Otravné reklami

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
???
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 16 Ún 2008 14:45

Otravné reklami

#1 Příspěvek od ??? »

Zdravím, prosím o kontrolu RSIT logu. Môj problém: keď zadávam hocijakú stránku tak ma to občas presmeruje na nejakú podivnú stránku: hxxp://adfoc.us/serve/?id=25497650908175

RSIT log:

Logfile of random's system information tool 1.10 (written by random/random)
Run by admin at 2014-11-24 21:25:06
Microsoft Windows 8.1
System drive C: has 103 GB (36%) free of 286 GB
Total RAM: 3982 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:13, on 24.11.2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\Garena Plus\ggdllhost.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?gd=&ctid=CT3 ... CE8F&SSPV=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [GarenaPlus] "C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe" -autolaunch
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
O4 - HKUS\S-1-5-21-3701647376-3946651554-1493002649-1003\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'UpdatusUser')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
O23 - Service: Asus WebStorage Windows Service - Unknown owner - C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Hi-Rez Studios - C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt and Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 10463 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe"
"C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe"
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe"
taskhostex.exe
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\Garena Plus\ggdllhost.exe" "C:\Program Files (x86)\Garena Plus\ggspawn.dll",rundll_entry
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe"
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe"
KBFiltr.exe
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\HPSIsvc.exe
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
"C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc

"C:\Program Files (x86)\PANDORA.TV\PanService\PanProcess.exe" PanProcess
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX3
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe"
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Program Files (x86)\Steam\config\htmlcache" -cookiepath "C:\Program Files (x86)\Steam\config\cookies" -steampid 4444 --blacklist-accelerated-compositing --process-per-tab --disable-accelerated-video-decode --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
dashost.exe {d00e39d6-a13b-4aa8-8d700f5d17a3a115}
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"

"C:\Program Files (x86)\Skype\Phone\Skype.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4508.0.2064753935\1280286238" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,17,38 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x0166 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3308 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group1 pct:10a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_89/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="4508.2.2061690939\655476461" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group1 pct:10a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_89/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="4508.3.656125452\1945737461" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group1 pct:10a stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/None/ExtensionInstallVerification/Enforce/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group3/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_89/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_05/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="4508.11.354771443\1047952182" /prefetch:673131151
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe22_ Global\UsGthrCtrlFltPipeMssGthrPipe22 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 564 572 580 65536 576
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey 6528A1A0-BE2B-534B-3BD0-254F0A48DA47 -Reinvoke

C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Users\admin\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2013-03-27 66688]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2013-10-01 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2013-10-01 771032]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2013-10-01 769496]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-05-30 13550152]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-05-20 1308232]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2013-03-27 132736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"GarenaPlus"=C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [2014-04-29 9936176]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2014-11-18 1940160]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2013-05-01 3187360]
"ASUSWebStorage"=C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [2012-12-19 3576784]
"RemoteControl10"=C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2012-03-28 91432]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"amd_dc_opt"=C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [2013-03-27 132736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2013-10-01 623104]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-11-24 21:25:06 ----D---- C:\rsit
2014-11-24 21:25:06 ----D---- C:\Program Files\trend micro
2014-11-19 20:40:48 ----A---- C:\WINDOWS\system32\kerberos.dll
2014-11-19 20:40:47 ----A---- C:\WINDOWS\SYSWOW64\pku2u.dll
2014-11-19 20:40:47 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2014-11-19 20:40:45 ----A---- C:\WINDOWS\system32\pku2u.dll
2014-11-12 08:52:41 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2014-11-12 08:52:41 ----A---- C:\WINDOWS\system32\schannel.dll
2014-11-12 08:52:40 ----A---- C:\WINDOWS\SYSWOW64\ncryptsslp.dll
2014-11-12 08:52:40 ----A---- C:\WINDOWS\system32\ncryptsslp.dll
2014-11-12 08:52:40 ----A---- C:\WINDOWS\system32\dpapisrv.dll
2014-11-12 08:52:35 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2014-11-12 08:52:35 ----A---- C:\WINDOWS\system32\msi.dll
2014-11-12 08:52:35 ----A---- C:\WINDOWS\system32\authui.dll
2014-11-12 08:52:33 ----A---- C:\WINDOWS\SYSWOW64\msihnd.dll
2014-11-12 08:52:33 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2014-11-12 08:52:33 ----A---- C:\WINDOWS\system32\msihnd.dll
2014-11-12 08:52:33 ----A---- C:\WINDOWS\system32\consent.exe
2014-11-12 08:52:32 ----A---- C:\WINDOWS\system32\appinfo.dll
2014-11-12 08:52:29 ----A---- C:\WINDOWS\system32\user32.dll
2014-11-12 08:52:28 ----A---- C:\WINDOWS\SYSWOW64\winshfhc.dll
2014-11-12 08:52:28 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2014-11-12 08:52:28 ----A---- C:\WINDOWS\system32\winshfhc.dll
2014-11-12 08:52:28 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2014-11-12 08:52:28 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2014-11-12 08:52:28 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2014-11-12 08:52:25 ----A---- C:\WINDOWS\system32\mshtml.dll
2014-11-12 08:52:23 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2014-11-12 08:51:55 ----A---- C:\WINDOWS\system32\ieframe.dll
2014-11-12 08:51:50 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2014-11-12 08:51:45 ----A---- C:\WINDOWS\system32\jscript9.dll
2014-11-12 08:51:43 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2014-11-12 08:51:42 ----A---- C:\WINDOWS\system32\wininet.dll
2014-11-12 08:51:41 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2014-11-12 08:51:41 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2014-11-12 08:51:41 ----A---- C:\WINDOWS\system32\urlmon.dll
2014-11-12 08:51:40 ----A---- C:\WINDOWS\system32\inetcomm.dll
2014-11-12 08:51:40 ----A---- C:\WINDOWS\system32\iertutil.dll
2014-11-12 08:51:40 ----A---- C:\WINDOWS\system32\actxprxy.dll
2014-11-12 08:51:39 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2014-11-12 08:51:39 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2014-11-12 08:51:38 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2014-11-12 08:51:38 ----A---- C:\WINDOWS\system32\msfeeds.dll
2014-11-12 08:51:38 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2014-11-12 08:51:38 ----A---- C:\WINDOWS\system32\jscript.dll
2014-11-12 08:51:38 ----A---- C:\WINDOWS\system32\ieui.dll
2014-11-12 08:51:37 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2014-11-12 08:51:37 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2014-11-12 08:51:37 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2014-11-12 08:51:36 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2014-11-12 08:51:36 ----A---- C:\WINDOWS\system32\vbscript.dll
2014-11-12 08:51:35 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2014-11-12 08:51:35 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2014-11-12 08:51:35 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2014-11-12 08:51:35 ----A---- C:\WINDOWS\system32\dxtrans.dll
2014-11-12 08:51:35 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2014-11-12 08:51:34 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2014-11-12 08:51:34 ----A---- C:\WINDOWS\system32\webcheck.dll
2014-11-12 08:51:34 ----A---- C:\WINDOWS\system32\ieetwproxystub.dll
2014-11-12 08:51:34 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2014-11-12 08:51:33 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2014-11-12 08:51:32 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2014-11-12 08:51:32 ----A---- C:\WINDOWS\SYSWOW64\hlink.dll
2014-11-12 08:51:32 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2014-11-12 08:51:32 ----A---- C:\WINDOWS\system32\hlink.dll
2014-11-12 08:51:31 ----A---- C:\WINDOWS\SYSWOW64\ieUnatt.exe
2014-11-12 08:51:31 ----A---- C:\WINDOWS\SYSWOW64\iesysprep.dll
2014-11-12 08:51:31 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2014-11-12 08:51:31 ----A---- C:\WINDOWS\system32\msrating.dll
2014-11-12 08:51:31 ----A---- C:\WINDOWS\system32\ieUnatt.exe
2014-11-12 08:51:31 ----A---- C:\WINDOWS\system32\iesysprep.dll
2014-11-12 08:51:31 ----A---- C:\WINDOWS\system32\iepeers.dll
2014-11-12 08:51:31 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2014-11-12 08:51:31 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2014-11-12 08:51:30 ----A---- C:\WINDOWS\SYSWOW64\occache.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\SYSWOW64\msfeedsbs.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\SYSWOW64\inseng.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\system32\mshtmled.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\system32\jsproxy.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-11-12 08:51:30 ----A---- C:\WINDOWS\system32\inseng.dll
2014-11-12 08:51:29 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2014-11-12 08:51:29 ----A---- C:\WINDOWS\SYSWOW64\JavaScriptCollectionAgent.dll
2014-11-12 08:51:29 ----A---- C:\WINDOWS\SYSWOW64\imgutil.dll
2014-11-12 08:51:29 ----A---- C:\WINDOWS\SYSWOW64\iexpress.exe
2014-11-12 08:51:29 ----A---- C:\WINDOWS\SYSWOW64\IEAdvpack.dll
2014-11-12 08:51:29 ----A---- C:\WINDOWS\system32\occache.dll
2014-11-12 08:51:29 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2014-11-12 08:51:29 ----A---- C:\WINDOWS\system32\imgutil.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\SYSWOW64\wextract.exe
2014-11-12 08:51:28 ----A---- C:\WINDOWS\SYSWOW64\url.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\SYSWOW64\pngfilt.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\SYSWOW64\licmgr10.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\SYSWOW64\iesetup.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\SYSWOW64\iernonce.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\SYSWOW64\ieetwproxystub.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\system32\url.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\system32\pngfilt.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\system32\licmgr10.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\system32\iernonce.dll
2014-11-12 08:51:28 ----A---- C:\WINDOWS\system32\IEAdvpack.dll
2014-11-12 08:51:27 ----A---- C:\WINDOWS\system32\wextract.exe
2014-11-12 08:51:27 ----A---- C:\WINDOWS\system32\iesetup.dll
2014-11-12 08:51:25 ----A---- C:\WINDOWS\SYSWOW64\mshta.exe
2014-11-12 08:51:25 ----A---- C:\WINDOWS\SYSWOW64\msfeedssync.exe
2014-11-12 08:51:25 ----A---- C:\WINDOWS\system32\iexpress.exe
2014-11-12 08:51:24 ----A---- C:\WINDOWS\system32\mshta.exe
2014-11-12 08:51:24 ----A---- C:\WINDOWS\system32\msfeedssync.exe
2014-11-12 08:51:18 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2014-11-12 08:51:17 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2014-11-12 08:51:17 ----A---- C:\WINDOWS\system32\lsasrv.dll
2014-11-12 08:51:17 ----A---- C:\WINDOWS\system32\certcli.dll
2014-11-12 08:51:16 ----A---- C:\WINDOWS\SYSWOW64\msaudite.dll
2014-11-12 08:51:16 ----A---- C:\WINDOWS\SYSWOW64\adtschema.dll
2014-11-12 08:51:16 ----A---- C:\WINDOWS\system32\rfxvmt.dll
2014-11-12 08:51:16 ----A---- C:\WINDOWS\system32\rdpudd.dll
2014-11-12 08:51:16 ----A---- C:\WINDOWS\system32\msaudite.dll
2014-11-12 08:51:16 ----A---- C:\WINDOWS\system32\drivers\rdpvideominiport.sys
2014-11-12 08:51:16 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2014-11-12 08:51:16 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2014-11-12 08:51:16 ----A---- C:\WINDOWS\system32\adtschema.dll
2014-11-12 08:51:01 ----A---- C:\WINDOWS\system32\oleaut32.dll
2014-11-12 08:51:00 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2014-11-12 08:50:54 ----A---- C:\WINDOWS\system32\wuaueng.dll
2014-11-12 08:50:53 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2014-11-12 08:50:53 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2014-11-12 08:50:53 ----A---- C:\WINDOWS\system32\wucltux.dll
2014-11-12 08:50:53 ----A---- C:\WINDOWS\system32\wuapi.dll
2014-11-12 08:50:52 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2014-11-12 08:50:52 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2014-11-12 08:50:52 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2014-11-12 08:50:52 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2014-11-12 08:50:52 ----A---- C:\WINDOWS\system32\wuwebv.dll
2014-11-12 08:50:52 ----A---- C:\WINDOWS\system32\wups2.dll
2014-11-12 08:50:52 ----A---- C:\WINDOWS\system32\wups.dll
2014-11-12 08:50:52 ----A---- C:\WINDOWS\system32\wudriver.dll
2014-11-12 08:50:52 ----A---- C:\WINDOWS\system32\wuauclt.exe
2014-11-12 08:50:52 ----A---- C:\WINDOWS\system32\wuapp.exe
2014-11-12 08:50:52 ----A---- C:\WINDOWS\system32\wuaext.dll
2014-11-12 08:50:40 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2014-11-12 08:50:38 ----A---- C:\WINDOWS\system32\msxml3.dll
2014-11-12 08:50:27 ----A---- C:\WINDOWS\system32\audiosrv.dll
2014-11-12 08:50:26 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2014-11-12 08:50:26 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2014-11-12 08:50:26 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2014-11-12 08:50:26 ----A---- C:\WINDOWS\system32\EncDump.dll
2014-11-12 08:50:26 ----A---- C:\WINDOWS\system32\AudioSes.dll
2014-11-12 08:50:26 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2014-11-12 08:50:26 ----A---- C:\WINDOWS\system32\AudioEng.dll
2014-11-12 08:50:26 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-11-12 08:50:26 ----A---- C:\WINDOWS\system32\audiodg.exe
2014-11-12 08:50:24 ----A---- C:\WINDOWS\system32\win32k.sys
2014-11-12 08:50:23 ----A---- C:\WINDOWS\SYSWOW64\packager.dll
2014-11-12 08:50:23 ----A---- C:\WINDOWS\system32\packager.dll
2014-11-12 08:50:20 ----A---- C:\WINDOWS\system32\shell32.dll
2014-11-12 08:50:19 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2014-11-12 08:50:17 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2014-11-12 08:50:16 ----A---- C:\WINDOWS\system32\twinui.dll
2014-11-12 08:50:16 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2014-11-12 08:50:15 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2014-11-12 08:50:14 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-11-12 08:50:14 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2014-11-12 08:50:14 ----A---- C:\WINDOWS\system32\localspl.dll
2014-11-12 08:50:12 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2014-11-12 08:50:12 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2014-11-12 08:50:12 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2014-11-12 08:50:12 ----A---- C:\WINDOWS\system32\win32spl.dll
2014-11-12 08:50:12 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2014-11-12 08:50:11 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2014-11-12 08:50:11 ----A---- C:\WINDOWS\system32\WsmSvc.dll
2014-11-12 08:50:11 ----A---- C:\WINDOWS\system32\puiobj.dll
2014-11-12 08:50:10 ----AC---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2014-11-12 08:50:10 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2014-11-12 08:50:09 ----A---- C:\WINDOWS\SYSWOW64\untfs.dll
2014-11-12 08:50:09 ----A---- C:\WINDOWS\system32\untfs.dll
2014-11-12 08:50:09 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2014-11-12 08:50:08 ----A---- C:\WINDOWS\system32\FXSCOMEX.dll
2014-11-12 08:50:07 ----A---- C:\WINDOWS\SYSWOW64\FXSAPI.dll
2014-11-12 08:50:07 ----A---- C:\WINDOWS\system32\FXSAPI.dll
2014-11-09 16:26:20 ----D---- C:\ProgramData\Sibelius Software
2014-11-09 16:25:15 ----D---- C:\Users\admin\AppData\Roaming\Sibelius Software
2014-11-09 16:13:45 ----D---- C:\Program Files (x86)\Sibelius Software
2014-11-09 13:49:28 ----D---- C:\Users\admin\AppData\Roaming\MusE
2014-11-09 13:48:50 ----D---- C:\Program Files (x86)\MuseScore

======List of files/folders modified in the last 1 month======

2014-11-24 21:25:13 ----D---- C:\WINDOWS\Prefetch
2014-11-24 21:25:06 ----RD---- C:\Program Files
2014-11-24 21:24:53 ----D---- C:\Users\admin\AppData\Roaming\Skype
2014-11-24 21:24:35 ----D---- C:\WINDOWS\Temp
2014-11-24 21:02:02 ----D---- C:\WINDOWS\system32\sru
2014-11-24 20:27:06 ----D---- C:\WINDOWS\system32\Tasks
2014-11-24 10:32:34 ----D---- C:\WINDOWS\Microsoft.NET
2014-11-23 22:30:17 ----D---- C:\WINDOWS\system32\config
2014-11-23 22:24:24 ----SHD---- C:\System Volume Information
2014-11-23 20:28:56 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2014-11-23 20:27:07 ----D---- C:\Program Files (x86)\Steam
2014-11-23 13:36:24 ----D---- C:\WINDOWS\AppReadiness
2014-11-23 05:18:46 ----HD---- C:\Program Files\WindowsApps
2014-11-22 09:35:19 ----D---- C:\WINDOWS\WinSxS
2014-11-21 08:09:36 ----D---- C:\Users\admin\AppData\Roaming\uTorrent
2014-11-20 07:44:39 ----D---- C:\WINDOWS\Inf
2014-11-20 07:43:40 ----RD---- C:\WINDOWS\System32
2014-11-20 07:43:40 ----D---- C:\WINDOWS\SysWOW64
2014-11-19 16:32:12 ----D---- C:\WINDOWS\CbsTemp
2014-11-17 13:38:07 ----D---- C:\Windows
2014-11-16 13:04:02 ----SHD---- C:\WINDOWS\Installer
2014-11-16 12:59:10 ----RD---- C:\Program Files (x86)
2014-11-16 12:59:07 ----D---- C:\WINDOWS\Tasks
2014-11-16 12:25:31 ----D---- C:\WINDOWS\system32\DriverStore
2014-11-15 19:54:40 ----RSD---- C:\WINDOWS\assembly
2014-11-13 21:38:09 ----D---- C:\WINDOWS\rescache
2014-11-12 23:19:00 ----D---- C:\WINDOWS\system32\drivers
2014-11-12 23:19:00 ----D---- C:\Program Files\Windows Defender
2014-11-12 23:18:59 ----D---- C:\Program Files (x86)\Windows Defender
2014-11-12 23:18:57 ----D---- C:\WINDOWS\system32\wbem
2014-11-12 23:18:56 ----D---- C:\WINDOWS\SYSWOW64\en-US
2014-11-12 23:18:51 ----D---- C:\WINDOWS\system32\en-US
2014-11-12 23:18:48 ----D---- C:\WINDOWS\system32\sk-SK
2014-11-12 23:18:47 ----D---- C:\WINDOWS\SYSWOW64\migration
2014-11-12 23:18:47 ----D---- C:\WINDOWS\system32\migration
2014-11-12 23:18:47 ----D---- C:\Program Files\Internet Explorer
2014-11-12 23:18:47 ----D---- C:\Program Files (x86)\Internet Explorer
2014-11-12 23:18:43 ----RD---- C:\WINDOWS\ToastData
2014-11-12 23:18:42 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2014-11-12 23:18:41 ----D---- C:\WINDOWS\apppatch
2014-11-12 21:47:35 ----D---- C:\WINDOWS\system32\MRT
2014-11-12 09:01:13 ----D---- C:\WINDOWS\debug
2014-11-12 09:01:09 ----A---- C:\WINDOWS\system32\MRT.exe
2014-11-12 08:48:26 ----D---- C:\WINDOWS\system32\catroot2
2014-11-09 16:26:20 ----HD---- C:\ProgramData
2014-11-09 16:15:53 ----RSD---- C:\WINDOWS\Fonts
2014-11-09 15:33:57 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2014-11-08 22:48:02 ----D---- C:\ProgramData\Skype
2014-11-01 20:00:32 ----D---- C:\WINDOWS\system32\NDF
2014-11-01 18:49:46 ----D---- C:\WINDOWS\ModemLogs
2014-10-30 23:07:45 ----D---- C:\Program Files (x86)\The KMPlayer
2014-10-30 12:25:26 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2014-10-30 01:55:02 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2014-10-28 21:25:08 ----D---- C:\WINDOWS\SoftwareDistribution
2014-10-28 20:56:25 ----D---- C:\Users\admin\AppData\Roaming\DAEMON Tools Lite
2014-10-28 20:56:13 ----D---- C:\WINDOWS\Logs
2014-10-28 20:53:57 ----D---- C:\Program Files\CCleaner

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-14 647736]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2013-12-10 32544]
R0 Tpkd;Tpkd; C:\WINDOWS\system32\drivers\Tpkd.sys [2009-12-23 105592]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 dtsoftbus01;@oem17.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2013-10-30 283064]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R3 AiCharger;ASUS Charger Driver; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [2012-09-18 17152]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 ATP;@oem6.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2013-04-16 65784]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2014-01-28 593000]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-01-31 81920]
R3 HIDSwitch;@oem12.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2012-05-31 21152]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-10-01 4177920]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-06-04 3441992]
R3 IntcDAud;@oem32.inf,%IntcDAud.SvcDesc%;Intel(R) Zvuk pre obrazovky; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-01-09 342528]
R3 iwdbus;@oem40.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-08-22 26008]
R3 kbfiltr;@oem15.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-02 14992]
R3 MEIx64;@oem30.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-12-10 12572960]
R3 RSBASTOR;@oem4.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\WINDOWS\system32\DRIVERS\RtsBaStor.sys [2012-10-08 298640]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2013-08-22 212224]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys []
S3 AthBTPort;@oem11.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2013-03-27 89168]
S3 BTATH_A2DP;@oem10.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2013-03-27 346192]
S3 btath_avdt;@oem10.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2013-03-27 115280]
S3 BTATH_HCRP;@oem14.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2013-03-27 179432]
S3 BTATH_LWFLT;@oem16.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2013-03-27 77464]
S3 BTATH_RCP;@oem18.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2013-03-27 136784]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2013-08-22 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2014-07-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-07-24 1200640]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys []
S3 GPU-Z;GPU-Z; \??\C:\Users\admin\AppData\Local\Temp\GPU-Z.sys []
S3 intaud_WaveExtensible;@oem39.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-08-22 39320]
S3 MAUSBMICRO;@oem43.inf,%MAUSBMICRO_SvcDesc%;Service for M-Audio Micro; C:\WINDOWS\system32\DRIVERS\MAudioMicro.sys [2009-09-03 187912]
S3 mvusbews;@oem28.inf,%mvusbews.SvcDesc%;USB EWS Device; C:\WINDOWS\System32\Drivers\mvusbews.sys [2012-12-24 20480]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2014-01-27 167424]
S3 usbaudio;@wdma_usb.inf,%USBAudio.SvcDesc%;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2013-12-13 121088]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2013-08-22 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2012-10-05 110976]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-04-13 277120]
R2 Asus WebStorage Windows Service;Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [2012-12-19 72192]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2013-03-27 227968]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [2014-08-22 9216]
R2 HPSIService;HP SI Service; C:\Windows\system32\HPSIsvc.exe [2010-04-29 127800]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-09-13 2466448]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-06-27 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-07-08 884512]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-05-16 1826592]
R2 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [2012-09-28 625304]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-11-18 833728]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-31 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-11 267440]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-10-01 279000]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-07-09 43696]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-31 116648]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------
Naposledy upravil(a) vyosek dne 24 Lis 2014 22:11, celkem upraveno 1 x.
Důvod: Z bezpecnostnich duvodu zneaktivnen link

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Otravné reklami

#2 Příspěvek od altrok »

Dobry vecer :bye:

:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Clean
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

???
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 16 Ún 2008 14:45

Re: Otravné reklami

#3 Příspěvek od ??? »

Keď som dal clean prvýkrat program prestal pracovať..na druhýkrat to prebehlo v poriadku. Inak vyzerá, že ma to tam už nehádže na tú stránku.

Tu je log:

# AdwCleaner v4.102 - Report created 24/11/2014 at 22:00:04
# Updated 23/11/2014 by Xplode
# Database : 2014-11-24.1 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : admin - ASUS
# Running from : C:\Users\admin\Desktop\adwcleaner_4.102.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : PanService

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\drivergenius
Folder Deleted : C:\Program Files (x86)\GreenTree Applications
Folder Deleted : C:\Program Files (x86)\PANDORA.TV
File Deleted : C:\WINDOWS\System32\roboot64.exe

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\PIP
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IM
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90120000-00B2-041B-0000-0000000FF1CE}

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17416

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v39.0.2171.65

[C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3310393&octid=EB_ORIGINAL_CTID&ISID=M780EDFA5-7C15-4B36-BC57-4132A6AA4510&SearchSource=58&CUI=&UM=5&UP=SP80704405-9CF5-448C-B0F4-F1644BB1CE8F&q={searchTerms}&SSPV=
[C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3310393&octid=EB_ORIGINAL_CTID&ISID=M780EDFA5-7C15-4B36-BC57-4132A6AA4510&SearchSource=58&CUI=&UM=5&UP=SP80704405-9CF5-448C-B0F4-F1644BB1CE8F&q={searchTerms}&SSPV=
[C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}

-\\ Comodo Dragon v

[C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3310393&octid=EB_ORIGINAL_CTID&ISID=M780EDFA5-7C15-4B36-BC57-4132A6AA4510&SearchSource=58&CUI=&UM=5&UP=SP80704405-9CF5-448C-B0F4-F1644BB1CE8F&q={searchTerms}&SSPV=
[C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3310393&octid=EB_ORIGINAL_CTID&ISID=M780EDFA5-7C15-4B36-BC57-4132A6AA4510&SearchSource=58&CUI=&UM=5&UP=SP80704405-9CF5-448C-B0F4-F1644BB1CE8F&q={searchTerms}&SSPV=
[C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}

*************************

AdwCleaner[R0].txt - [2457 octets] - [24/11/2014 21:57:02]
AdwCleaner[R1].txt - [2576 octets] - [24/11/2014 21:59:10]
AdwCleaner[S0].txt - [309 octets] - [24/11/2014 21:58:21]
AdwCleaner[S1].txt - [2996 octets] - [24/11/2014 22:00:04]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3056 octets] ##########

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Otravné reklami

#4 Příspěvek od altrok »

:arrow: Tak to jeste docistime poradne ;)

:arrow: Ulozte na plochu zoek.exe http://hijackthis.nl/smeenk/zoek.htm
  • spustte jako spravce
  • do velkeho okna zkopirujte script uvedeny nize
  • kliknete na Run script
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\zoek-results.log) - vlozte mi jej do pristi odpovedi

    Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

???
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 16 Ún 2008 14:45

Re: Otravné reklami

#5 Příspěvek od ??? »

Zoek.exe v5.0.0.0 Updated 24-11-2014
Tool run by admin on po 24.11.2014 at 22:12:53,51.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\admin\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

24.11.2014 22:14:24 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~2\InterLok deleted successfully
C:\Users\admin\AppData\Roaming\Awesomium deleted successfully
C:\Users\admin\AppData\Local\CrashDumps deleted successfully
C:\Users\admin\AppData\Local\ErfNvrdCfxD deleted successfully
C:\Users\admin\AppData\Local\NVIDIA deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3701647376-3946651554-1493002649-1002\Software\Microsoft\Internet Explorer\SearchScopes\{0CDBB3F2-434D-4B89-A7BF-0AC27DE14606} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Users\admin\AppData\Roaming\burnaware.ini deleted
C:\PROGRA~3\SetStretch.VBS deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\admin\Downloads\SoftonicDownloader_for_mkv-player.exe deleted
C:\Users\admin\Downloads\SoftonicDownloader_for_mywinlocker.exe deleted
C:\Users\admin\Downloads\bs_MyWinLocker.exe deleted
"C:\ProgramData\T2" deleted

==== Chromium Look ======================

AdBlock Premium - admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0CDBB3F2-434D-4B89-A7BF-0AC27DE14606}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0CDBB3F2-434D-4B89-A7BF-0AC27DE14606}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=6 folders=0 1011522 bytes)

==== Empty Temp Folders ======================

C:\Users\admin\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\admin\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp\MpCmdRun.log" not found

==== EOF on po 24.11.2014 at 22:23:55,45 ======================

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Otravné reklami

#6 Příspěvek od altrok »

:arrow: Dejte novy log FRST.txt, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

???
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 16 Ún 2008 14:45

Re: Otravné reklami

#7 Příspěvek od ??? »

addition v prilohe :)

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2014 01
Ran by admin (administrator) on ASUS on 24-11-2014 22:33:23
Running from C:\Users\admin\Desktop
Loaded Profiles: admin & UpdatusUser (Available profiles: admin & UpdatusUser)
Platform: Windows 8.1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
() C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
() C:\Program Files (x86)\Garena Plus\ggdllhost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(forum.viry.cz) C:\Users\admin\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13550152 2013-05-30] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1308232 2013-05-20] (Realtek Semiconductor)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-05-01] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [3576784 2012-12-19] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-03-27] ( (Atheros Communications))
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [9936176 2014-04-29] ()
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1940160 2014-11-18] (Valve Corporation)
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\MountPoints2: {a99fa24c-d1c4-11e3-bf55-ac220bac81f5} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\MountPoints2: {e731eaaf-493f-11e3-be86-240a644d9d7e} - "G:\SISetup.exe"
HKU\S-1-5-21-3701647376-3946651554-1493002649-1003\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2013-08-22] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
URLSearchHook: [S-1-5-21-3701647376-3946651554-1493002649-1003] ATTENTION ==> Default URLSearchHook is missing.
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... &pc=ASU2JS
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... &pc=ASU2JS
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... &pc=ASU2JS
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... &pc=ASU2JS
SearchScopes: HKU\S-1-5-21-3701647376-3946651554-1493002649-1002 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3701647376-3946651554-1493002649-1002 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
Tcpip\Parameters: [DhcpNameServer] 94.249.192.82 8.8.8.8

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://google.sk/
CHR StartupUrls: Default -> "hxxp://google.sk/"
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentácie Google) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-24]
CHR Extension: (Dokumenty Google) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-31]
CHR Extension: (Disk Google) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-31]
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-31]
CHR Extension: (AdBlocker - Blokovač reklám pre YouTube™) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2014-03-01]
CHR Extension: (Hľadať v Google) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-31]
CHR Extension: (Tabuľky Google) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-24]
CHR Extension: (AdBlock Premium) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj [2014-10-28]
CHR Extension: (Peňaženka Google) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-31]
CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-31]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [72192 2012-12-19] () [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [227968 2013-03-27] (Qualcomm Atheros Commnucations)
R2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-08-22] (Hi-Rez Studios) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-03-27] (Atheros) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-16] (ASUS Corporation)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-03-27] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-10-30] (Disc Soft Ltd)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
S3 MAUSBMICRO; C:\Windows\system32\DRIVERS\MAudioMicro.sys [187912 2009-09-03] (Avid Technology, Inc.)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2012-12-24] (Marvell Semiconductor, Inc.)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S1 cmdHlp; System32\DRIVERS\cmdhlp.sys [X]
S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [X]
S3 GPU-Z; \??\C:\Users\admin\AppData\Local\Temp\GPU-Z.sys [X]
S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-24 22:33 - 2014-11-24 22:33 - 00016554 _____ () C:\Users\admin\Desktop\FRST.txt
2014-11-24 22:32 - 2014-11-24 22:33 - 00000000 ____D () C:\FRST
2014-11-24 22:32 - 2014-11-24 22:32 - 00112640 _____ (forum.viry.cz) C:\Users\admin\Downloads\FRSTLauncher.exe
2014-11-24 22:32 - 2014-11-24 22:32 - 00112640 _____ (forum.viry.cz) C:\Users\admin\Desktop\FRSTLauncher.exe
2014-11-24 22:31 - 2014-11-24 22:30 - 02118144 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2014-11-24 22:30 - 2014-11-24 22:30 - 02118144 _____ (Farbar) C:\Users\admin\Downloads\FRST64.exe
2014-11-24 22:22 - 2014-11-24 22:12 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-11-24 22:13 - 2014-11-24 22:23 - 00006617 _____ () C:\zoek-results.log
2014-11-24 22:12 - 2014-11-24 22:21 - 00000000 ____D () C:\zoek_backup
2014-11-24 22:12 - 2014-11-24 22:12 - 01294848 _____ () C:\Users\admin\Downloads\zoek.exe
2014-11-24 22:12 - 2014-11-24 22:12 - 01294848 _____ () C:\Users\admin\Desktop\zoek.exe
2014-11-24 21:56 - 2014-11-24 22:00 - 00000000 ____D () C:\AdwCleaner
2014-11-24 21:55 - 2014-11-24 21:55 - 02148864 _____ () C:\Users\admin\Desktop\adwcleaner_4.102.exe
2014-11-24 21:54 - 2014-11-24 21:55 - 02148864 _____ () C:\Users\admin\Downloads\adwcleaner_4.102.exe
2014-11-24 21:25 - 2014-11-24 21:25 - 00000000 ____D () C:\rsit
2014-11-24 21:25 - 2014-11-24 21:25 - 00000000 ____D () C:\Program Files\trend micro
2014-11-24 21:24 - 2014-11-24 21:24 - 01222144 _____ () C:\Users\admin\Downloads\RSITx64.exe
2014-11-21 14:00 - 2014-11-21 14:00 - 00000000 ____D () C:\Users\admin\Desktop\SWAY
2014-11-20 22:25 - 2014-11-20 22:29 - 214326786 _____ () C:\Users\admin\Downloads\[CNT]_Naruto_Shippuuden_387_[A7117964].mkv
2014-11-20 22:25 - 2014-11-20 22:25 - 00016913 _____ () C:\Users\admin\Downloads\[CNT]_Naruto_Shippuuden_387_[A7117964].mkv.torrent
2014-11-19 20:40 - 2014-11-10 00:19 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2014-11-19 20:40 - 2014-11-10 00:19 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2014-11-19 20:40 - 2014-11-10 00:18 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2014-11-19 20:40 - 2014-11-10 00:18 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2014-11-16 12:19 - 2014-11-16 12:20 - 00000000 ____D () C:\Users\admin\Downloads\The.100.Year.Old.Man.Who.Climbed.Out.the.Window.and.Disappeared.2013.BDRip.XViD.MP3.CZ-GRiNGO
2014-11-16 12:18 - 2014-11-16 12:18 - 00013325 _____ () C:\Users\admin\Downloads\[SkT]Stolety_starik,_ktery_vylezl_z_okna_a_zmizel_-_Hundraaringen_som_klev_ut_genom_fonstret_och_forsvann_(2013)(CZ)_=_CSFD_78%.torrent
2014-11-15 18:59 - 2014-11-15 20:45 - 780621824 _____ () C:\Users\admin\Downloads\Znova-chuť-žiť.avi
2014-11-13 23:15 - 2014-11-13 23:20 - 198583085 _____ () C:\Users\admin\Downloads\[CNT]_Naruto_Shippuuden_386_[9E878C4C].mkv
2014-11-13 23:15 - 2014-11-13 23:15 - 00015713 _____ () C:\Users\admin\Downloads\[CNT]_Naruto_Shippuuden_386_[9E878C4C].mkv.torrent
2014-11-13 09:57 - 2014-11-24 22:23 - 00003496 _____ () C:\WINDOWS\System32\Tasks\gg_uac_daemon_admin
2014-11-12 08:52 - 2014-10-31 06:28 - 25110016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-11-12 08:52 - 2014-10-31 04:42 - 19781632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-11-12 08:52 - 2014-10-13 03:33 - 00116032 _____ (Microsoft Corporation) C:\WINDOWS\system32\consent.exe
2014-11-12 08:52 - 2014-10-11 01:58 - 03320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-11-12 08:52 - 2014-10-11 01:53 - 03607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-11-12 08:52 - 2014-10-08 08:30 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2014-11-12 08:52 - 2014-10-08 08:09 - 00428032 _____ (Microsoft Corporation) C:\WINDOWS\system32\msihnd.dll
2014-11-12 08:52 - 2014-10-08 07:27 - 00325120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msihnd.dll
2014-11-12 08:52 - 2014-10-08 06:32 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-11-12 08:52 - 2014-10-08 06:19 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-11-12 08:52 - 2014-09-27 08:13 - 00104336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2014-11-12 08:52 - 2014-09-27 06:24 - 00088800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2014-11-12 08:52 - 2014-09-27 04:38 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2014-11-12 08:52 - 2014-09-27 04:30 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2014-11-12 08:52 - 2014-09-27 04:17 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2014-11-12 08:52 - 2014-09-22 05:38 - 01519488 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2014-11-12 08:52 - 2014-09-22 04:06 - 00258368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-11-12 08:52 - 2014-09-22 04:06 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2014-11-12 08:52 - 2014-09-22 03:49 - 00035320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-11-12 08:52 - 2014-09-19 01:16 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2014-11-12 08:52 - 2014-09-02 23:08 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
2014-11-12 08:52 - 2014-09-02 23:08 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
2014-11-12 08:51 - 2014-10-31 06:12 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wextract.exe
2014-11-12 08:51 - 2014-10-31 06:12 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshta.exe
2014-11-12 08:51 - 2014-10-31 06:10 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iexpress.exe
2014-11-12 08:51 - 2014-10-31 06:09 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pngfilt.dll
2014-11-12 08:51 - 2014-10-31 06:08 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedssync.exe
2014-11-12 08:51 - 2014-10-31 06:06 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-11-12 08:51 - 2014-10-31 06:06 - 00237568 _____ (Microsoft Corporation) C:\WINDOWS\system32\url.dll
2014-11-12 08:51 - 2014-10-31 06:06 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-11-12 08:51 - 2014-10-31 06:06 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-11-12 08:51 - 2014-10-31 06:05 - 02884096 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-11-12 08:51 - 2014-10-31 06:05 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-11-12 08:51 - 2014-10-31 06:04 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-11-12 08:51 - 2014-10-31 05:57 - 00054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-11-12 08:51 - 2014-10-31 05:56 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-11-12 08:51 - 2014-10-31 05:54 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\IEAdvpack.dll
2014-11-12 08:51 - 2014-10-31 05:53 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2014-11-12 08:51 - 2014-10-31 05:52 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2014-11-12 08:51 - 2014-10-31 05:51 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-11-12 08:51 - 2014-10-31 05:51 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-11-12 08:51 - 2014-10-31 05:51 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-11-12 08:51 - 2014-10-31 05:50 - 06040064 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-11-12 08:51 - 2014-10-31 05:50 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-11-12 08:51 - 2014-10-31 05:40 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\licmgr10.dll
2014-11-12 08:51 - 2014-10-31 05:38 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-11-12 08:51 - 2014-10-31 05:30 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-11-12 08:51 - 2014-10-31 05:29 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-11-12 08:51 - 2014-10-31 05:29 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2014-11-12 08:51 - 2014-10-31 05:28 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
2014-11-12 08:51 - 2014-10-31 05:25 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-11-12 08:51 - 2014-10-31 05:24 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-11-12 08:51 - 2014-10-31 05:24 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeedsbs.dll
2014-11-12 08:51 - 2014-10-31 05:23 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-11-12 08:51 - 2014-10-31 05:21 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-11-12 08:51 - 2014-10-31 05:19 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\occache.dll
2014-11-12 08:51 - 2014-10-31 05:15 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2014-11-12 08:51 - 2014-10-31 05:08 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2014-11-12 08:51 - 2014-10-31 05:06 - 00372736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-11-12 08:51 - 2014-10-31 05:05 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-11-12 08:51 - 2014-10-31 05:05 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-11-12 08:51 - 2014-10-31 05:03 - 02124288 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-11-12 08:51 - 2014-10-31 04:59 - 14390272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-11-12 08:51 - 2014-10-31 04:45 - 02365440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-11-12 08:51 - 2014-10-31 04:44 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-11-12 08:51 - 2014-10-31 04:42 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\imgutil.dll
2014-11-12 08:51 - 2014-10-31 04:32 - 01550336 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-11-12 08:51 - 2014-10-31 04:28 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wextract.exe
2014-11-12 08:51 - 2014-10-31 04:28 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshta.exe
2014-11-12 08:51 - 2014-10-31 04:27 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iexpress.exe
2014-11-12 08:51 - 2014-10-31 04:26 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pngfilt.dll
2014-11-12 08:51 - 2014-10-31 04:25 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedssync.exe
2014-11-12 08:51 - 2014-10-31 04:24 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-11-12 08:51 - 2014-10-31 04:24 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\url.dll
2014-11-12 08:51 - 2014-10-31 04:24 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-11-12 08:51 - 2014-10-31 04:23 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2014-11-12 08:51 - 2014-10-31 04:23 - 00047616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-11-12 08:51 - 2014-10-31 04:22 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-11-12 08:51 - 2014-10-31 04:20 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-11-12 08:51 - 2014-10-31 04:18 - 02277376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-11-12 08:51 - 2014-10-31 04:16 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-11-12 08:51 - 2014-10-31 04:15 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-11-12 08:51 - 2014-10-31 04:14 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IEAdvpack.dll
2014-11-12 08:51 - 2014-10-31 04:13 - 00478208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2014-11-12 08:51 - 2014-10-31 04:13 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2014-11-12 08:51 - 2014-10-31 04:12 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-11-12 08:51 - 2014-10-31 04:12 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-11-12 08:51 - 2014-10-31 04:11 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-11-12 08:51 - 2014-10-31 04:03 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licmgr10.dll
2014-11-12 08:51 - 2014-10-31 04:02 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-11-12 08:51 - 2014-10-31 03:57 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-12 08:51 - 2014-10-31 03:56 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inseng.dll
2014-11-12 08:51 - 2014-10-31 03:56 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-11-12 08:51 - 2014-10-31 03:56 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2014-11-12 08:51 - 2014-10-31 03:53 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-11-12 08:51 - 2014-10-31 03:53 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeedsbs.dll
2014-11-12 08:51 - 2014-10-31 03:52 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-11-12 08:51 - 2014-10-31 03:51 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2014-11-12 08:51 - 2014-10-31 03:50 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-11-12 08:51 - 2014-10-31 03:48 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\occache.dll
2014-11-12 08:51 - 2014-10-31 03:46 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-11-12 08:51 - 2014-10-31 03:46 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2014-11-12 08:51 - 2014-10-31 03:42 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2014-11-12 08:51 - 2014-10-31 03:40 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-11-12 08:51 - 2014-10-31 03:40 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-11-12 08:51 - 2014-10-31 03:39 - 02051072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-11-12 08:51 - 2014-10-31 03:30 - 12819456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-11-12 08:51 - 2014-10-31 03:26 - 01042944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-11-12 08:51 - 2014-10-31 03:24 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imgutil.dll
2014-11-12 08:51 - 2014-10-31 03:17 - 01892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-11-12 08:51 - 2014-10-31 03:13 - 01310208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-11-12 08:51 - 2014-10-31 03:11 - 00708096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-11-12 08:51 - 2014-10-17 08:01 - 00789184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2014-11-12 08:51 - 2014-10-17 07:58 - 00602768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2014-11-12 08:51 - 2014-10-10 02:58 - 00177472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2014-11-12 08:51 - 2014-10-10 02:58 - 00027456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2014-11-12 08:51 - 2014-10-10 02:44 - 00563976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-11-12 08:51 - 2014-10-08 08:37 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-11-12 08:51 - 2014-10-08 08:37 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2014-11-12 08:51 - 2014-10-08 08:34 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2014-11-12 08:51 - 2014-10-08 08:24 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rfxvmt.dll
2014-11-12 08:51 - 2014-10-08 07:56 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-11-12 08:51 - 2014-10-08 07:51 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-11-12 08:51 - 2014-10-08 07:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2014-11-12 08:51 - 2014-10-08 07:18 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-11-12 08:51 - 2014-10-08 07:17 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-11-12 08:51 - 2014-10-08 06:23 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-11-12 08:50 - 2014-10-23 06:48 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll
2014-11-12 08:50 - 2014-10-23 06:05 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll
2014-11-12 08:50 - 2014-10-18 10:55 - 00055776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-11-12 08:50 - 2014-10-18 09:09 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2014-11-12 08:50 - 2014-10-18 09:09 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2014-11-12 08:50 - 2014-10-18 08:25 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2014-11-12 08:50 - 2014-10-18 07:50 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
2014-11-12 08:50 - 2014-10-18 07:38 - 03557376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-11-12 08:50 - 2014-10-18 07:27 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2014-11-12 08:50 - 2014-10-18 07:26 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2014-11-12 08:50 - 2014-10-18 07:23 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-11-12 08:50 - 2014-10-18 07:23 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-11-12 08:50 - 2014-10-18 07:21 - 00894976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-11-12 08:50 - 2014-10-18 07:20 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-11-12 08:50 - 2014-10-18 07:14 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2014-11-12 08:50 - 2014-10-18 07:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2014-11-12 08:50 - 2014-10-18 07:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-11-12 08:50 - 2014-10-18 07:11 - 00723968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-11-12 08:50 - 2014-10-07 07:28 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2014-11-12 08:50 - 2014-10-07 07:27 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2014-11-12 08:50 - 2014-10-07 07:27 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2014-11-12 08:50 - 2014-10-07 07:27 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2014-11-12 08:50 - 2014-10-07 07:27 - 00108432 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2014-11-12 08:50 - 2014-10-07 04:34 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2014-11-12 08:50 - 2014-10-07 04:34 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2014-11-12 08:50 - 2014-10-07 04:33 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2014-11-12 08:50 - 2014-10-07 04:30 - 04182016 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-11-12 08:50 - 2014-10-07 02:54 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2014-11-12 08:50 - 2014-10-07 02:46 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2014-11-12 08:50 - 2014-09-10 07:25 - 00474432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2014-11-12 08:50 - 2014-09-08 04:07 - 02497344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-11-12 08:50 - 2014-09-08 04:07 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2014-11-12 08:50 - 2014-09-07 23:08 - 00389176 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-11-12 08:50 - 2014-09-04 23:30 - 00822272 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-11-12 08:50 - 2014-09-04 23:21 - 01053184 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-11-12 08:50 - 2014-09-04 04:05 - 00836176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2014-11-12 08:50 - 2014-09-04 03:22 - 00670384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2014-11-12 08:50 - 2014-09-04 02:01 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2014-11-12 08:50 - 2014-09-04 01:32 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2014-11-12 08:50 - 2014-08-31 01:17 - 00148800 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2014-11-12 08:50 - 2014-08-31 01:15 - 21197152 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-11-12 08:50 - 2014-08-30 23:59 - 18723112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-11-12 08:50 - 2014-08-30 23:05 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMEX.dll
2014-11-12 08:50 - 2014-08-30 22:58 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSAPI.dll
2014-11-12 08:50 - 2014-08-30 22:04 - 00941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2014-11-12 08:50 - 2014-08-30 21:53 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FXSAPI.dll
2014-11-12 08:50 - 2014-08-30 21:17 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2014-11-12 08:50 - 2014-08-28 03:55 - 07484224 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2014-11-12 08:50 - 2014-08-28 01:21 - 02480128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2014-11-12 08:50 - 2014-08-28 01:06 - 02030592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2014-11-12 08:50 - 2014-08-23 06:18 - 02149376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2014-11-12 08:50 - 2014-08-23 06:14 - 13424128 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-11-12 08:50 - 2014-08-23 06:04 - 11820544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-11-12 08:50 - 2014-08-23 06:03 - 01346048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2014-11-12 08:50 - 2014-08-23 05:50 - 02714112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2014-11-12 08:50 - 2014-08-02 01:51 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2014-11-12 08:50 - 2014-08-02 01:35 - 00485376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2014-11-10 14:40 - 2014-11-10 14:40 - 00000509 _____ () C:\Users\admin\Desktop\Jedálniček.txt
2014-11-09 20:10 - 2014-11-09 20:10 - 00012769 _____ () C:\Users\admin\Downloads\[SkT]Zachrante_pana_Bankse_-_Saving_Mr._Banks_(2013)(CZ)_=_CSFD_71%.torrent
2014-11-09 20:06 - 2014-11-09 20:06 - 00016953 _____ () C:\Users\admin\Downloads\[SkT]Zachrante_pana_Bankse_-_Saving_Mr._Banks_(2013)(CZ)_=_CSFD_72%.torrent
2014-11-09 20:02 - 2014-11-09 22:13 - 2019911680 _____ () C:\Users\admin\Downloads\Zachrante_pana_Bankse_CZ_dabing_2013_.avi
2014-11-09 16:26 - 2014-11-09 16:26 - 00000604 ____H () C:\WINDOWS\T4
2014-11-09 16:26 - 2014-11-09 16:26 - 00000604 ____H () C:\WINDOWS\SysWOW64\T3
2014-11-09 16:26 - 2014-11-09 16:26 - 00000604 ____H () C:\Program Files (x86)\STLL Notifier
2014-11-09 16:26 - 2014-11-09 16:26 - 00000000 ____D () C:\ProgramData\Sibelius Software
2014-11-09 16:25 - 2014-11-09 16:29 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Sibelius Software
2014-11-09 16:15 - 2014-11-09 17:04 - 00000000 ____D () C:\Users\admin\Documents\Scores
2014-11-09 16:15 - 2014-11-09 16:15 - 00002107 _____ () C:\Users\Public\Desktop\Sibelius 5.lnk
2014-11-09 16:15 - 2014-11-09 16:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sibelius Software
2014-11-09 16:13 - 2014-11-09 16:13 - 00000000 ____D () C:\Program Files (x86)\Sibelius Software
2014-11-09 15:58 - 2014-11-09 16:09 - 00000000 ____D () C:\Users\admin\Downloads\Sibelius 5.1 [h33t][poolpro]
2014-11-09 15:27 - 2014-11-09 15:28 - 01155232 _____ (Noteworthy Software, Inc.) C:\Users\admin\Downloads\setup_nwc251_demo.exe
2014-11-09 13:49 - 2014-11-09 13:49 - 00001106 _____ () C:\Users\Public\Desktop\MuseScore.lnk
2014-11-09 13:49 - 2014-11-09 13:49 - 00000000 ____D () C:\Users\admin\AppData\Roaming\MusE
2014-11-09 13:49 - 2014-11-09 13:49 - 00000000 ____D () C:\Users\admin\AppData\Local\MusE
2014-11-09 13:49 - 2014-11-09 13:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MuseScore
2014-11-09 13:48 - 2014-11-09 13:49 - 00000000 ____D () C:\Program Files (x86)\MuseScore
2014-11-08 18:05 - 2014-11-08 18:06 - 38678632 _____ () C:\Users\admin\Downloads\MuseScore-1.3.exe
2014-11-06 22:52 - 2014-11-06 22:56 - 174966861 _____ () C:\Users\admin\Downloads\[CNT]_Naruto_Shippuuden_385_[3F2CDB16].mkv
2014-11-06 22:52 - 2014-11-06 22:52 - 00013913 _____ () C:\Users\admin\Downloads\[CNT]_Naruto_Shippuuden_385_[3F2CDB16].mkv.torrent
2014-11-01 18:48 - 2014-11-01 18:50 - 00000078 _____ () C:\WINDOWS\setupact.log
2014-11-01 18:48 - 2014-11-01 18:48 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-10-31 20:18 - 2014-11-24 22:23 - 00006100 _____ () C:\WINDOWS\PFRO.log
2014-10-30 23:07 - 2014-10-30 23:07 - 00000000 ____D () C:\Users\admin\Documents\The KMPlayer
2014-10-30 23:05 - 2014-10-30 23:05 - 00001053 _____ () C:\Users\admin\Desktop\KMPlayer.lnk
2014-10-30 23:05 - 2014-10-30 23:05 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
2014-10-30 23:02 - 2014-10-30 23:03 - 13099824 _____ () C:\Users\admin\Downloads\2.9.3.1433_KMPlayer2931433.exe
2014-10-30 22:36 - 2014-10-30 22:40 - 264183574 _____ () C:\Users\admin\Downloads\[CNT]_Naruto_Shippuuden_384_[F00E18C9].mkv
2014-10-30 22:35 - 2014-10-30 22:35 - 00020713 _____ () C:\Users\admin\Downloads\[CNT]_Naruto_Shippuuden_384_[F00E18C9].mkv.torrent
2014-10-28 21:25 - 2014-11-24 22:14 - 01691421 _____ () C:\WINDOWS\WindowsUpdate.log
2014-10-28 20:56 - 2014-10-28 20:56 - 00048034 _____ () C:\Users\admin\Documents\cc_20141028_205651.reg
2014-10-28 20:52 - 2014-10-28 20:53 - 04974864 _____ (Piriform Ltd) C:\Users\admin\Downloads\ccsetup419.exe
2014-10-28 20:20 - 2014-10-28 20:47 - 00000000 ____D () C:\Users\admin\Downloads\Hercules.2014.EXTENDED.BRRip.XviD.MP3-RARBG
2014-10-26 20:36 - 2014-10-26 20:37 - 00015497 _____ () C:\Users\admin\Downloads\[Limetorrents.cc]_Hercules 2014 DVDRip Xvid [The Rock ]-SUPERNOVA.torrent

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-24 22:28 - 2013-11-03 09:28 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3701647376-3946651554-1493002649-1002
2014-11-24 22:24 - 2014-08-18 22:22 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-11-24 22:23 - 2013-10-31 13:54 - 00000950 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-24 22:23 - 2013-10-31 01:32 - 00000062 _____ () C:\Users\admin\AppData\Roaming\sp_data.sys
2014-11-24 22:23 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-24 22:04 - 2013-10-31 13:54 - 00000954 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-24 22:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-11-24 22:00 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-11-24 21:56 - 2013-11-15 18:35 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Skype
2014-11-24 21:37 - 2014-03-29 10:15 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-24 21:11 - 2013-10-31 13:56 - 00002217 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-11-23 13:36 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-11-21 08:09 - 2013-10-30 19:45 - 00000000 ____D () C:\Users\admin\AppData\Roaming\uTorrent
2014-11-19 22:39 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-11-16 12:59 - 2013-10-31 13:54 - 00003926 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-16 12:59 - 2013-10-31 13:54 - 00003690 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-13 21:38 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-11-13 09:55 - 2013-08-22 15:44 - 00379776 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-11-12 23:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-12 23:19 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-12 23:19 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows Defender
2014-11-12 23:18 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-11-12 23:18 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2014-11-12 23:18 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sk-SK
2014-11-12 23:18 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-11-12 21:47 - 2013-11-01 13:42 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-11-12 09:01 - 2013-11-01 13:42 - 103374192 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-11-11 21:37 - 2014-03-29 10:15 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-11-09 15:33 - 2014-07-08 20:20 - 00048754 _____ () C:\WINDOWS\system32\perfh01B.dat
2014-11-09 15:33 - 2014-07-08 20:20 - 00012006 _____ () C:\WINDOWS\system32\perfc01B.dat
2014-11-09 15:33 - 2013-11-14 08:28 - 00907186 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-11-08 22:48 - 2013-11-15 18:34 - 00000000 ____D () C:\ProgramData\Skype
2014-11-01 20:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-10-30 23:07 - 2013-10-30 21:41 - 00000000 ____D () C:\Program Files (x86)\The KMPlayer
2014-10-30 12:25 - 2013-12-25 20:57 - 00275080 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2014-10-30 01:55 - 2014-10-18 23:54 - 00714208 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-10-30 01:55 - 2014-10-18 23:54 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-28 20:56 - 2013-10-30 19:52 - 00000000 ____D () C:\Users\admin\AppData\Roaming\DAEMON Tools Lite
2014-10-28 20:54 - 2013-11-15 22:37 - 00000836 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-10-28 20:53 - 2013-11-15 22:37 - 00000000 ____D () C:\Program Files\CCleaner
2014-10-26 21:14 - 2014-06-16 19:35 - 00000000 ____D () C:\Users\admin\AppData\Local\The Witcher
2014-10-26 21:05 - 2013-11-04 19:45 - 00000000 ____D () C:\Users\admin\AppData\Local\Adobe

Files to move or delete:
====================
C:\ProgramData\SetStretch.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================


Available physical RAM: 2385.13 MB
Total physical RAM: 3981.68 MB
Percentage of memory in use: 40%

==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Users\admin\SkyDrive:ms-properties
AlternateDataStreams: C:\ProgramData\Microsoft:BSLoHaad0nxmQVt3dpUtOj
AlternateDataStreams: C:\ProgramData\Microsoft:SegFIAIMJTzgHEYLCkyInWmqEmQ

==================== Security Center ==================

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\admin\Desktop" je 7738 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Přílohy
Addition.zip
(8.8 KiB) Staženo 87 x

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Otravné reklami

#8 Příspěvek od altrok »

:arrow: Velikost plochy by nemela presahovat 200 MB. Snizuje se pak start i samotny chod celeho PC.
  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu na Vas vyskoci fixlog (pripadne bude ulozen na Plose), jehoz obsah mi vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
    HKLM\...\Policies\Explorer: [NoControlPanel] 0
    HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
    HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\MountPoints2: {a99fa24c-d1c4-11e3-bf55-ac220bac81f5} - "G:\HTC_Sync_Manager_PC.exe"
    HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\MountPoints2: {e731eaaf-493f-11e3-be86-240a644d9d7e} - "G:\SISetup.exe" 
    ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
    ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
    
    HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
    URLSearchHook: [S-1-5-21-3701647376-3946651554-1493002649-1003] ATTENTION ==> Default URLSearchHook is missing.
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
    SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
    
    S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [X]
    S3 GPU-Z; \??\C:\Users\admin\AppData\Local\Temp\GPU-Z.sys [X]
    S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X]
    
    2014-11-24 22:32 - 2014-11-24 22:32 - 00112640 _____ (forum.viry.cz) C:\Users\admin\Downloads\FRSTLauncher.exe
    2014-11-24 22:22 - 2014-11-24 22:12 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
    2014-11-24 22:13 - 2014-11-24 22:23 - 00006617 _____ () C:\zoek-results.log
    2014-11-24 22:12 - 2014-11-24 22:21 - 00000000 ____D () C:\zoek_backup
    2014-11-24 22:12 - 2014-11-24 22:12 - 01294848 _____ () C:\Users\admin\Downloads\zoek.exe
    2014-11-24 22:12 - 2014-11-24 22:12 - 01294848 _____ () C:\Users\admin\Desktop\zoek.exe
    2014-11-24 21:56 - 2014-11-24 22:00 - 00000000 ____D () C:\AdwCleaner
    2014-11-24 21:55 - 2014-11-24 21:55 - 02148864 _____ () C:\Users\admin\Desktop\adwcleaner_4.102.exe
    2014-11-24 21:54 - 2014-11-24 21:55 - 02148864 _____ () C:\Users\admin\Downloads\adwcleaner_4.102.exe
    2014-11-24 21:25 - 2014-11-24 21:25 - 00000000 ____D () C:\rsit
    2014-11-24 21:25 - 2014-11-24 21:25 - 00000000 ____D () C:\Program Files\trend micro
    2014-11-24 21:24 - 2014-11-24 21:24 - 01222144 _____ () C:\Users\admin\Downloads\RSITx64.exe
    2014-10-28 20:52 - 2014-10-28 20:53 - 04974864 _____ (Piriform Ltd) C:\Users\admin\Downloads\ccsetup419.exe
    
    C:\ProgramData\SetStretch.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    AlternateDataStreams: C:\ProgramData\Microsoft:BSLoHaad0nxmQVt3dpUtOj
    AlternateDataStreams: C:\ProgramData\Microsoft:SegFIAIMJTzgHEYLCkyInWmqEmQ
    Hosts:
    EmptyTemp:
    End
    
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

???
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 16 Ún 2008 14:45

Re: Otravné reklami

#9 Příspěvek od ??? »

tak ten adfocus tu stale mam, teraz ma to tam presmerovalo + dalsiu reklamu mi to vyhodilo na novu kartu :/

tu je ten log:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 23-11-2014 01
Ran by admin at 2014-11-24 23:02:20 Run:1
Running from C:\Users\admin\Desktop
Loaded Profiles: admin & UpdatusUser (Available profiles: admin & UpdatusUser)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\MountPoints2: {a99fa24c-d1c4-11e3-bf55-ac220bac81f5} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\...\MountPoints2: {e731eaaf-493f-11e3-be86-240a644d9d7e} - "G:\SISetup.exe"
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File

HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
URLSearchHook: [S-1-5-21-3701647376-3946651554-1493002649-1003] ATTENTION ==> Default URLSearchHook is missing.
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... &pc=ASU2JS
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... &pc=ASU2JS
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... &pc=ASU2JS
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... &pc=ASU2JS

S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena Plus\Room\safedrv.sys [X]
S3 GPU-Z; \??\C:\Users\admin\AppData\Local\Temp\GPU-Z.sys [X]
S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X]

2014-11-24 22:32 - 2014-11-24 22:32 - 00112640 _____ (forum.viry.cz) C:\Users\admin\Downloads\FRSTLauncher.exe
2014-11-24 22:22 - 2014-11-24 22:12 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-11-24 22:13 - 2014-11-24 22:23 - 00006617 _____ () C:\zoek-results.log
2014-11-24 22:12 - 2014-11-24 22:21 - 00000000 ____D () C:\zoek_backup
2014-11-24 22:12 - 2014-11-24 22:12 - 01294848 _____ () C:\Users\admin\Downloads\zoek.exe
2014-11-24 22:12 - 2014-11-24 22:12 - 01294848 _____ () C:\Users\admin\Desktop\zoek.exe
2014-11-24 21:56 - 2014-11-24 22:00 - 00000000 ____D () C:\AdwCleaner
2014-11-24 21:55 - 2014-11-24 21:55 - 02148864 _____ () C:\Users\admin\Desktop\adwcleaner_4.102.exe
2014-11-24 21:54 - 2014-11-24 21:55 - 02148864 _____ () C:\Users\admin\Downloads\adwcleaner_4.102.exe
2014-11-24 21:25 - 2014-11-24 21:25 - 00000000 ____D () C:\rsit
2014-11-24 21:25 - 2014-11-24 21:25 - 00000000 ____D () C:\Program Files\trend micro
2014-11-24 21:24 - 2014-11-24 21:24 - 01222144 _____ () C:\Users\admin\Downloads\RSITx64.exe
2014-10-28 20:52 - 2014-10-28 20:53 - 04974864 _____ (Piriform Ltd) C:\Users\admin\Downloads\ccsetup419.exe

C:\ProgramData\SetStretch.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\Microsoft:BSLoHaad0nxmQVt3dpUtOj
AlternateDataStreams: C:\ProgramData\Microsoft:SegFIAIMJTzgHEYLCkyInWmqEmQ
Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully.
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
"HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a99fa24c-d1c4-11e3-bf55-ac220bac81f5}" => Key deleted successfully.
"HKCR\CLSID\{a99fa24c-d1c4-11e3-bf55-ac220bac81f5}" => Key not found.
"HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e731eaaf-493f-11e3-be86-240a644d9d7e}" => Key deleted successfully.
"HKCR\CLSID\{e731eaaf-493f-11e3-be86-240a644d9d7e}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully.
"HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully.
"HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully.
"HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key not found.
HKU\S-1-5-21-3701647376-3946651554-1493002649-1002\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
Error setting Default URLSearchHook.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
GGSAFERDriver => Service deleted successfully.
GPU-Z => Service deleted successfully.
xhunter1 => Service deleted successfully.
C:\Users\admin\Downloads\FRSTLauncher.exe => Moved successfully.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\admin\Downloads\zoek.exe => Moved successfully.
C:\Users\admin\Desktop\zoek.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\admin\Desktop\adwcleaner_4.102.exe => Moved successfully.
C:\Users\admin\Downloads\adwcleaner_4.102.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Users\admin\Downloads\RSITx64.exe => Moved successfully.
C:\Users\admin\Downloads\ccsetup419.exe => Moved successfully.
C:\ProgramData\SetStretch.exe => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\ProgramData\Microsoft => ":BSLoHaad0nxmQVt3dpUtOj" ADS removed successfully.
C:\ProgramData\Microsoft => ":SegFIAIMJTzgHEYLCkyInWmqEmQ" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 375.3 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Otravné reklami

#10 Příspěvek od altrok »

:arrow: I po tomto kroku s fixlistem?

:arrow: Dela to ve vsech prohlizecich ci jenom v jednom konkretnim?
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

???
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 16 Ún 2008 14:45

Re: Otravné reklami

#11 Příspěvek od ??? »

iny prehliadac nepouzivam..ale ono sa mi zda ze prave po tomto kroku s fixlistom to zacalo zasa robit..po prvom kroku co sme spravili to vyzeralo fajn, tak neviem teraz..neda sa to vratit? :)

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Otravné reklami

#12 Příspěvek od altrok »

:arrow: Postupujte dle navodu kolegy
Rudy napsal:Chrome zazálohujte pomocí Chromebackup: http://www.stahuj.centrum.cz/internet_a ... me-backup/ Pak chrome odinstalujte vč. jeho profilu. Znovu nainstalujte a zpět ze zálohy nakopírujte pouze záložky, příp. hesla.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

???
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 16 Ún 2008 14:45

Re: Otravné reklami

#13 Příspěvek od ??? »

odinstaloval som naspat nainstaloval..stale to iste :/

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Otravné reklami

#14 Příspěvek od altrok »

:arrow: Opravdu jste Chrome odinstaloval vcetne profilu?

:arrow: Od kdy tyto problemy pozorujete?

:arrow: Vyzkousejte, zda Vam okna vyskakuji i v Internet Exploreru

:arrow: Nainstalujte MBAM a udelejte vlastni sken vsech disku - http://forum.viry.cz/viewtopic.php?f=29&t=137928
  • Upozorneni: tento sken zabere od 30 minut po nekolik hodin
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

???
Návštěvník
Návštěvník
Příspěvky: 52
Registrován: 16 Ún 2008 14:45

Re: Otravné reklami

#15 Příspěvek od ??? »

okna zacali vyskakovat tento tyzden..robi to aj v IE...ten sken teda spravim az zajtra..zatial vdaka

Odpovědět