Problém s pomalým webovým prohlížečem
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Problém s pomalým webovým prohlížečem
Dobrý den,
je to už asi 14 dní, co se mi zničehonic zpomalil počítač a načítaní webových stránek. Výkon procesoru jsem měla v určitých chvílích na 100%, ale to jsem již nějakým způsobem zase opravila. Ale pořád mám problém s pomalým během webových stránek.
Zkoušela jsem si vytáhnout log pomocí FRST i RSIT, ale když je chci spustit, hlásí mi to "RSIT.exe\není platná aplikace typu Win 32" přitom mám 64bitový systém a stáhla jsem si správnou verzi. Zkusila jsem pak i tu druhou, ale chyba se objevuje stále.
Děkuji za každou pomoc.
je to už asi 14 dní, co se mi zničehonic zpomalil počítač a načítaní webových stránek. Výkon procesoru jsem měla v určitých chvílích na 100%, ale to jsem již nějakým způsobem zase opravila. Ale pořád mám problém s pomalým během webových stránek.
Zkoušela jsem si vytáhnout log pomocí FRST i RSIT, ale když je chci spustit, hlásí mi to "RSIT.exe\není platná aplikace typu Win 32" přitom mám 64bitový systém a stáhla jsem si správnou verzi. Zkusila jsem pak i tu druhou, ale chyba se objevuje stále.
Děkuji za každou pomoc.
Re: Problém s pomalým webovým prohlížečem
Zdravim
Zkuste provest stazeni FRST znovu, obcas se toto stava pri neuplnem stazeni
Re: Problém s pomalým webovým prohlížečem
Bohužel pořád stejná hláška :-/ bez toho logu se dál asi nepohneme, co? :-/
Re: Problém s pomalým webovým prohlížečem
Zkuste jeste udelat DDS http://forum.viry.cz/viewtopic.php?f=24&t=123680
Re: Problém s pomalým webovým prohlížečem
Tak tady je DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16561 BrowserJavaVersion: 10.67.2
Run by vas286 at 9:10:49 on 2014-11-15
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.3767.1868 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localservice
C:\Windows\system32\atieclxx.exe
c:\windows\system32\svchost.exe -k networkservice
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k localservicenonetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\Launch Manager\dsiwmis.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Windows\System32\hkcmd.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Launch Manager\MMDx64Fx.exe
C:\Program Files\Launch Manager\LMworker.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
c:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\neurowise\updateneurowise.exe
C:\Program Files (x86)\neurowise\bin\utilneurowise.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
C:\Windows\system32\SearchIndexer.exe
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
c:\windows\system32\svchost.exe -k localservicepeernet
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
c:\windows\system32\svchost.exe -k secsvcs
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Bar = hxxp://search.qip.ru/ie
uSearch Page = hxxp://search.qip.ru
uDefault_Page_URL = hxxp://www.google.com
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
uSearchAssistant = hxxp://search.qip.ru/ie
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mWinlogon: Userinit = userinit.exe
BHO: {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: {9030D464-4C02-4ABF-8ECC-5164760863C6} - <orphaned>
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [Thunderbird] "C:\Program Files (x86)\Mozilla Thunderbird\thunderbird" -turbo
uRun: [OEXPRESS] <no file>
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [LManager] C:\Program Files\Launch Manager\LManager.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:221
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xportovat do aplikace Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CC963627-B1DC-40E0-B52A-CF21EE748449} - - LocalServer32 - <no file>
IE: {CC963627-B1DC-40E0-B52A-CF21EE748450} - - LocalServer32 - <no file>
IE: {CC963627-B1DC-40E0-B52A-CF21EE748451} - - LocalServer32 - <no file>
IE: {CC963627-B1DC-40E0-B52A-CF21EE748452} - - LocalServer32 - <no file>
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 178.72.241.110 10.152.32.1
TCP: Interfaces\{6628DB81-9D5D-49DD-AC30-0FF20E29B084}\4656661657C647 : DHCPNameServer = 192.168.5.1
TCP: Interfaces\{6628DB81-9D5D-49DD-AC30-0FF20E29B084}\7796669604D6F627166737B616 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{6628DB81-9D5D-49DD-AC30-0FF20E29B084}\E4F4B4941402C457D6961602532303F563034323 : DHCPNameServer = 192.168.137.1
TCP: Interfaces\{E90EA134-3B33-403E-8F2F-00F006B5C57B} : DHCPNameServer = 178.72.241.110 10.152.32.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
x64-mStart Page = hxxp://www.google.com
x64-mDefault_Page_URL = hxxp://www.google.com
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: {9030D464-4C02-4ABF-8ECC-5164760863C6} - <orphaned>
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - LocalServer32 - <no file>
x64-Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
x64-Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
x64-Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon
x64-Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-14 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2013-3-14 224896]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswsnx.sys [2012-11-30 1041168]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswsp.sys [2012-11-30 427360]
R1 iSafeKrnl;YAC Mini-Filter Driver;C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2014-11-9 248488]
R1 iSafeKrnlKit;YAC Kit Driver;C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2014-11-9 99496]
R1 iSafeKrnlR3;YAC Ring3 Driver;C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2014-11-9 65704]
R1 iSafeNetFilter;YAC NDIS Driver;C:\Windows\System32\drivers\iSafeNetFilter.sys [2014-11-12 49320]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-9-17 202752]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\drivers\aswHwid.sys [2014-6-22 29208]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-11-30 79184]
R2 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2013-12-25 92008]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2010-1-18 23592]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-7-13 50344]
R2 DsiWMIService;Dritek WMI Service;C:\Program Files\Launch Manager\dsiwmis.exe [2010-8-4 325200]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-8-4 865824]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-8-4 13336]
R2 iSafeService;YAC Service;C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2014-11-9 118048]
R2 MaintainerSvc3.32.7672459;MaintainerSvc3.32.7672459;C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe [2014-10-28 123680]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-11-12 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-11-12 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-11-12 171928]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-9-17 2320920]
R2 Update neurowise;Update neurowise;C:\Program Files (x86)\neurowise\updateneurowise.exe [2014-11-13 526112]
R2 Util neurowise;Util neurowise;C:\Program Files (x86)\neurowise\bin\utilneurowise.exe [2014-9-21 525600]
R3 AmUStor;AM USB Stroage Driver;C:\Windows\System32\drivers\AmUStor.sys [2009-5-26 40448]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-9-17 56344]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2010-9-17 10322848]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2010-8-4 74280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 btusbflt;Bluetooth USB Filter;C:\Windows\System32\drivers\btusbflt.sys [2010-8-4 52264]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2010-8-4 35104]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-9-17 158976]
S3 iSafeKrnlBoot;YAC Boot Driver;C:\Windows\System32\drivers\iSafeKrnlBoot.sys [2014-11-9 45224]
S3 StorSvc;Služba úložiště;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 TeamViewer9;TeamViewer 9;C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-5-26 5024576]
S3 TFsExDisk;TFsExDisk;C:\Windows\System32\drivers\TFsExDisk.sys [2010-9-1 16448]
S3 WatAdminSvc;Služba Technologie aktivace Windows;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-8-8 1255736]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\PROGRA~2\PSPADE~1\PSPad.exe "%1"
.
=============== Created Last 30 ================
.
2014-11-14 03:40:41 304640 ----a-w- C:\Windows\System32\generaltel.dll
2014-11-14 03:40:41 228864 ----a-w- C:\Windows\System32\aepdu.dll
2014-11-14 03:40:40 424448 ----a-w- C:\Windows\System32\aeinv.dll
2014-11-12 15:27:44 49320 ----a-w- C:\Windows\System32\drivers\iSafeNetFilter.sys
2014-11-12 15:09:05 21040 ----a-w- C:\Windows\System32\sdnclean64.exe
2014-11-12 14:36:03 9125352 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{70956CDD-5FCC-4C16-9FE8-11B2BC0AF1BB}\mpengine.dll
2014-11-09 19:51:19 45224 ----a-w- C:\Windows\System32\drivers\iSafeKrnlBoot.sys
2014-11-09 19:51:19 -------- d-----w- C:\Windows\System32\log
2014-11-09 19:51:15 -------- d-----w- C:\Program Files (x86)\Elex-tech
2014-11-09 19:51:00 -------- d-----w- C:\Users\vas286\AppData\Roaming\Elex-tech
2014-11-09 11:47:19 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2014-11-09 11:47:10 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-09 08:30:16 -------- d-----w- C:\sh4ldr
2014-11-09 08:30:16 -------- d-----w- C:\Program Files\Enigma Software Group
2014-11-09 08:29:32 -------- d-----w- C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-10-28 07:51:28 -------- d-----w- C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056
2014-10-17 03:08:19 3195392 ----a-w- C:\Windows\System32\win32k.sys
.
==================== Find3M ====================
.
2014-11-12 14:52:23 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-12 14:52:23 701104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-10-28 05:34:58 275080 ----a-w- C:\Windows\System32\MpSigStub.exe
2014-10-07 20:58:18 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-09-22 13:49:38 99384 ----a-w- C:\Users\vas286\AppData\Roaming\inst.exe
2014-09-22 13:49:38 82816 ----a-w- C:\Users\vas286\AppData\Roaming\pcouffin.sys
.
============= FINISH: 9:11:39,95 ===============
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16561 BrowserJavaVersion: 10.67.2
Run by vas286 at 9:10:49 on 2014-11-15
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.3767.1868 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus *Disabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
C:\Windows\system32\atiesrxx.exe
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localservice
C:\Windows\system32\atieclxx.exe
c:\windows\system32\svchost.exe -k networkservice
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k localservicenonetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Program Files\Launch Manager\dsiwmis.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Windows\System32\hkcmd.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Launch Manager\MMDx64Fx.exe
C:\Program Files\Launch Manager\LMworker.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
c:\windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\neurowise\updateneurowise.exe
C:\Program Files (x86)\neurowise\bin\utilneurowise.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
C:\Windows\system32\SearchIndexer.exe
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
c:\windows\system32\svchost.exe -k localservicepeernet
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
c:\windows\system32\svchost.exe -k secsvcs
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Bar = hxxp://search.qip.ru/ie
uSearch Page = hxxp://search.qip.ru
uDefault_Page_URL = hxxp://www.google.com
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = hxxp://www.google.com
mDefault_Page_URL = hxxp://www.google.com
uSearchAssistant = hxxp://search.qip.ru/ie
uURLSearchHooks: <No Name>: - LocalServer32 - <no file>
mWinlogon: Userinit = userinit.exe
BHO: {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - <orphaned>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: {9030D464-4C02-4ABF-8ECC-5164760863C6} - <orphaned>
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [Thunderbird] "C:\Program Files (x86)\Mozilla Thunderbird\thunderbird" -turbo
uRun: [OEXPRESS] <no file>
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [LManager] C:\Program Files\Launch Manager\LManager.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:221
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xportovat do aplikace Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CC963627-B1DC-40E0-B52A-CF21EE748449} - - LocalServer32 - <no file>
IE: {CC963627-B1DC-40E0-B52A-CF21EE748450} - - LocalServer32 - <no file>
IE: {CC963627-B1DC-40E0-B52A-CF21EE748451} - - LocalServer32 - <no file>
IE: {CC963627-B1DC-40E0-B52A-CF21EE748452} - - LocalServer32 - <no file>
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 178.72.241.110 10.152.32.1
TCP: Interfaces\{6628DB81-9D5D-49DD-AC30-0FF20E29B084}\4656661657C647 : DHCPNameServer = 192.168.5.1
TCP: Interfaces\{6628DB81-9D5D-49DD-AC30-0FF20E29B084}\7796669604D6F627166737B616 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{6628DB81-9D5D-49DD-AC30-0FF20E29B084}\E4F4B4941402C457D6961602532303F563034323 : DHCPNameServer = 192.168.137.1
TCP: Interfaces\{E90EA134-3B33-403E-8F2F-00F006B5C57B} : DHCPNameServer = 178.72.241.110 10.152.32.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
x64-mStart Page = hxxp://www.google.com
x64-mDefault_Page_URL = hxxp://www.google.com
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: {9030D464-4C02-4ABF-8ECC-5164760863C6} - <orphaned>
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - LocalServer32 - <no file>
x64-Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
x64-Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
x64-Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon
x64-Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-14 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2013-3-14 224896]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswsnx.sys [2012-11-30 1041168]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswsp.sys [2012-11-30 427360]
R1 iSafeKrnl;YAC Mini-Filter Driver;C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2014-11-9 248488]
R1 iSafeKrnlKit;YAC Kit Driver;C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2014-11-9 99496]
R1 iSafeKrnlR3;YAC Ring3 Driver;C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2014-11-9 65704]
R1 iSafeNetFilter;YAC NDIS Driver;C:\Windows\System32\drivers\iSafeNetFilter.sys [2014-11-12 49320]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-9-17 202752]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\drivers\aswHwid.sys [2014-6-22 29208]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-11-30 79184]
R2 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2013-12-25 92008]
R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2010-1-18 23592]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-7-13 50344]
R2 DsiWMIService;Dritek WMI Service;C:\Program Files\Launch Manager\dsiwmis.exe [2010-8-4 325200]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-8-4 865824]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-8-4 13336]
R2 iSafeService;YAC Service;C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2014-11-9 118048]
R2 MaintainerSvc3.32.7672459;MaintainerSvc3.32.7672459;C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe [2014-10-28 123680]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-11-12 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-11-12 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-11-12 171928]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-9-17 2320920]
R2 Update neurowise;Update neurowise;C:\Program Files (x86)\neurowise\updateneurowise.exe [2014-11-13 526112]
R2 Util neurowise;Util neurowise;C:\Program Files (x86)\neurowise\bin\utilneurowise.exe [2014-9-21 525600]
R3 AmUStor;AM USB Stroage Driver;C:\Windows\System32\drivers\AmUStor.sys [2009-5-26 40448]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-9-17 56344]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2010-9-17 10322848]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\System32\drivers\L1C62x64.sys [2010-8-4 74280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 btusbflt;Bluetooth USB Filter;C:\Windows\System32\drivers\btusbflt.sys [2010-8-4 52264]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2010-8-4 35104]
S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-9-17 158976]
S3 iSafeKrnlBoot;YAC Boot Driver;C:\Windows\System32\drivers\iSafeKrnlBoot.sys [2014-11-9 45224]
S3 StorSvc;Služba úložiště;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 27136]
S3 TeamViewer9;TeamViewer 9;C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [2014-5-26 5024576]
S3 TFsExDisk;TFsExDisk;C:\Windows\System32\drivers\TFsExDisk.sys [2010-9-1 16448]
S3 WatAdminSvc;Služba Technologie aktivace Windows;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-8-8 1255736]
.
=============== File Associations ===============
.
FileExt: .txt: txtfile=C:\PROGRA~2\PSPADE~1\PSPad.exe "%1"
.
=============== Created Last 30 ================
.
2014-11-14 03:40:41 304640 ----a-w- C:\Windows\System32\generaltel.dll
2014-11-14 03:40:41 228864 ----a-w- C:\Windows\System32\aepdu.dll
2014-11-14 03:40:40 424448 ----a-w- C:\Windows\System32\aeinv.dll
2014-11-12 15:27:44 49320 ----a-w- C:\Windows\System32\drivers\iSafeNetFilter.sys
2014-11-12 15:09:05 21040 ----a-w- C:\Windows\System32\sdnclean64.exe
2014-11-12 14:36:03 9125352 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{70956CDD-5FCC-4C16-9FE8-11B2BC0AF1BB}\mpengine.dll
2014-11-09 19:51:19 45224 ----a-w- C:\Windows\System32\drivers\iSafeKrnlBoot.sys
2014-11-09 19:51:19 -------- d-----w- C:\Windows\System32\log
2014-11-09 19:51:15 -------- d-----w- C:\Program Files (x86)\Elex-tech
2014-11-09 19:51:00 -------- d-----w- C:\Users\vas286\AppData\Roaming\Elex-tech
2014-11-09 11:47:19 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2014-11-09 11:47:10 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-09 08:30:16 -------- d-----w- C:\sh4ldr
2014-11-09 08:30:16 -------- d-----w- C:\Program Files\Enigma Software Group
2014-11-09 08:29:32 -------- d-----w- C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-10-28 07:51:28 -------- d-----w- C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056
2014-10-17 03:08:19 3195392 ----a-w- C:\Windows\System32\win32k.sys
.
==================== Find3M ====================
.
2014-11-12 14:52:23 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-11-12 14:52:23 701104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-10-28 05:34:58 275080 ----a-w- C:\Windows\System32\MpSigStub.exe
2014-10-07 20:58:18 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-09-22 13:49:38 99384 ----a-w- C:\Users\vas286\AppData\Roaming\inst.exe
2014-09-22 13:49:38 82816 ----a-w- C:\Users\vas286\AppData\Roaming\pcouffin.sys
.
============= FINISH: 9:11:39,95 ===============
Re: Problém s pomalým webovým prohlížečem
- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Po spusteni probehne stazeni databaze
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: Problém s pomalým webovým prohlížečem
tak tedy log z AdwCleaner:
# AdwCleaner v4.101 - Report created 15/11/2014 at 09:42:39
# Updated 09/11/2014 by Xplode
# Database : 2014-11-13.1 [Live]
# Operating System : Windows 7 Professional (64 bits)
# Username : vas286 - VAS286-NOTEBOOK
# Running from : C:\Users\vas286\Desktop\adwcleaner_4.101.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\Elex-tech
Folder Deleted : C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{32A1FD71-835E-4B11-8E54-886FDA0B4C89}
File Deleted : C:\Windows\System32\log\iSafeKrnlCall.log
File Deleted : C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\searchplugins\dsrlte.xml
File Deleted : C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\user.js
File Deleted : C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977\user.js
***** [ Scheduled Tasks ] *****
Task Deleted : Yahoo! Search
Task Deleted : RunAsStdUser Task
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90120000-00B0-0405-0000-0000000FF1CE}
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16561
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
-\\ Mozilla Firefox v33.0.2 (x86 cs)
[adoinqh6.default\prefs.js] - Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1392133609795");
[adoinqh6.default\prefs.js] - Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
[adoinqh6.default\prefs.js] - Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [2459 octets] - [15/11/2014 09:41:02]
AdwCleaner[S0].txt - [2307 octets] - [15/11/2014 09:42:39]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2367 octets] ##########
a log z Zoek:
Zoek.exe v5.0.0.0 Updated 14-November-2014
Tool run by vas286 on so 15.11.2014 at 9:51:49,55.
Microsoft Windows 7 Professional 6.1.7600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\vas286\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
15.11.2014 9:56:13 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BFC32E1D-EE75-4A48-BC60-104E11EE2431} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{BFC32E1D-EE75-4A48-BC60-104E11EE2431} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{BFC32E1D-EE75-4A48-BC60-104E11EE2431} deleted successfully
==== Deleting Services ======================
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Util neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Util neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Update neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Update neurowise deleted successfully
==== FireFox Fix ======================
Deleted from C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.newtab.url", "http://www.google.com");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\prefs.js:
Deleted from C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977\prefs.js:
Added to C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\vas286\AppData\Roaming\Thunderbird\Profiles\529dgvd8.default\prefs.js:
Added to C:\Users\vas286\AppData\Roaming\Thunderbird\Profiles\529dgvd8.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.11.2014_1019_.backup
ProfilePath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.11.2014_1019_.backup
ProfilePath: C:\Users\vas286\AppData\Roaming\Thunderbird\Profiles\529dgvd8.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.11.2014_1019_.backup
==== Deleting Files \ Folders ======================
C:\Windows\syswow64\appdata deleted
C:\PROGRA~3\DivX deleted
C:\setup95.exe deleted
C:\found.000 deleted
C:\PROGRA~3\boost_interprocess deleted
C:\Users\vas286\Downloads\iMeshV10.exe deleted
C:\Users\vas286\AppData\LocalLow\boost_interprocess deleted
C:\Windows\WININIT.INI deleted
C:\windows\SysNative\Tasks\Yahoo! Search Updater deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
"C:\PROGRA~2\neurowise\bin\utilneurowise.exe" deleted
"C:\PROGRA~2\neurowise" not deleted
"C:\PROGRA~2\neurowise\bin" not deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [12.11.2014 15:28]
==== Firefox Extensions ======================
ProfilePath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default
- Undetermined - {c45c406e-ab73-11d8-be73-000a95be3b12}
- Undetermined - 2020Player_IKEA@2020Technologies.com
- Undetermined - {46e267d7-2aad-4738-adaf-d4d0a8fac9ea}
- Undetermined - %ProfilePath%\extensions\2020Player_IKEA@2020Technologies.com
- Undetermined - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
- Undetermined - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
ProfilePath: C:\Users\vas286\AppData\Roaming\Thunderbird\Profiles\529dgvd8.default
- iLeopard Mail - %ProfilePath%\extensions\iLeopardMail@reo-2007
- MinimizeToTray Plus - %ProfilePath%\extensions\{de1b245c-de57-11da-ba2d-0050c2490048}
==== Firefox Plugins ======================
Profilepath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977
63F8C13F269B10BC9363B007DAAACAE6 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll - Shockwave Flash
40AAE0A1A4F664828DF5A95875AEA1C8 - C:\Users\vas286\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll - Google Update
CA36F6DCA9A783FF60CB2DC5D28FA5F0 - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll - PDF-XChange Viewer
87132527E2256CF6683A18C4EB34DD3B - C:\Windows\system32\Wat\npWatWeb.dll - Windows Activation Technologies
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[13.07.2014 14:36]
nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx[]
Avast Online Security - vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0191A6B0-1154-4C22-9182-23A95BBE92D9}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0191A6B0-1154-4C22-9182-23A95BBE92D9} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
==== Reset Google Chrome ======================
C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_CURRENT_USER\Software\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\nneajnkjbffgblleaoojgaacokifdkhm deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\vas286\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\vas286\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\vas286\AppData\Local\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=7103 folders=18 17833578 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\vas286\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\vas286\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\vas286\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\PROGRA~2\neurowise" not found
==== EOF on so 15.11.2014 at 10:31:26,12 ======================
# AdwCleaner v4.101 - Report created 15/11/2014 at 09:42:39
# Updated 09/11/2014 by Xplode
# Database : 2014-11-13.1 [Live]
# Operating System : Windows 7 Professional (64 bits)
# Username : vas286 - VAS286-NOTEBOOK
# Running from : C:\Users\vas286\Desktop\adwcleaner_4.101.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\Elex-tech
Folder Deleted : C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{32A1FD71-835E-4B11-8E54-886FDA0B4C89}
File Deleted : C:\Windows\System32\log\iSafeKrnlCall.log
File Deleted : C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\searchplugins\dsrlte.xml
File Deleted : C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\user.js
File Deleted : C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977\user.js
***** [ Scheduled Tasks ] *****
Task Deleted : Yahoo! Search
Task Deleted : RunAsStdUser Task
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90120000-00B0-0405-0000-0000000FF1CE}
***** [ Browsers ] *****
-\\ Internet Explorer v9.0.8112.16561
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
-\\ Mozilla Firefox v33.0.2 (x86 cs)
[adoinqh6.default\prefs.js] - Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1392133609795");
[adoinqh6.default\prefs.js] - Line Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
[adoinqh6.default\prefs.js] - Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [2459 octets] - [15/11/2014 09:41:02]
AdwCleaner[S0].txt - [2307 octets] - [15/11/2014 09:42:39]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2367 octets] ##########
a log z Zoek:
Zoek.exe v5.0.0.0 Updated 14-November-2014
Tool run by vas286 on so 15.11.2014 at 9:51:49,55.
Microsoft Windows 7 Professional 6.1.7600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\vas286\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
15.11.2014 9:56:13 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BFC32E1D-EE75-4A48-BC60-104E11EE2431} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extensions\{BFC32E1D-EE75-4A48-BC60-104E11EE2431} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{BFC32E1D-EE75-4A48-BC60-104E11EE2431} deleted successfully
==== Deleting Services ======================
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Util neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Util neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Util neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Util neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Update neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Update neurowise deleted successfully
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Update neurowise deleted successfully
==== FireFox Fix ======================
Deleted from C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.newtab.url", "http://www.google.com");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\prefs.js:
Deleted from C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977\prefs.js:
Added to C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\vas286\AppData\Roaming\Thunderbird\Profiles\529dgvd8.default\prefs.js:
Added to C:\Users\vas286\AppData\Roaming\Thunderbird\Profiles\529dgvd8.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.11.2014_1019_.backup
ProfilePath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.11.2014_1019_.backup
ProfilePath: C:\Users\vas286\AppData\Roaming\Thunderbird\Profiles\529dgvd8.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_15.11.2014_1019_.backup
==== Deleting Files \ Folders ======================
C:\Windows\syswow64\appdata deleted
C:\PROGRA~3\DivX deleted
C:\setup95.exe deleted
C:\found.000 deleted
C:\PROGRA~3\boost_interprocess deleted
C:\Users\vas286\Downloads\iMeshV10.exe deleted
C:\Users\vas286\AppData\LocalLow\boost_interprocess deleted
C:\Windows\WININIT.INI deleted
C:\windows\SysNative\Tasks\Yahoo! Search Updater deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
"C:\PROGRA~2\neurowise\bin\utilneurowise.exe" deleted
"C:\PROGRA~2\neurowise" not deleted
"C:\PROGRA~2\neurowise\bin" not deleted
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [12.11.2014 15:28]
==== Firefox Extensions ======================
ProfilePath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default
- Undetermined - {c45c406e-ab73-11d8-be73-000a95be3b12}
- Undetermined - 2020Player_IKEA@2020Technologies.com
- Undetermined - {46e267d7-2aad-4738-adaf-d4d0a8fac9ea}
- Undetermined - %ProfilePath%\extensions\2020Player_IKEA@2020Technologies.com
- Undetermined - %ProfilePath%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
- Undetermined - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
ProfilePath: C:\Users\vas286\AppData\Roaming\Thunderbird\Profiles\529dgvd8.default
- iLeopard Mail - %ProfilePath%\extensions\iLeopardMail@reo-2007
- MinimizeToTray Plus - %ProfilePath%\extensions\{de1b245c-de57-11da-ba2d-0050c2490048}
==== Firefox Plugins ======================
Profilepath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977
63F8C13F269B10BC9363B007DAAACAE6 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll - Shockwave Flash
40AAE0A1A4F664828DF5A95875AEA1C8 - C:\Users\vas286\AppData\Local\Google\Update\1.3.25.5\npGoogleUpdate3.dll - Google Update
CA36F6DCA9A783FF60CB2DC5D28FA5F0 - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll - PDF-XChange Viewer
87132527E2256CF6683A18C4EB34DD3B - C:\Windows\system32\Wat\npWatWeb.dll - Windows Activation Technologies
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[13.07.2014 14:36]
nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\google_chrome\html5video\html5video.crx[]
Avast Online Security - vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0191A6B0-1154-4C22-9182-23A95BBE92D9}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0191A6B0-1154-4C22-9182-23A95BBE92D9} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
==== Reset Google Chrome ======================
C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_CURRENT_USER\Software\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\nneajnkjbffgblleaoojgaacokifdkhm deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\vas286\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\vas286\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\vas286\AppData\Local\Mozilla\Firefox\Profiles\t27jeftq.default-1415647198977\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=7103 folders=18 17833578 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\vas286\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\vas286\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\vas286\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\PROGRA~2\neurowise" not found
==== EOF on so 15.11.2014 at 10:31:26,12 ======================
Re: Problém s pomalým webovým prohlížečem
Zkuste nyni udelat FRST
Re: Problém s pomalým webovým prohlížečem
log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2014
Ran by vas286 (administrator) on VAS286-NOTEBOOK on 15-11-2014 14:48:46
Running from C:\Users\vas286\Desktop
Loaded Profile: vas286 (Available profiles: vas286)
Platform: Windows 7 Professional (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
() C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\vas286\Desktop\FRSTLauncher (2).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [320000 2009-04-09] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860192 2010-02-05] (Acer Incorporated)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [430632 2010-01-18] ()
HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-10] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2114376 2008-03-17] (CANON INC.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-23] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [1289296 2010-02-25] (Dritek System Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Thunderbird] => "C:\Program Files (x86)\Mozilla Thunderbird\thunderbird" -turbo
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [OEXPRESS] => [X]
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Nektra OEAPI] => [X]
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Google Update] => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\MountPoints2: {a040fe2d-9fe1-11df-95a2-506313b622f2} - G:\setup.exe
HKU\S-1-5-18\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x20000000
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x846AFE7BD433CB01
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Tcpip\Parameters: [DhcpNameServer] 178.72.241.110 10.152.32.1
FireFox:
========
FF ProfilePath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.7.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc;version=0.8.6c -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @wolfram.com/Mathematica -> C:\Program Files (x86)\Common Files\Wolfram Research\Browser\9.0.1.4092550\npmathplugin.dll (Wolfram Research, Inc.)
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-12-12]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-08-04]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-04]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-11-30]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [Not Found]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{46e267d7-2aad-4738-adaf-d4d0a8fac9ea}.xpi [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
FF Extension: No Name - {c45c406e-ab73-11d8-be73-000a95be3b12} [Not Found]
FF Extension: No Name - {46e267d7-2aad-4738-adaf-d4d0a8fac9ea} [Not Found]
Chrome:
=======
CHR HomePage: Default -> https://www.seznam.cz/?clid=22668
CHR StartupUrls: Default -> "https://www.seznam.cz/?clid=22668"
CHR DefaultSearchKeyword: Default -> google
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-10]
CHR Extension: (Dokumenty Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-10]
CHR Extension: (Disk Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-10]
CHR Extension: (Tabulky Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-10]
CHR Extension: (Avast Online Security) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-11-10]
CHR Extension: (Peněženka Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-10]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-13]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [23592 2010-01-18] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-13] (AVAST Software)
R2 DsiWMIService; C:\Program Files\Launch Manager\dsiwmis.exe [325200 2010-02-25] (Dritek System Inc.)
S3 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [103808 2008-01-22] ()
R2 MaintainerSvc3.32.7672459; C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe [123680 2014-11-15] ()
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-13] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-13] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-13] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-13] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-13] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-13] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-13] ()
S3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [34144 2010-12-21] (ESET)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-08-04] () [File not signed]
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed]
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
U3 amq4hxpx; C:\Windows\System32\Drivers\amq4hxpx.sys [0 ] (Microsoft Corporation)
S3 PCAlertDriver; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\NTGLM7X.sys [X]
S3 RushTopDevice; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\RushTop.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S0 vmci; system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-15 14:48 - 2014-11-15 14:49 - 00017370 _____ () C:\Users\vas286\Desktop\FRST.txt
2014-11-15 14:48 - 2014-11-15 14:48 - 00000000 ____D () C:\FRST
2014-11-15 14:46 - 2014-11-15 14:46 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\FRSTLauncher (2).exe
2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 604013.crdownload
2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 565752.crdownload
2014-11-15 14:44 - 2014-11-15 14:44 - 02116608 _____ (Farbar) C:\Users\vas286\Desktop\FRST64.exe
2014-11-15 10:29 - 2014-11-15 09:51 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-11-15 09:55 - 2014-11-15 10:31 - 00015010 _____ () C:\zoek-results.log
2014-11-15 09:47 - 2014-11-15 10:20 - 00000000 ____D () C:\zoek_backup
2014-11-15 09:47 - 2014-11-15 09:47 - 01294848 _____ () C:\Users\vas286\Desktop\zoek.exe
2014-11-15 09:40 - 2014-11-15 09:42 - 00000000 ____D () C:\AdwCleaner
2014-11-15 09:37 - 2014-11-15 09:37 - 02140160 _____ () C:\Users\vas286\Desktop\adwcleaner_4.101.exe
2014-11-15 09:12 - 2014-11-15 09:12 - 00013496 _____ () C:\Users\vas286\Desktop\attach.txt
2014-11-15 09:12 - 2014-11-15 09:11 - 00015823 _____ () C:\Users\vas286\Desktop\dds.txt
2014-11-15 09:10 - 2014-11-15 09:10 - 00688992 ____R (Swearware) C:\Users\vas286\Desktop\dds.exe
2014-11-15 09:08 - 2014-11-15 09:08 - 02106388 _____ () C:\Users\vas286\Downloads\FRST64.exe
2014-11-14 04:40 - 2014-11-05 03:48 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-14 04:40 - 2014-11-05 03:47 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-14 04:40 - 2014-11-05 03:41 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-13 17:02 - 2010-10-03 12:20 - 00000904 _____ () C:\Windows\system32\Drivers\etc\hosts.20141113-170212.backup
2014-11-13 16:57 - 2014-11-15 10:30 - 00012590 _____ () C:\Windows\PFRO.log
2014-11-13 16:57 - 2014-11-15 10:30 - 00000672 _____ () C:\Windows\setupact.log
2014-11-13 16:57 - 2014-11-13 16:57 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-12 21:35 - 2014-11-12 21:35 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zařízení Bluetooth
2014-11-12 16:09 - 2014-11-12 16:09 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-11-11 18:49 - 2014-11-11 18:49 - 00000000 ____D () C:\Users\vas286\Desktop\výpověď z bytu
2014-11-11 18:47 - 2014-11-13 16:54 - 00000000 ____D () C:\Users\vas286\Desktop\RWE
2014-11-09 20:51 - 2014-11-15 09:42 - 00000000 ____D () C:\Windows\system32\log
2014-11-09 12:47 - 2014-11-15 09:24 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-09 12:47 - 2014-11-13 17:00 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-11-09 09:32 - 2014-11-09 09:32 - 00000000 _____ () C:\autoexec.bat
2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\sh4ldr
2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-11-09 09:29 - 2014-11-09 09:30 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-10-29 09:36 - 2014-11-13 16:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-28 08:51 - 2014-11-15 09:45 - 00000000 ____D () C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056
2014-10-17 04:08 - 2014-09-15 01:44 - 03195392 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-15 14:48 - 2012-01-25 22:08 - 00000966 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job
2014-11-15 14:45 - 2010-08-04 13:29 - 01445609 _____ () C:\Windows\WindowsUpdate.log
2014-11-15 14:24 - 2013-05-23 07:20 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-15 13:52 - 2012-08-19 17:03 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-15 12:50 - 2012-01-25 22:08 - 00002335 _____ () C:\Users\vas286\Desktop\Google Chrome.lnk
2014-11-15 12:43 - 2012-04-11 20:16 - 00000986 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job
2014-11-15 10:38 - 2009-07-14 05:45 - 00021440 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-15 10:38 - 2009-07-14 05:45 - 00021440 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-15 10:32 - 2010-08-19 10:51 - 00000000 ____D () C:\Users\vas286\AppData\Local\CrashDumps
2014-11-15 10:31 - 2013-05-23 07:20 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-15 10:30 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-15 09:50 - 2012-11-30 20:54 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-11-15 08:22 - 2010-08-04 14:39 - 00091976 _____ () C:\Users\vas286\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-15 08:21 - 2009-07-14 05:45 - 04921144 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-15 08:19 - 2013-05-23 07:20 - 00003948 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-15 08:19 - 2013-05-23 07:20 - 00003696 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-15 07:54 - 2013-05-04 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KLC
2014-11-15 07:52 - 2010-11-26 13:46 - 00000000 ____D () C:\ProgramData\Skype
2014-11-15 07:46 - 2011-05-22 09:16 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-11-15 07:46 - 2010-09-17 15:25 - 00000000 ____D () C:\ProgramData\Cisco
2014-11-15 07:46 - 2010-09-17 15:25 - 00000000 ____D () C:\Program Files (x86)\Cisco
2014-11-15 07:45 - 2010-10-16 08:24 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-11-15 07:44 - 2010-08-04 15:21 - 00000000 ____D () C:\ProgramData\Adobe
2014-11-15 07:43 - 2010-08-04 14:48 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\Adobe
2014-11-15 07:42 - 2011-02-05 19:31 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-11-15 07:41 - 2011-02-05 19:34 - 00000000 ____D () C:\Program Files\Adobe
2014-11-15 07:36 - 2011-01-05 21:20 - 00000000 ____D () C:\Program Files\DivX
2014-11-15 07:36 - 2011-01-05 21:19 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-11-15 07:32 - 2010-08-04 14:45 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\Samsung
2014-11-15 07:31 - 2010-08-04 14:12 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-11-14 20:48 - 2012-01-25 22:08 - 00000914 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job
2014-11-14 20:12 - 2009-07-14 06:08 - 00032626 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-11-14 04:49 - 2014-07-10 04:56 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-13 21:01 - 2011-01-01 18:07 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\vlc
2014-11-13 16:49 - 2010-08-04 20:02 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\uTorrent
2014-11-13 16:49 - 2010-08-04 13:40 - 00000000 ____D () C:\Windows\Minidump
2014-11-13 16:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-13 05:01 - 2010-08-04 15:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-12 21:39 - 2009-07-14 16:18 - 00668464 _____ () C:\Windows\system32\perfh005.dat
2014-11-12 21:39 - 2009-07-14 16:18 - 00141080 _____ () C:\Windows\system32\perfc005.dat
2014-11-12 21:39 - 2009-07-14 06:13 - 01577482 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-12 17:20 - 2010-12-18 11:01 - 00000000 ____D () C:\Program Files (x86)\IrfanView
2014-11-12 17:04 - 2013-05-23 07:20 - 00000000 ____D () C:\Program Files (x86)\Google
2014-11-12 17:04 - 2011-03-25 16:18 - 00000000 ____D () C:\Users\vas286\AppData\Local\Google
2014-11-12 15:52 - 2012-08-19 17:03 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-12 15:52 - 2012-04-02 09:10 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-12 15:52 - 2011-06-05 14:15 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-12 15:29 - 2010-08-04 13:37 - 00000000 ____D () C:\Users\vas286
2014-11-12 15:28 - 2013-10-24 05:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-11-12 15:27 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-11-12 15:24 - 2013-07-23 03:07 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-12 15:03 - 2014-06-11 04:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-11-12 15:03 - 2014-01-16 14:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IBM SPSS Statistics
2014-11-12 15:03 - 2014-01-16 14:33 - 00000000 ____D () C:\Program Files\IBM
2014-11-12 15:03 - 2013-07-24 11:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrindEQ Math Utilities (x64)
2014-11-12 15:03 - 2013-07-24 11:10 - 00000000 ____D () C:\Program Files\GrindEQ
2014-11-12 15:03 - 2013-05-31 18:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wolfram CDF Player
2014-11-12 15:03 - 2013-05-31 18:47 - 00000000 ____D () C:\Program Files\Common Files\Wolfram Research
2014-11-12 15:03 - 2013-05-31 18:45 - 00000000 ____D () C:\Program Files (x86)\Wolfram Research
2014-11-12 15:03 - 2013-03-24 19:43 - 00000000 ____D () C:\Program Files\swipl
2014-11-12 15:03 - 2013-03-01 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LEd
2014-11-12 15:03 - 2013-03-01 15:44 - 00000000 ____D () C:\Program Files (x86)\LEd
2014-11-12 15:03 - 2013-02-23 20:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ulož.to File Manager
2014-11-12 15:03 - 2013-02-23 20:58 - 00000000 ____D () C:\Program Files (x86)\Ulozto File Manager
2014-11-12 15:03 - 2013-01-12 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R
2014-11-12 15:03 - 2013-01-12 22:08 - 00000000 ____D () C:\Program Files\R
2014-11-12 15:03 - 2012-11-29 12:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QIP 2012
2014-11-12 15:03 - 2012-04-11 18:45 - 00000000 ____D () C:\Program Files (x86)\QIP
2014-11-12 15:03 - 2011-11-04 15:46 - 00000000 ____D () C:\Program Files (x86)\QIP 2012
2014-11-12 15:03 - 2011-03-24 21:59 - 00000000 ____D () C:\Program Files (x86)\SPSSInc
2014-11-12 15:03 - 2010-09-28 18:14 - 00000000 ____D () C:\Program Files\BatteryBar
2014-11-12 15:00 - 2010-08-04 13:58 - 00000000 ____D () C:\Users\vas286\AppData\Local\Mozilla
2014-11-12 14:58 - 2013-05-31 18:47 - 00000000 ____D () C:\Program Files\Extras
2014-11-08 21:38 - 2011-03-21 20:42 - 00007602 _____ () C:\Users\vas286\AppData\Local\Resmon.ResmonCfg
2014-11-03 21:43 - 2012-04-11 20:16 - 00000964 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job
2014-10-29 07:46 - 2014-08-18 03:32 - 00000000 ____D () C:\Users\vas286\AppData\Local\Adobe
2014-10-28 06:34 - 2010-08-04 13:58 - 00275080 _____ (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-22 17:42 - 2010-11-26 13:46 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\Skype
2014-10-21 19:43 - 2012-01-25 22:08 - 00003938 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA
2014-10-21 19:43 - 2012-01-25 22:08 - 00003542 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core
2014-10-17 04:28 - 2010-08-04 15:24 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\vas286\AppData\Local\Temp\KMP_3.9.1.130.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:15B79D44
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\vas286\Desktop" je 21 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetI
C:\Windows\PLFSetI.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-11-2014
Ran by vas286 (administrator) on VAS286-NOTEBOOK on 15-11-2014 14:48:46
Running from C:\Users\vas286\Desktop
Loaded Profile: vas286 (Available profiles: vas286)
Platform: Windows 7 Professional (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
() C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
() C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\vas286\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\vas286\Desktop\FRSTLauncher (2).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [320000 2009-04-09] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860192 2010-02-05] (Acer Incorporated)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [430632 2010-01-18] ()
HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-10] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2114376 2008-03-17] (CANON INC.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2009-12-23] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files\Launch Manager\LManager.exe [1289296 2010-02-25] (Dritek System Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Thunderbird] => "C:\Program Files (x86)\Mozilla Thunderbird\thunderbird" -turbo
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [OEXPRESS] => [X]
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Nektra OEAPI] => [X]
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Google Update] => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\MountPoints2: {a040fe2d-9fe1-11df-95a2-506313b622f2} - G:\setup.exe
HKU\S-1-5-18\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x20000000
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x846AFE7BD433CB01
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Tcpip\Parameters: [DhcpNameServer] 178.72.241.110 10.152.32.1
FireFox:
========
FF ProfilePath: C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.7.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc;version=0.8.6c -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @wolfram.com/Mathematica -> C:\Program Files (x86)\Common Files\Wolfram Research\Browser\9.0.1.4092550\npmathplugin.dll (Wolfram Research, Inc.)
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\2020Player_IKEA@2020Technologies.com [2013-12-12]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-08-04]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-04]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-11-30]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [Not Found]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{46e267d7-2aad-4738-adaf-d4d0a8fac9ea}.xpi [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
FF Extension: No Name - {c45c406e-ab73-11d8-be73-000a95be3b12} [Not Found]
FF Extension: No Name - {46e267d7-2aad-4738-adaf-d4d0a8fac9ea} [Not Found]
Chrome:
=======
CHR HomePage: Default -> https://www.seznam.cz/?clid=22668
CHR StartupUrls: Default -> "https://www.seznam.cz/?clid=22668"
CHR DefaultSearchKeyword: Default -> google
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-10]
CHR Extension: (Dokumenty Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-10]
CHR Extension: (Disk Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-10]
CHR Extension: (Tabulky Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-10]
CHR Extension: (Avast Online Security) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-11-10]
CHR Extension: (Peněženka Google) - C:\Users\vas286\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-10]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-13]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [23592 2010-01-18] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-13] (AVAST Software)
R2 DsiWMIService; C:\Program Files\Launch Manager\dsiwmis.exe [325200 2010-02-25] (Dritek System Inc.)
S3 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [103808 2008-01-22] ()
R2 MaintainerSvc3.32.7672459; C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe [123680 2014-11-15] ()
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-13] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-13] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-13] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-13] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-13] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-13] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-13] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-13] ()
S3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [34144 2010-12-21] (ESET)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-08-04] () [File not signed]
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed]
S3 vpnva; C:\Windows\System32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
U3 amq4hxpx; C:\Windows\System32\Drivers\amq4hxpx.sys [0 ] (Microsoft Corporation)
S3 PCAlertDriver; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\NTGLM7X.sys [X]
S3 RushTopDevice; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\RushTop.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S0 vmci; system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-15 14:48 - 2014-11-15 14:49 - 00017370 _____ () C:\Users\vas286\Desktop\FRST.txt
2014-11-15 14:48 - 2014-11-15 14:48 - 00000000 ____D () C:\FRST
2014-11-15 14:46 - 2014-11-15 14:46 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\FRSTLauncher (2).exe
2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 604013.crdownload
2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 565752.crdownload
2014-11-15 14:44 - 2014-11-15 14:44 - 02116608 _____ (Farbar) C:\Users\vas286\Desktop\FRST64.exe
2014-11-15 10:29 - 2014-11-15 09:51 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-11-15 09:55 - 2014-11-15 10:31 - 00015010 _____ () C:\zoek-results.log
2014-11-15 09:47 - 2014-11-15 10:20 - 00000000 ____D () C:\zoek_backup
2014-11-15 09:47 - 2014-11-15 09:47 - 01294848 _____ () C:\Users\vas286\Desktop\zoek.exe
2014-11-15 09:40 - 2014-11-15 09:42 - 00000000 ____D () C:\AdwCleaner
2014-11-15 09:37 - 2014-11-15 09:37 - 02140160 _____ () C:\Users\vas286\Desktop\adwcleaner_4.101.exe
2014-11-15 09:12 - 2014-11-15 09:12 - 00013496 _____ () C:\Users\vas286\Desktop\attach.txt
2014-11-15 09:12 - 2014-11-15 09:11 - 00015823 _____ () C:\Users\vas286\Desktop\dds.txt
2014-11-15 09:10 - 2014-11-15 09:10 - 00688992 ____R (Swearware) C:\Users\vas286\Desktop\dds.exe
2014-11-15 09:08 - 2014-11-15 09:08 - 02106388 _____ () C:\Users\vas286\Downloads\FRST64.exe
2014-11-14 04:40 - 2014-11-05 03:48 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-14 04:40 - 2014-11-05 03:47 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-14 04:40 - 2014-11-05 03:41 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-13 17:02 - 2010-10-03 12:20 - 00000904 _____ () C:\Windows\system32\Drivers\etc\hosts.20141113-170212.backup
2014-11-13 16:57 - 2014-11-15 10:30 - 00012590 _____ () C:\Windows\PFRO.log
2014-11-13 16:57 - 2014-11-15 10:30 - 00000672 _____ () C:\Windows\setupact.log
2014-11-13 16:57 - 2014-11-13 16:57 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-12 21:35 - 2014-11-12 21:35 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zařízení Bluetooth
2014-11-12 16:09 - 2014-11-12 16:09 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-11-11 18:49 - 2014-11-11 18:49 - 00000000 ____D () C:\Users\vas286\Desktop\výpověď z bytu
2014-11-11 18:47 - 2014-11-13 16:54 - 00000000 ____D () C:\Users\vas286\Desktop\RWE
2014-11-09 20:51 - 2014-11-15 09:42 - 00000000 ____D () C:\Windows\system32\log
2014-11-09 12:47 - 2014-11-15 09:24 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-09 12:47 - 2014-11-13 17:00 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-11-09 09:32 - 2014-11-09 09:32 - 00000000 _____ () C:\autoexec.bat
2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\sh4ldr
2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-11-09 09:29 - 2014-11-09 09:30 - 00000000 ____D () C:\Windows\1F7E4FF9D2E542589AE1E16E6CB3252A.TMP
2014-10-29 09:36 - 2014-11-13 16:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-10-28 08:51 - 2014-11-15 09:45 - 00000000 ____D () C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056
2014-10-17 04:08 - 2014-09-15 01:44 - 03195392 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-15 14:48 - 2012-01-25 22:08 - 00000966 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job
2014-11-15 14:45 - 2010-08-04 13:29 - 01445609 _____ () C:\Windows\WindowsUpdate.log
2014-11-15 14:24 - 2013-05-23 07:20 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-15 13:52 - 2012-08-19 17:03 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-15 12:50 - 2012-01-25 22:08 - 00002335 _____ () C:\Users\vas286\Desktop\Google Chrome.lnk
2014-11-15 12:43 - 2012-04-11 20:16 - 00000986 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job
2014-11-15 10:38 - 2009-07-14 05:45 - 00021440 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-15 10:38 - 2009-07-14 05:45 - 00021440 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-15 10:32 - 2010-08-19 10:51 - 00000000 ____D () C:\Users\vas286\AppData\Local\CrashDumps
2014-11-15 10:31 - 2013-05-23 07:20 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-15 10:30 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-15 09:50 - 2012-11-30 20:54 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-11-15 08:22 - 2010-08-04 14:39 - 00091976 _____ () C:\Users\vas286\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-15 08:21 - 2009-07-14 05:45 - 04921144 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-15 08:19 - 2013-05-23 07:20 - 00003948 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-15 08:19 - 2013-05-23 07:20 - 00003696 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-15 07:54 - 2013-05-04 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KLC
2014-11-15 07:52 - 2010-11-26 13:46 - 00000000 ____D () C:\ProgramData\Skype
2014-11-15 07:46 - 2011-05-22 09:16 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-11-15 07:46 - 2010-09-17 15:25 - 00000000 ____D () C:\ProgramData\Cisco
2014-11-15 07:46 - 2010-09-17 15:25 - 00000000 ____D () C:\Program Files (x86)\Cisco
2014-11-15 07:45 - 2010-10-16 08:24 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-11-15 07:44 - 2010-08-04 15:21 - 00000000 ____D () C:\ProgramData\Adobe
2014-11-15 07:43 - 2010-08-04 14:48 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\Adobe
2014-11-15 07:42 - 2011-02-05 19:31 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-11-15 07:41 - 2011-02-05 19:34 - 00000000 ____D () C:\Program Files\Adobe
2014-11-15 07:36 - 2011-01-05 21:20 - 00000000 ____D () C:\Program Files\DivX
2014-11-15 07:36 - 2011-01-05 21:19 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-11-15 07:32 - 2010-08-04 14:45 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\Samsung
2014-11-15 07:31 - 2010-08-04 14:12 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-11-14 20:48 - 2012-01-25 22:08 - 00000914 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job
2014-11-14 20:12 - 2009-07-14 06:08 - 00032626 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-11-14 04:49 - 2014-07-10 04:56 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-13 21:01 - 2011-01-01 18:07 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\vlc
2014-11-13 16:49 - 2010-08-04 20:02 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\uTorrent
2014-11-13 16:49 - 2010-08-04 13:40 - 00000000 ____D () C:\Windows\Minidump
2014-11-13 16:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-13 05:01 - 2010-08-04 15:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-12 21:39 - 2009-07-14 16:18 - 00668464 _____ () C:\Windows\system32\perfh005.dat
2014-11-12 21:39 - 2009-07-14 16:18 - 00141080 _____ () C:\Windows\system32\perfc005.dat
2014-11-12 21:39 - 2009-07-14 06:13 - 01577482 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-12 17:20 - 2010-12-18 11:01 - 00000000 ____D () C:\Program Files (x86)\IrfanView
2014-11-12 17:04 - 2013-05-23 07:20 - 00000000 ____D () C:\Program Files (x86)\Google
2014-11-12 17:04 - 2011-03-25 16:18 - 00000000 ____D () C:\Users\vas286\AppData\Local\Google
2014-11-12 15:52 - 2012-08-19 17:03 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-12 15:52 - 2012-04-02 09:10 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-12 15:52 - 2011-06-05 14:15 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-12 15:29 - 2010-08-04 13:37 - 00000000 ____D () C:\Users\vas286
2014-11-12 15:28 - 2013-10-24 05:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-11-12 15:27 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-11-12 15:24 - 2013-07-23 03:07 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-12 15:03 - 2014-06-11 04:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-11-12 15:03 - 2014-01-16 14:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IBM SPSS Statistics
2014-11-12 15:03 - 2014-01-16 14:33 - 00000000 ____D () C:\Program Files\IBM
2014-11-12 15:03 - 2013-07-24 11:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrindEQ Math Utilities (x64)
2014-11-12 15:03 - 2013-07-24 11:10 - 00000000 ____D () C:\Program Files\GrindEQ
2014-11-12 15:03 - 2013-05-31 18:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wolfram CDF Player
2014-11-12 15:03 - 2013-05-31 18:47 - 00000000 ____D () C:\Program Files\Common Files\Wolfram Research
2014-11-12 15:03 - 2013-05-31 18:45 - 00000000 ____D () C:\Program Files (x86)\Wolfram Research
2014-11-12 15:03 - 2013-03-24 19:43 - 00000000 ____D () C:\Program Files\swipl
2014-11-12 15:03 - 2013-03-01 15:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LEd
2014-11-12 15:03 - 2013-03-01 15:44 - 00000000 ____D () C:\Program Files (x86)\LEd
2014-11-12 15:03 - 2013-02-23 20:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ulož.to File Manager
2014-11-12 15:03 - 2013-02-23 20:58 - 00000000 ____D () C:\Program Files (x86)\Ulozto File Manager
2014-11-12 15:03 - 2013-01-12 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R
2014-11-12 15:03 - 2013-01-12 22:08 - 00000000 ____D () C:\Program Files\R
2014-11-12 15:03 - 2012-11-29 12:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QIP 2012
2014-11-12 15:03 - 2012-04-11 18:45 - 00000000 ____D () C:\Program Files (x86)\QIP
2014-11-12 15:03 - 2011-11-04 15:46 - 00000000 ____D () C:\Program Files (x86)\QIP 2012
2014-11-12 15:03 - 2011-03-24 21:59 - 00000000 ____D () C:\Program Files (x86)\SPSSInc
2014-11-12 15:03 - 2010-09-28 18:14 - 00000000 ____D () C:\Program Files\BatteryBar
2014-11-12 15:00 - 2010-08-04 13:58 - 00000000 ____D () C:\Users\vas286\AppData\Local\Mozilla
2014-11-12 14:58 - 2013-05-31 18:47 - 00000000 ____D () C:\Program Files\Extras
2014-11-08 21:38 - 2011-03-21 20:42 - 00007602 _____ () C:\Users\vas286\AppData\Local\Resmon.ResmonCfg
2014-11-03 21:43 - 2012-04-11 20:16 - 00000964 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job
2014-10-29 07:46 - 2014-08-18 03:32 - 00000000 ____D () C:\Users\vas286\AppData\Local\Adobe
2014-10-28 06:34 - 2010-08-04 13:58 - 00275080 _____ (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-22 17:42 - 2010-11-26 13:46 - 00000000 ____D () C:\Users\vas286\AppData\Roaming\Skype
2014-10-21 19:43 - 2012-01-25 22:08 - 00003938 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA
2014-10-21 19:43 - 2012-01-25 22:08 - 00003542 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core
2014-10-17 04:28 - 2010-08-04 15:24 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\vas286\AppData\Local\Temp\KMP_3.9.1.130.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:15B79D44
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\vas286\Desktop" je 21 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetI
C:\Windows\PLFSetI.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
- Přílohy
-
- Addition.zip
- (8.75 KiB) Staženo 44 x
Re: Problém s pomalým webovým prohlížečem
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start CloseProcesses: HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [OEXPRESS] => [X] HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Nektra OEAPI] => [X] HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Google Update] => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.) HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\MountPoints2: {a040fe2d-9fe1-11df-95a2-506313b622f2} - G:\setup.exe HKU\S-1-5-18\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x20000000 ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File BootExecute: autocheck autochk * sdnclean64.exe HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x846AFE7BD433CB01 URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-08-04] FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-04] FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [Not Found] FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{46e267d7-2aad-4738-adaf-d4d0a8fac9ea}.xpi [Not Found] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found] FF Extension: No Name - {c45c406e-ab73-11d8-be73-000a95be3b12} [Not Found] FF Extension: No Name - {46e267d7-2aad-4738-adaf-d4d0a8fac9ea} [Not Found] R2 MaintainerSvc3.32.7672459; C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe [123680 2014-11-15] () U3 amq4hxpx; C:\Windows\System32\Drivers\amq4hxpx.sys [0 ] (Microsoft Corporation) S3 PCAlertDriver; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\NTGLM7X.sys [X] S3 RushTopDevice; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\RushTop.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] S0 vmci; system32\DRIVERS\vmci.sys [X] S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X] C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c9605 2014-11-15 14:48 - 2014-11-15 14:49 - 00017370 _____ () C:\Users\vas286\Desktop\FRST.txt 2014-11-15 14:46 - 2014-11-15 14:46 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\FRSTLauncher (2).exe 2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 604013.crdownload 2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 565752.crdownload 2014-11-15 10:29 - 2014-11-15 09:51 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-11-15 09:55 - 2014-11-15 10:31 - 00015010 _____ () C:\zoek-results.log 2014-11-15 09:47 - 2014-11-15 10:20 - 00000000 ____D () C:\zoek_backup 2014-11-15 09:47 - 2014-11-15 09:47 - 01294848 _____ () C:\Users\vas286\Desktop\zoek.exe 2014-11-15 09:40 - 2014-11-15 09:42 - 00000000 ____D () C:\AdwCleaner 2014-11-15 09:37 - 2014-11-15 09:37 - 02140160 _____ () C:\Users\vas286\Desktop\adwcleaner_4.101.exe 2014-11-15 09:12 - 2014-11-15 09:12 - 00013496 _____ () C:\Users\vas286\Desktop\attach.txt 2014-11-15 09:12 - 2014-11-15 09:11 - 00015823 _____ () C:\Users\vas286\Desktop\dds.txt 2014-11-15 09:10 - 2014-11-15 09:10 - 00688992 ____R (Swearware) C:\Users\vas286\Desktop\dds.exe 2014-11-13 17:02 - 2010-10-03 12:20 - 00000904 _____ () C:\Windows\system32\Drivers\etc\hosts.20141113-170212.backup 2014-11-13 16:57 - 2014-11-15 10:30 - 00012590 _____ () C:\Windows\PFRO.log 2014-11-13 16:57 - 2014-11-15 10:30 - 00000672 _____ () C:\Windows\setupact.log 2014-11-13 16:57 - 2014-11-13 16:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-11-12 16:09 - 2014-11-12 16:09 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking 2014-11-09 12:47 - 2014-11-15 09:24 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-11-09 12:47 - 2014-11-13 17:00 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy 2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\sh4ldr 2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\Program Files\Enigma Software Group 2014-10-28 08:51 - 2014-11-15 09:45 - 00000000 ____D () C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056 Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe Task: {A1384146-40C9-45D9-8724-546D0D914293} - \Yahoo! Search Updater No Task File <==== ATTENTION HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Classes\.exe: exefile => <===== ATTENTION! AlternateDataStreams: C:\ProgramData\TEMP:15B79D44 REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f Hosts: EmptyTemp: Reboot: End- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST
- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt
Re: Problém s pomalým webovým prohlížečem
tady přikládám fixlog.txt:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-11-2014
Ran by vas286 at 2014-11-15 15:07:38 Run:1
Running from C:\Users\vas286\Desktop
Loaded Profile: vas286 (Available profiles: vas286)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [OEXPRESS] => [X]
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Nektra OEAPI] => [X]
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Google Update] => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\MountPoints2: {a040fe2d-9fe1-11df-95a2-506313b622f2} - G:\setup.exe
HKU\S-1-5-18\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x20000000
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
BootExecute: autocheck autochk * sdnclean64.exe
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x846AFE7BD433CB01
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-08-04]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-04]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [Not Found]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{46e267d7-2aad-4738-adaf-d4d0a8fac9ea}.xpi [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
FF Extension: No Name - {c45c406e-ab73-11d8-be73-000a95be3b12} [Not Found]
FF Extension: No Name - {46e267d7-2aad-4738-adaf-d4d0a8fac9ea} [Not Found]
R2 MaintainerSvc3.32.7672459; C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe [123680 2014-11-15] ()
U3 amq4hxpx; C:\Windows\System32\Drivers\amq4hxpx.sys [0 ] (Microsoft Corporation)
S3 PCAlertDriver; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\NTGLM7X.sys [X]
S3 RushTopDevice; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\RushTop.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S0 vmci; system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c9605
2014-11-15 14:48 - 2014-11-15 14:49 - 00017370 _____ () C:\Users\vas286\Desktop\FRST.txt
2014-11-15 14:46 - 2014-11-15 14:46 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\FRSTLauncher (2).exe
2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 604013.crdownload
2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 565752.crdownload
2014-11-15 10:29 - 2014-11-15 09:51 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-11-15 09:55 - 2014-11-15 10:31 - 00015010 _____ () C:\zoek-results.log
2014-11-15 09:47 - 2014-11-15 10:20 - 00000000 ____D () C:\zoek_backup
2014-11-15 09:47 - 2014-11-15 09:47 - 01294848 _____ () C:\Users\vas286\Desktop\zoek.exe
2014-11-15 09:40 - 2014-11-15 09:42 - 00000000 ____D () C:\AdwCleaner
2014-11-15 09:37 - 2014-11-15 09:37 - 02140160 _____ () C:\Users\vas286\Desktop\adwcleaner_4.101.exe
2014-11-15 09:12 - 2014-11-15 09:12 - 00013496 _____ () C:\Users\vas286\Desktop\attach.txt
2014-11-15 09:12 - 2014-11-15 09:11 - 00015823 _____ () C:\Users\vas286\Desktop\dds.txt
2014-11-15 09:10 - 2014-11-15 09:10 - 00688992 ____R (Swearware) C:\Users\vas286\Desktop\dds.exe
2014-11-13 17:02 - 2010-10-03 12:20 - 00000904 _____ () C:\Windows\system32\Drivers\etc\hosts.20141113-170212.backup
2014-11-13 16:57 - 2014-11-15 10:30 - 00012590 _____ () C:\Windows\PFRO.log
2014-11-13 16:57 - 2014-11-15 10:30 - 00000672 _____ () C:\Windows\setupact.log
2014-11-13 16:57 - 2014-11-13 16:57 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-12 16:09 - 2014-11-12 16:09 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-11-09 12:47 - 2014-11-15 09:24 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-09 12:47 - 2014-11-13 17:00 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\sh4ldr
2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-10-28 08:51 - 2014-11-15 09:45 - 00000000 ____D () C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {A1384146-40C9-45D9-8724-546D0D914293} - \Yahoo! Search Updater No Task File <==== ATTENTION
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Classes\.exe: exefile => <===== ATTENTION!
AlternateDataStreams: C:\ProgramData\TEMP:15B79D44
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Run\\OEXPRESS => value deleted successfully.
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Nektra OEAPI => value deleted successfully.
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully.
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => value deleted successfully.
"HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a040fe2d-9fe1-11df-95a2-506313b622f2}" => Key deleted successfully.
"HKCR\CLSID\{a040fe2d-9fe1-11df-95a2-506313b622f2}" => Key not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDriveTypeAutoRun => value deleted successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GDriveSharedOverlay" => Key deleted successfully.
"HKCR\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" => Key not found.
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP => value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
"HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found.
C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} => Moved successfully.
C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} => Moved successfully.
C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi not found.
C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{46e267d7-2aad-4738-adaf-d4d0a8fac9ea}.xpi not found.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} not found.
FF Extension: No Name - {c45c406e-ab73-11d8-be73-000a95be3b12} [Not Found] not found.
FF Extension: No Name - {46e267d7-2aad-4738-adaf-d4d0a8fac9ea} [Not Found] not found.
MaintainerSvc3.32.7672459 => Service deleted successfully.
amq4hxpx => Service deleted successfully.
PCAlertDriver => Service deleted successfully.
RushTopDevice => Service deleted successfully.
VBoxNetFlt => Service deleted successfully.
vmci => Service deleted successfully.
VMnetAdapter => Service deleted successfully.
"C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c9605" => File/Directory not found.
C:\Users\vas286\Desktop\FRST.txt => Moved successfully.
C:\Users\vas286\Desktop\FRSTLauncher (2).exe => Moved successfully.
"C:\Users\vas286\Desktop\Nepotvrzeno 604013.crdownload" => File/Directory not found.
"C:\Users\vas286\Desktop\Nepotvrzeno 565752.crdownload" => File/Directory not found.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\vas286\Desktop\zoek.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\vas286\Desktop\adwcleaner_4.101.exe => Moved successfully.
C:\Users\vas286\Desktop\attach.txt => Moved successfully.
C:\Users\vas286\Desktop\dds.txt => Moved successfully.
C:\Users\vas286\Desktop\dds.exe => Moved successfully.
C:\Windows\system32\Drivers\etc\hosts.20141113-170212.backup => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Windows\System32\Tasks\Safer-Networking => Moved successfully.
C:\Program Files (x86)\Spybot - Search & Destroy 2 => Moved successfully.
C:\ProgramData\Spybot - Search & Destroy => Moved successfully.
C:\sh4ldr => Moved successfully.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056 => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A1384146-40C9-45D9-8724-546D0D914293}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1384146-40C9-45D9-8724-546D0D914293}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Search Updater" => Key deleted successfully.
"HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Classes\.exe" => Key deleted successfully.
C:\ProgramData\TEMP => ":15B79D44" ADS removed successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 170 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-11-2014
Ran by vas286 at 2014-11-15 15:07:38 Run:1
Running from C:\Users\vas286\Desktop
Loaded Profile: vas286 (Available profiles: vas286)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [OEXPRESS] => [X]
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Nektra OEAPI] => [X]
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Run: [Google Update] => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe [107912 2014-10-21] (Google Inc.)
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\...\MountPoints2: {a040fe2d-9fe1-11df-95a2-506313b622f2} - G:\setup.exe
HKU\S-1-5-18\...\Policies\Explorer: [NoDriveTypeAutoRun] 0x20000000
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
BootExecute: autocheck autochk * sdnclean64.exe
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x846AFE7BD433CB01
URLSearchHook: HKCU - Default Value = {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-08-04]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-04]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi [Not Found]
FF Extension: No Name - C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{46e267d7-2aad-4738-adaf-d4d0a8fac9ea}.xpi [Not Found]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]
FF Extension: No Name - {c45c406e-ab73-11d8-be73-000a95be3b12} [Not Found]
FF Extension: No Name - {46e267d7-2aad-4738-adaf-d4d0a8fac9ea} [Not Found]
R2 MaintainerSvc3.32.7672459; C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056\maintainer.exe [123680 2014-11-15] ()
U3 amq4hxpx; C:\Windows\System32\Drivers\amq4hxpx.sys [0 ] (Microsoft Corporation)
S3 PCAlertDriver; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\NTGLM7X.sys [X]
S3 RushTopDevice; \??\C:\Program Files (x86)\MSI\FuzzyLogic4\RushTop.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S0 vmci; system32\DRIVERS\vmci.sys [X]
S3 VMnetAdapter; system32\DRIVERS\vmnetadapter.sys [X]
C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c9605
2014-11-15 14:48 - 2014-11-15 14:49 - 00017370 _____ () C:\Users\vas286\Desktop\FRST.txt
2014-11-15 14:46 - 2014-11-15 14:46 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\FRSTLauncher (2).exe
2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 604013.crdownload
2014-11-15 14:45 - 2014-11-15 14:45 - 00112640 _____ (forum.viry.cz) C:\Users\vas286\Desktop\Nepotvrzeno 565752.crdownload
2014-11-15 10:29 - 2014-11-15 09:51 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-11-15 09:55 - 2014-11-15 10:31 - 00015010 _____ () C:\zoek-results.log
2014-11-15 09:47 - 2014-11-15 10:20 - 00000000 ____D () C:\zoek_backup
2014-11-15 09:47 - 2014-11-15 09:47 - 01294848 _____ () C:\Users\vas286\Desktop\zoek.exe
2014-11-15 09:40 - 2014-11-15 09:42 - 00000000 ____D () C:\AdwCleaner
2014-11-15 09:37 - 2014-11-15 09:37 - 02140160 _____ () C:\Users\vas286\Desktop\adwcleaner_4.101.exe
2014-11-15 09:12 - 2014-11-15 09:12 - 00013496 _____ () C:\Users\vas286\Desktop\attach.txt
2014-11-15 09:12 - 2014-11-15 09:11 - 00015823 _____ () C:\Users\vas286\Desktop\dds.txt
2014-11-15 09:10 - 2014-11-15 09:10 - 00688992 ____R (Swearware) C:\Users\vas286\Desktop\dds.exe
2014-11-13 17:02 - 2010-10-03 12:20 - 00000904 _____ () C:\Windows\system32\Drivers\etc\hosts.20141113-170212.backup
2014-11-13 16:57 - 2014-11-15 10:30 - 00012590 _____ () C:\Windows\PFRO.log
2014-11-13 16:57 - 2014-11-15 10:30 - 00000672 _____ () C:\Windows\setupact.log
2014-11-13 16:57 - 2014-11-13 16:57 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-12 16:09 - 2014-11-12 16:09 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2014-11-09 12:47 - 2014-11-15 09:24 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-11-09 12:47 - 2014-11-13 17:00 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\sh4ldr
2014-11-09 09:30 - 2014-11-09 09:30 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-10-28 08:51 - 2014-11-15 09:45 - 00000000 ____D () C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => C:\Users\vas286\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {A1384146-40C9-45D9-8724-546D0D914293} - \Yahoo! Search Updater No Task File <==== ATTENTION
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Classes\.exe: exefile => <===== ATTENTION!
AlternateDataStreams: C:\ProgramData\TEMP:15B79D44
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Run\\OEXPRESS => value deleted successfully.
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Nektra OEAPI => value deleted successfully.
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully.
HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => value deleted successfully.
"HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a040fe2d-9fe1-11df-95a2-506313b622f2}" => Key deleted successfully.
"HKCR\CLSID\{a040fe2d-9fe1-11df-95a2-506313b622f2}" => Key not found.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoDriveTypeAutoRun => value deleted successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GDriveSharedOverlay" => Key deleted successfully.
"HKCR\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" => Key not found.
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache_TIMESTAMP => value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
"HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} => value deleted successfully.
"HKCR\CLSID\{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}" => Key not found.
C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} => Moved successfully.
C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} => Moved successfully.
C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi not found.
C:\Users\vas286\AppData\Roaming\Mozilla\Firefox\Profiles\adoinqh6.default\extensions\{46e267d7-2aad-4738-adaf-d4d0a8fac9ea}.xpi not found.
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} not found.
FF Extension: No Name - {c45c406e-ab73-11d8-be73-000a95be3b12} [Not Found] not found.
FF Extension: No Name - {46e267d7-2aad-4738-adaf-d4d0a8fac9ea} [Not Found] not found.
MaintainerSvc3.32.7672459 => Service deleted successfully.
amq4hxpx => Service deleted successfully.
PCAlertDriver => Service deleted successfully.
RushTopDevice => Service deleted successfully.
VBoxNetFlt => Service deleted successfully.
vmci => Service deleted successfully.
VMnetAdapter => Service deleted successfully.
"C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c9605" => File/Directory not found.
C:\Users\vas286\Desktop\FRST.txt => Moved successfully.
C:\Users\vas286\Desktop\FRSTLauncher (2).exe => Moved successfully.
"C:\Users\vas286\Desktop\Nepotvrzeno 604013.crdownload" => File/Directory not found.
"C:\Users\vas286\Desktop\Nepotvrzeno 565752.crdownload" => File/Directory not found.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\vas286\Desktop\zoek.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\vas286\Desktop\adwcleaner_4.101.exe => Moved successfully.
C:\Users\vas286\Desktop\attach.txt => Moved successfully.
C:\Users\vas286\Desktop\dds.txt => Moved successfully.
C:\Users\vas286\Desktop\dds.exe => Moved successfully.
C:\Windows\system32\Drivers\etc\hosts.20141113-170212.backup => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Windows\System32\Tasks\Safer-Networking => Moved successfully.
C:\Program Files (x86)\Spybot - Search & Destroy 2 => Moved successfully.
C:\ProgramData\Spybot - Search & Destroy => Moved successfully.
C:\sh4ldr => Moved successfully.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\ProgramData\e5c4ef79-068a-447e-b589-daa814c96056 => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3855174053-2276168570-2652203745-1000UA.job => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A1384146-40C9-45D9-8724-546D0D914293}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A1384146-40C9-45D9-8724-546D0D914293}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Yahoo! Search Updater" => Key deleted successfully.
"HKU\S-1-5-21-3855174053-2276168570-2652203745-1000\Software\Classes\.exe" => Key deleted successfully.
C:\ProgramData\TEMP => ":15B79D44" ADS removed successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 170 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: Problém s pomalým webovým prohlížečem
Supr, jak se chova nas pacient 
Re: Problém s pomalým webovým prohlížečem
úplně perfektně
moc Vám děkuju 
Re: Problém s pomalým webovým prohlížečem
Tak jeste uklidime
DelFix https://toolslib.net/downloads/finish/2/
Stahnete Ccleaner https://www.piriform.com/ccleaner/download/standard
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse 
- Stahnete a spustte
- Ponechte zatrzitkou pouze u volby Remote disinfection tools
- Kliknete na Run
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy
Re: Problém s pomalým webovým prohlížečem
Moc děkuju. Jede to úplně perfektně




Přispějete na provoz fóra?