 2014-07-07 02:52 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2014-10-15 20:30 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2014-10-15 20:30 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2014-10-15 20:30 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2014-10-15 20:30 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2014-10-15 20:30 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2014-10-15 20:30 - 2014-06-28 01:21 - 00619056 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2014-10-15 20:30 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2014-10-15 20:30 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2014-10-15 20:25 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-15 20:25 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2014-10-15 20:20 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-10-15 20:20 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2014-10-15 20:20 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-10-15 20:15 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2014-10-15 20:15 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2014-10-15 20:15 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-15 20:15 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-10-15 20:15 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-10-15 20:15 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2014-10-15 20:15 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-10-15 20:15 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-10-15 20:15 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2014-10-15 20:15 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2014-10-15 20:14 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-15 20:14 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2014-10-10 08:59 - 2014-10-10 08:59 - 00243440 _____ (ESET) C:\windows\system32\Drivers\eamonm.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00241368 _____ (ESET) C:\windows\system32\Drivers\edevmon.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00222280 _____ (ESET) C:\windows\system32\Drivers\epfw.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00169280 _____ (ESET) C:\windows\system32\Drivers\ehdrv.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00063160 _____ (ESET) C:\windows\system32\Drivers\epfwwfp.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00044632 _____ (ESET) C:\windows\system32\Drivers\EpfwLWF.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 18:23 - 2011-02-28 16:46 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForJirka
2014-11-06 18:23 - 2011-02-28 16:46 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForJirka.job
2014-11-06 16:50 - 2011-02-25 18:28 - 00000000 ____D () C:\windows\rescache
2014-11-06 12:50 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 12:50 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 12:45 - 2010-10-06 00:20 - 01204768 _____ () C:\windows\WindowsUpdate.log
2014-11-06 12:42 - 2010-09-09 22:57 - 00927012 _____ () C:\windows\PFRO.log
2014-11-06 12:42 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-11-06 12:42 - 2009-07-14 05:51 - 00256386 _____ () C:\windows\setupact.log
2014-11-06 11:26 - 2014-01-29 16:43 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-11-06 11:11 - 2009-07-14 04:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-11-06 11:11 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-11-06 00:38 - 2011-02-25 10:39 - 00000000 ____D () C:\ProgramData\WinZip
2014-11-06 00:20 - 2011-02-25 10:48 - 00058016 _____ () C:\Users\Jirka\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-06 00:19 - 2009-07-14 05:45 - 00268800 _____ () C:\windows\system32\FNTCACHE.DAT
2014-11-06 00:17 - 2012-05-16 15:52 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Skype
2014-11-06 00:09 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-06 00:07 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-11-06 00:06 - 2011-03-03 14:32 - 00000000 ____D () C:\ProgramData\Norton
2014-11-06 00:06 - 2010-10-06 00:22 - 00008391 _____ () C:\windows\system32\RaCoInst.log
2014-11-05 23:35 - 2013-11-02 17:59 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Seznam.cz
2014-11-05 21:54 - 2010-09-09 22:51 - 00000000 ____D () C:\Program Files\Common Files\McAfee
2014-11-05 21:51 - 2011-02-25 10:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
2014-11-05 21:40 - 2010-09-09 21:56 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-11-05 21:33 - 2011-02-28 17:05 - 00000000 ____D () C:\Program Files\DivX
2014-11-05 21:33 - 2011-02-28 17:02 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-11-05 21:33 - 2011-02-28 16:58 - 00000000 ____D () C:\ProgramData\DivX
2014-11-05 21:25 - 2011-02-25 10:47 - 00000969 _____ () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-05 21:11 - 2010-09-09 22:52 - 00008727 _____ () C:\windows\system32\Config.MPF
2014-11-05 20:51 - 2010-09-09 22:18 - 00669576 _____ () C:\windows\system32\perfh005.dat
2014-11-05 20:51 - 2010-09-09 22:18 - 00141946 _____ () C:\windows\system32\perfc005.dat
2014-11-05 20:51 - 2009-07-14 06:13 - 01586138 _____ () C:\windows\system32\PerfStringBackup.INI
2014-11-03 01:53 - 2011-04-08 07:58 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\SoftGrid Client
2014-11-02 20:44 - 2013-04-12 13:02 - 00010590 _____ () C:\Users\Jirka\Desktop\debug.log
2014-10-29 12:28 - 2013-11-02 18:27 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-29 12:27 - 2011-02-28 16:45 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Deployment
2014-10-28 19:55 - 2009-07-14 06:08 - 00032568 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-10-16 05:47 - 2009-07-14 06:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2014-10-16 05:43 - 2014-05-06 10:41 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-10-16 05:43 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2014-10-16 05:43 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\Dism
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForJirka.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Jirka\Desktop" je 3031 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackup
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Ran by Jirka (administrator) on JIRKA-HP on 06-11-2014 18:28:18
Running from C:\Users\Jirka\Desktop
Loaded Profile: Jirka (Available profiles: Jirka)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\stacsv64.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\AESTSr64.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Macrovision Europe Ltd.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\audiosrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Motorola, Inc.) C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
() C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Service.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2010-01-08] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2174760 2010-06-04] (Synaptics Incorporated)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-01-29] (IDT, Inc.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595336 2014-10-01] (ESET)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [563736 2010-01-12] (PDF Complete Inc)
HKLM-x32\...\Run: [WirelessAssistant] => C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [499768 2009-09-01] (Hewlett-Packard)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\Run: [LightScribe Control Panel] => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-01-22] (Hewlett-Packard Company)
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\MountPoints2: {d8c5e845-3de4-11e1-88e6-806e6f6e6963} - D:\start.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\windows\System32\SPReview\SPReview.exe [301568 2013-03-20] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {F5D99D81-EA76-435F-B064-F6A5D55306DA} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 172.16.42.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR DefaultSearchKeyword: Default -> seznam.cz
CHR DefaultSearchURL: Default -> http://search.seznam.cz/?q={searchTerms}
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Profile: C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-29]
CHR Extension: (Dokumenty Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-06-30]
CHR Extension: (Disk Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-29]
CHR Extension: (YouTube) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-29]
CHR Extension: (Vyhledávání Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-29]
CHR Extension: (Tabulky Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-29]
CHR Extension: (Peněženka Google) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-29]
CHR Extension: (Gmail) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-29]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1349576 2014-10-01] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2010-10-06] (Macrovision Europe Ltd.) [File not signed]
R3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1028096 2010-10-06] (Macrovision Europe Ltd.) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2010-01-22] (Hewlett-Packard Company) [File not signed]
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4233088 2013-04-29] (Symantec Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [635416 2010-01-12] (PDF Complete Inc)
R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_21dba265e7e67cda\STacSV64.exe [244736 2010-01-29] (IDT, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [241368 2014-10-10] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1803904 2010-04-27] ()
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 11:47 - 2014-11-06 12:47 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-06 11:45 - 2014-11-06 11:45 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-06 11:45 - 2014-11-06 11:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-06 11:45 - 2014-11-06 11:45 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-06 11:45 - 2014-11-06 11:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-06 11:45 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-11-06 11:45 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-11-06 11:45 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-11-06 11:41 - 2014-11-06 11:42 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Jirka\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-06 11:29 - 2014-11-06 12:45 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-11-06 11:14 - 2014-11-06 10:57 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-11-06 10:57 - 2014-11-06 11:27 - 00027367 _____ () C:\zoek-results.log
2014-11-06 10:57 - 2014-11-06 11:11 - 00000000 ____D () C:\zoek_backup
2014-11-06 10:55 - 2014-11-06 10:55 - 01292800 _____ () C:\Users\Jirka\Desktop\zoek.exe
2014-11-06 10:54 - 2014-11-06 10:55 - 00000000 ____D () C:\Users\Jirka\Downloads\zoek
2014-11-06 10:54 - 2014-11-06 10:54 - 04123237 _____ () C:\Users\Jirka\Downloads\zoek.zip
2014-11-06 00:39 - 2014-11-06 00:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-11-06 00:39 - 2014-11-06 00:39 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-11-06 00:38 - 2014-11-06 00:38 - 01110476 _____ () C:\Users\Jirka\Downloads\7zip+Setup.exe
2014-11-06 00:29 - 2014-11-06 18:28 - 00012190 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-11-06 00:29 - 2014-11-06 18:28 - 00000000 ____D () C:\FRST
2014-11-06 00:27 - 2014-11-06 00:27 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-11-06 00:26 - 2014-11-06 00:26 - 02114560 _____ (Farbar) C:\Users\Jirka\Desktop\FRST64.exe
2014-11-06 00:05 - 2014-11-06 00:05 - 00896048 _____ () C:\Users\Jirka\Downloads\Norton_Removal_Tool.exe
2014-11-06 00:05 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\Drivers\TsUsbFlt.sys
2014-11-06 00:05 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-11-06 00:05 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-11-06 00:05 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\windows\system32\MsRdpWebAccess.dll
2014-11-06 00:05 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\windows\system32\wksprtPS.dll
2014-11-06 00:05 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\windows\system32\tsgqec.dll
2014-11-06 00:05 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\windows\system32\TsUsbGDCoInstaller.dll
2014-11-06 00:05 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2014-11-06 00:05 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\MsRdpWebAccess.dll
2014-11-06 00:05 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wksprtPS.dll
2014-11-06 00:05 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2014-11-06 00:05 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\windows\system32\wksprt.exe
2014-11-06 00:05 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\tsgqec.dll
2014-11-06 00:05 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-11-06 00:05 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2014-11-06 00:05 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-11-06 00:05 - 2013-10-01 21:57 - 06578176 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-11-06 00:05 - 2013-10-01 21:55 - 05698048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-11-06 00:03 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2014-11-06 00:03 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpvideominiport.sys
2014-11-06 00:03 - 2012-08-23 14:24 - 00015360 _____ (Microsoft Corporation) C:\windows\system32\RdpGroupPolicyExtension.dll
2014-11-06 00:03 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdpendp_winip.dll
2014-11-06 00:03 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\rdpendp_winip.dll
2014-11-06 00:03 - 2012-08-23 10:51 - 03174912 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-11-05 23:59 - 2014-11-06 00:02 - 00000000 ____D () C:\windows\system32\MRT
2014-11-05 23:59 - 2014-10-03 10:02 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-11-05 22:14 - 2014-10-28 05:34 - 00275080 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-11-05 22:01 - 2014-11-05 22:01 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\ESET
2014-11-05 22:01 - 2014-11-05 22:01 - 00000000 ____D () C:\Users\Jirka\AppData\Local\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\ProgramData\ESET
2014-11-05 21:59 - 2014-11-05 21:59 - 00000000 ____D () C:\Program Files\ESET
2014-11-05 21:48 - 2010-02-10 15:09 - 00000384 _____ () C:\windows\myClean.bat
2014-11-05 21:24 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-11-05 21:23 - 2014-11-05 21:25 - 00000000 ____D () C:\AdwCleaner
2014-11-05 21:22 - 2014-11-05 21:21 - 01375089 _____ () C:\Users\Jirka\Desktop\adwcleaner_3.311.exe
2014-11-05 21:21 - 2014-11-05 21:21 - 01375089 _____ () C:\Users\Jirka\Downloads\adwcleaner_3.311.exe
2014-11-05 21:09 - 2014-11-05 21:09 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Mozilla
2014-11-05 20:44 - 2014-11-05 20:44 - 01660616 _____ (ESET) C:\Users\Jirka\Downloads\eset_smart_security_live_installer_.exe
2014-10-29 12:28 - 2014-10-29 12:28 - 00002259 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-10-29 12:28 - 2014-10-29 12:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-10-29 12:27 - 2014-11-06 18:23 - 00000950 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-29 12:27 - 2014-11-06 12:43 - 00000946 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-29 12:27 - 2014-10-29 12:27 - 00003946 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-29 12:27 - 2014-10-29 12:27 - 00003694 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-29 12:23 - 2014-10-29 12:23 - 00000000 __SHD () C:\Users\Jirka\AppData\Local\EmieUserList
2014-10-29 12:23 - 2014-10-29 12:23 - 00000000 __SHD () C:\Users\Jirka\AppData\Local\EmieSiteList
2014-10-15 20:54 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-15 20:54 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-15 20:54 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-15 20:54 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-15 20:54 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-15 20:54 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-15 20:54 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-15 20:54 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-15 20:54 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-10-15 20:54 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-10-15 20:54 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-15 20:54 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-15 20:54 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-15 20:54 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-10-15 20:54 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-10-15 20:54 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-15 20:54 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-15 20:54 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-10-15 20:54 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-10-15 20:54 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-10-15 20:54 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-10-15 20:54 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-15 20:54 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-15 20:54 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-10-15 20:54 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-15 20:54 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-10-15 20:54 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-10-15 20:54 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 20:54 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-10-15 20:54 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-10-15 20:54 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-15 20:54 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-15 20:54 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-15 20:54 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-15 20:54 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-10-15 20:54 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-10-15 20:54 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-10-15 20:54 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-10-15 20:54 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-10-15 20:54 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-15 20:54 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-15 20:54 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-10-15 20:54 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 20:54 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-15 20:54 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-10-15 20:54 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-15 20:54 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-10-15 20:54 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-15 20:54 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-15 20:54 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-15 20:54 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-15 20:54 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-15 20:30 - 2014-08-19 04:11 - 00693176 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2014-10-15 20:30 - 2014-08-19 04:10 - 00616352 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2014-10-15 20:30 - 2014-08-19 04:08 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2014-10-15 20:30 - 2014-08-19 04:08 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2014-10-15 20:30 - 2014-08-19 04:08 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2014-10-15 20:30 - 2014-08-19 04:07 - 00146944 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2014-10-15 20:30 - 2014-08-19 04:07 - 00058880 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00032256 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2014-10-15 20:30 - 2014-08-19 04:07 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2014-10-15 20:30 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2014-10-15 20:30 - 2014-08-19 03:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2014-10-15 20:30 - 2014-08-19 03:06 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2014-10-15 20:30 - 2014-07-07 03:07 - 14632960 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2014-10-15 20:30 - 2014-07-07 03:07 - 00782848 _____ (Microsoft Corporation) C:\windows\system32\wmdrmsdk.dll
2014-10-15 20:30 - 2014-07-07 03:07 - 00229376 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 05551032 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 04120576 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01574400 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01480192 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01202176 _____ (Microsoft Corporation) C:\windows\system32\drmv2clt.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 01069056 _____ (Microsoft Corporation) C:\windows\system32\cryptui.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00842240 _____ (Microsoft Corporation) C:\windows\system32\blackbox.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00641024 _____ (Microsoft Corporation) C:\windows\system32\msscp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00631808 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00500224 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00497664 _____ (Microsoft Corporation) C:\windows\system32\drmmgrtn.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\AudioEng.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00325632 _____ (Microsoft Corporation) C:\windows\system32\msnetobj.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00296448 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\EncDump.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00188416 _____ (Microsoft Corporation) C:\windows\system32\pcasvc.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00187904 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00082432 _____ (Microsoft Corporation) C:\windows\system32\cryptsp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2014-10-15 20:30 - 2014-07-07 03:06 - 00009728 _____ (Microsoft Corporation) C:\windows\system32\spwmp.dll
2014-10-15 20:30 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\msdxm.ocx
2014-10-15 20:30 - 2014-07-07 03:06 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\dxmasf.dll
2014-10-15 20:30 - 2014-07-07 03:05 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2014-10-15 20:30 - 2014-07-07 03:05 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2014-10-15 20:30 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2014-10-15 20:30 - 2014-07-07 02:52 - 00663552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\PEAuth.sys
2014-10-15 20:30 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptui.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmv2clt.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\windows\SysWOW64\blackbox.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmdrmsdk.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msscp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\windows\SysWOW64\AUDIOKSE.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\windows\SysWOW64\drmmgrtn.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioEng.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msnetobj.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\windows\SysWOW64\AudioSes.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\windows\SysWOW64\spwmp.dll
2014-10-15 20:30 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdxm.ocx
2014-10-15 20:30 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxmasf.dll
2014-10-15 20:30 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2014-10-15 20:30 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2014-10-15 20:30 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2014-10-15 20:30 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2014-10-15 20:30 - 2014-06-28 01:21 - 00619056 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2014-10-15 20:30 - 2014-06-28 01:21 - 00532176 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2014-10-15 20:30 - 2014-06-28 01:21 - 00457400 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2014-10-15 20:25 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-15 20:25 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2014-10-15 20:25 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2014-10-15 20:20 - 2014-10-10 03:05 - 00507392 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-10-15 20:20 - 2014-10-10 03:05 - 00276480 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2014-10-15 20:20 - 2014-10-10 03:00 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-10-15 20:15 - 2014-09-18 03:00 - 03241472 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2014-10-15 20:15 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2014-10-15 20:15 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-15 20:15 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-10-15 20:15 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-10-15 20:15 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-10-15 20:15 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2014-10-15 20:15 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-10-15 20:15 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-10-15 20:15 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2014-10-15 20:15 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2014-10-15 20:14 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-15 20:14 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
2014-10-10 08:59 - 2014-10-10 08:59 - 00243440 _____ (ESET) C:\windows\system32\Drivers\eamonm.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00241368 _____ (ESET) C:\windows\system32\Drivers\edevmon.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00222280 _____ (ESET) C:\windows\system32\Drivers\epfw.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00169280 _____ (ESET) C:\windows\system32\Drivers\ehdrv.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00063160 _____ (ESET) C:\windows\system32\Drivers\epfwwfp.sys
2014-10-10 08:59 - 2014-10-10 08:59 - 00044632 _____ (ESET) C:\windows\system32\Drivers\EpfwLWF.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 18:23 - 2011-02-28 16:46 - 00003186 _____ () C:\windows\System32\Tasks\HPCeeScheduleForJirka
2014-11-06 18:23 - 2011-02-28 16:46 - 00000332 _____ () C:\windows\Tasks\HPCeeScheduleForJirka.job
2014-11-06 16:50 - 2011-02-25 18:28 - 00000000 ____D () C:\windows\rescache
2014-11-06 12:50 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 12:50 - 2009-07-14 05:45 - 00022704 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 12:45 - 2010-10-06 00:20 - 01204768 _____ () C:\windows\WindowsUpdate.log
2014-11-06 12:42 - 2010-09-09 22:57 - 00927012 _____ () C:\windows\PFRO.log
2014-11-06 12:42 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-11-06 12:42 - 2009-07-14 05:51 - 00256386 _____ () C:\windows\setupact.log
2014-11-06 11:26 - 2014-01-29 16:43 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-11-06 11:11 - 2009-07-14 04:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-11-06 11:11 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-11-06 00:38 - 2011-02-25 10:39 - 00000000 ____D () C:\ProgramData\WinZip
2014-11-06 00:20 - 2011-02-25 10:48 - 00058016 _____ () C:\Users\Jirka\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-06 00:19 - 2009-07-14 05:45 - 00268800 _____ () C:\windows\system32\FNTCACHE.DAT
2014-11-06 00:17 - 2012-05-16 15:52 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Skype
2014-11-06 00:09 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-06 00:07 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-11-06 00:06 - 2011-03-03 14:32 - 00000000 ____D () C:\ProgramData\Norton
2014-11-06 00:06 - 2010-10-06 00:22 - 00008391 _____ () C:\windows\system32\RaCoInst.log
2014-11-05 23:35 - 2013-11-02 17:59 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Seznam.cz
2014-11-05 21:54 - 2010-09-09 22:51 - 00000000 ____D () C:\Program Files\Common Files\McAfee
2014-11-05 21:51 - 2011-02-25 10:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Online Backup
2014-11-05 21:40 - 2010-09-09 21:56 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard
2014-11-05 21:33 - 2011-02-28 17:05 - 00000000 ____D () C:\Program Files\DivX
2014-11-05 21:33 - 2011-02-28 17:02 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-11-05 21:33 - 2011-02-28 16:58 - 00000000 ____D () C:\ProgramData\DivX
2014-11-05 21:25 - 2011-02-25 10:47 - 00000969 _____ () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-05 21:11 - 2010-09-09 22:52 - 00008727 _____ () C:\windows\system32\Config.MPF
2014-11-05 20:51 - 2010-09-09 22:18 - 00669576 _____ () C:\windows\system32\perfh005.dat
2014-11-05 20:51 - 2010-09-09 22:18 - 00141946 _____ () C:\windows\system32\perfc005.dat
2014-11-05 20:51 - 2009-07-14 06:13 - 01586138 _____ () C:\windows\system32\PerfStringBackup.INI
2014-11-03 01:53 - 2011-04-08 07:58 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\SoftGrid Client
2014-11-02 20:44 - 2013-04-12 13:02 - 00010590 _____ () C:\Users\Jirka\Desktop\debug.log
2014-10-29 12:28 - 2013-11-02 18:27 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-29 12:27 - 2011-02-28 16:45 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Deployment
2014-10-28 19:55 - 2009-07-14 06:08 - 00032568 _____ () C:\windows\Tasks\SCHEDLGU.TXT
2014-10-16 05:47 - 2009-07-14 06:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD
2014-10-16 05:43 - 2014-05-06 10:41 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-10-16 05:43 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\Dism
2014-10-16 05:43 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\Dism
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForJirka.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Jirka\Desktop" je 3031 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackup
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
- Přílohy
-
- Addition.zip
- (4.8 KiB) Staženo 57 x
Re: Prosím o kontrolu logu



- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu na Vas vyskoci fixlog, jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\MountPoints2: {d8c5e845-3de4-11e1-88e6-806e6f6e6963} - D:\start.exe FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File CHR DefaultSearchURL: Default -> http://search.seznam.cz/?q={searchTerms} CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fulltext_ff?phrase={searchTerms} 2014-11-06 11:14 - 2014-11-06 10:57 - 00024064 _____ () C:\windows\zoek-delete.exe 2014-11-06 10:57 - 2014-11-06 11:27 - 00027367 _____ () C:\zoek-results.log 2014-11-06 10:57 - 2014-11-06 11:11 - 00000000 ____D () C:\zoek_backup 2014-11-06 10:55 - 2014-11-06 10:55 - 01292800 _____ () C:\Users\Jirka\Desktop\zoek.exe 2014-11-06 10:54 - 2014-11-06 10:55 - 00000000 ____D () C:\Users\Jirka\Downloads\zoek 2014-11-06 10:54 - 2014-11-06 10:54 - 04123237 _____ () C:\Users\Jirka\Downloads\zoek.zip 2014-11-06 00:05 - 2014-11-06 00:05 - 00896048 _____ () C:\Users\Jirka\Downloads\Norton_Removal_Tool.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\HPCeeScheduleForJirka.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackup" /f Hosts: EmptyTemp: End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-11-2014
Ran by Jirka at 2014-11-06 19:27:04 Run:1
Running from C:\Users\Jirka\Desktop
Loaded Profile: Jirka (Available profiles: Jirka)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\MountPoints2: {d8c5e845-3de4-11e1-88e6-806e6f6e6963} - D:\start.exe
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
CHR DefaultSearchURL: Default -> http://search.seznam.cz/?q={searchTerms}
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
2014-11-06 11:14 - 2014-11-06 10:57 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-11-06 10:57 - 2014-11-06 11:27 - 00027367 _____ () C:\zoek-results.log
2014-11-06 10:57 - 2014-11-06 11:11 - 00000000 ____D () C:\zoek_backup
2014-11-06 10:55 - 2014-11-06 10:55 - 01292800 _____ () C:\Users\Jirka\Desktop\zoek.exe
2014-11-06 10:54 - 2014-11-06 10:55 - 00000000 ____D () C:\Users\Jirka\Downloads\zoek
2014-11-06 10:54 - 2014-11-06 10:54 - 04123237 _____ () C:\Users\Jirka\Downloads\zoek.zip
2014-11-06 00:05 - 2014-11-06 00:05 - 00896048 _____ () C:\Users\Jirka\Downloads\Norton_Removal_Tool.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForJirka.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackup" /f
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
"HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8c5e845-3de4-11e1-88e6-806e6f6e6963}" => Key deleted successfully.
"HKCR\CLSID\{d8c5e845-3de4-11e1-88e6-806e6f6e6963}" => Key not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
Chrome DefaultSearchURL deleted successfully.
Chrome DefaultSuggestURL deleted successfully.
C:\windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Jirka\Desktop\zoek.exe => Moved successfully.
C:\Users\Jirka\Downloads\zoek => Moved successfully.
C:\Users\Jirka\Downloads\zoek.zip => Moved successfully.
C:\Users\Jirka\Downloads\Norton_Removal_Tool.exe => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\windows\Tasks\HPCeeScheduleForJirka.job => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 48.1 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Ran by Jirka at 2014-11-06 19:27:04 Run:1
Running from C:\Users\Jirka\Desktop
Loaded Profile: Jirka (Available profiles: Jirka)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\...\MountPoints2: {d8c5e845-3de4-11e1-88e6-806e6f6e6963} - D:\start.exe
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
CHR DefaultSearchURL: Default -> http://search.seznam.cz/?q={searchTerms}
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
2014-11-06 11:14 - 2014-11-06 10:57 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-11-06 10:57 - 2014-11-06 11:27 - 00027367 _____ () C:\zoek-results.log
2014-11-06 10:57 - 2014-11-06 11:11 - 00000000 ____D () C:\zoek_backup
2014-11-06 10:55 - 2014-11-06 10:55 - 01292800 _____ () C:\Users\Jirka\Desktop\zoek.exe
2014-11-06 10:54 - 2014-11-06 10:55 - 00000000 ____D () C:\Users\Jirka\Downloads\zoek
2014-11-06 10:54 - 2014-11-06 10:54 - 04123237 _____ () C:\Users\Jirka\Downloads\zoek.zip
2014-11-06 00:05 - 2014-11-06 00:05 - 00896048 _____ () C:\Users\Jirka\Downloads\Norton_Removal_Tool.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HPCeeScheduleForJirka.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackup" /f
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
"HKU\S-1-5-21-1582745763-2883292187-2515674152-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8c5e845-3de4-11e1-88e6-806e6f6e6963}" => Key deleted successfully.
"HKCR\CLSID\{d8c5e845-3de4-11e1-88e6-806e6f6e6963}" => Key not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
Chrome DefaultSearchURL deleted successfully.
Chrome DefaultSuggestURL deleted successfully.
C:\windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Jirka\Desktop\zoek.exe => Moved successfully.
C:\Users\Jirka\Downloads\zoek => Moved successfully.
C:\Users\Jirka\Downloads\zoek.zip => Moved successfully.
C:\Users\Jirka\Downloads\Norton_Removal_Tool.exe => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\windows\Tasks\HPCeeScheduleForJirka.job => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackup" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 48.1 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: Prosím o kontrolu logu
Takze jeste uklidime.
- Stahnete a spustte DelFix - https://toolslib.net/downloads/viewdownload/2-delfix/
- Oznacte jen moznost "Remove disinfection tools"
- kliknete na Run
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Hotovo. Díky za pomoc. Posílám jako poděkování 100,- Kč na podporu fóra.
Re: Prosím o kontrolu logu
Nemate zac, rad jsem pomohl
Za podporu fora jmenem celeho tymu dekuji
Mejte se a treba zase nekdy

Za podporu fora jmenem celeho tymu dekuji

Mejte se a treba zase nekdy

Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.