
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Asi tu mám hosta
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Asi tu mám hosta
Prosím o kontrolu logu, díky.
Logfile of random's system information tool 1.09 (written by random/random)
Run by Honza23 at 2014-12-15 14:38:03
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 114 GB (60%) free of 191 GB
Total RAM: 6048 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:38:07, on 15.12.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
E:\MyHeritage\Bin\FTBCheckUpdates.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
C:\Program Files\trend micro\Honza23.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rts.dsrlte.com?affID=na
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ttessab 1.0.0.5 - {e3a06b08-18fc-45fd-9922-38b48d04d699} - C:\Program Files (x86)\Ttessab\TtessabBHO.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Family Tree Builder Update] E:\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Spotify] "C:\Users\Honza23\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Yahoo! Search] C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - E:\Karty\Poker\PokerStarsUpdate.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HiSuiteOuc64.exe - Unknown owner - C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Installer Service - Unknown owner - C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{0C808377-8C23-44ED-9016-05F42E6D4900}\Installer\InstallerService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MaintainerSvc2.69.9464532 - Unknown owner - C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update Ttessab - Unknown owner - C:\Program Files (x86)\Ttessab\updateTtessab.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12412 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\servicing\TrustedInstaller.exe
C:\windows\system32\svchost.exe -k NetworkService
"C:\windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe"
"C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe" -/service
"C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe" -/service
"C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Ttessab\updateTtessab.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2268
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe"
ATKOSD.exe
taskeng.exe {13C37CD9-DDD9-4D75-9042-C6C8BE91D71B}
taskeng.exe {4990B21D-055E-4012-AF25-F7AF416F2A19}
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
KBFiltr.exe
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
WDC.exe
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
C:\Windows\SysWOW64\ACEngSvr.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
"C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe" /S
"C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"E:\MyHeritage\Bin\FTBCheckUpdates.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\windows\system32\sppsvc.exe
C:\windows\System32\svchost.exe -k secsvcs
taskeng.exe {4E9EC3C0-3061-43CC-B76D-009C3BA31E61}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=5940.204f9820.1738143565 "C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 5940 "\\.\pipe\gecko-crash-server-pipe.5940" plugin
"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe" --proxy-stub-channel=Flash2548.61716188.29429 --host-broker-channel=Flash2548.61716188.23114 --host-pid=2548 --host-npapi-version=27 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll"
"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe" --channel=2876.003FF390.706486763 --proxy-stub-channel=Flash2548.61716188.29429 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll" --host-npapi-version=27 --type=renderer
"C:\Users\Honza23\Desktop\RSITx64.exe"
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/?clid=22668"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.246 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=E:\Picaso\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\Sony\Media Go\npmediago.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.246 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\searchplugins\
dsrlte.xml
seznam-avast.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-24 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-24 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e3a06b08-18fc-45fd-9922-38b48d04d699}]
Ttessab 1.0.0.5 - C:\Program Files (x86)\Ttessab\TtessabBHO.dll [2014-12-11 250136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-11-03 167704]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-11-03 392472]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2010-12-31 2587944]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2011-08-16 2277480]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"Spotify"=C:\Users\Honza23\AppData\Roaming\Spotify\Spotify.exe [2014-09-22 6342200]
"Spotify Web Helper"=C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-09-22 1245752]
"Yahoo! Search"=C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe [2014-12-01 533352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-06-07 90832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2014-09-04 40336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2010-08-20 107816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-09-05 12850792]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2012-06-27 3331312]
"ASUSWebStorage"=C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe [2012-05-17 3417984]
"SonicMasterTray"=C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [2010-07-10 984400]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-26 322208]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2012-06-19 174752]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"Family Tree Builder Update"=E:\MyHeritage\Bin\FTBCheckUpdates.exe [2013-11-12 2532864]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-29 4085896]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-11-03 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-12-13 22:14:07 ----A---- C:\windows\system32\drivers\{4351033a-acd6-47da-b89b-8a65492c9234}Gw64.sys
2014-12-11 18:12:48 ----D---- C:\windows\system32\appraiser
2014-12-11 17:42:06 ----A---- C:\windows\SYSWOW64\rrinstaller.exe
2014-12-11 17:42:06 ----A---- C:\windows\SYSWOW64\mfps.dll
2014-12-11 17:42:06 ----A---- C:\windows\SYSWOW64\mfpmp.exe
2014-12-11 17:42:06 ----A---- C:\windows\SYSWOW64\mferror.dll
2014-12-11 17:42:06 ----A---- C:\windows\system32\rrinstaller.exe
2014-12-11 17:42:06 ----A---- C:\windows\system32\mfpmp.exe
2014-12-11 17:42:06 ----A---- C:\windows\system32\mferror.dll
2014-12-11 17:42:05 ----A---- C:\windows\SYSWOW64\mf.dll
2014-12-11 17:42:05 ----A---- C:\windows\system32\mfps.dll
2014-12-11 17:42:05 ----A---- C:\windows\system32\mf.dll
2014-12-10 17:42:37 ----A---- C:\windows\system32\appraiser.dll
2014-12-10 17:42:37 ----A---- C:\windows\system32\aitstatic.exe
2014-12-10 17:42:37 ----A---- C:\windows\system32\aepic.dll
2014-12-10 17:42:37 ----A---- C:\windows\system32\aeinv.dll
2014-12-10 17:42:36 ----A---- C:\windows\system32\invagent.dll
2014-12-10 17:42:36 ----A---- C:\windows\system32\generaltel.dll
2014-12-10 17:42:36 ----A---- C:\windows\system32\devinv.dll
2014-12-10 17:42:35 ----A---- C:\windows\system32\aepdu.dll
2014-12-10 17:42:01 ----A---- C:\windows\system32\WindowsCodecs.dll
2014-12-10 17:42:00 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2014-12-10 17:41:58 ----A---- C:\windows\system32\drivers\tdx.sys
2014-12-10 17:41:55 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-12-10 17:41:55 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-12-10 17:41:55 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-12-10 17:41:55 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-12-10 17:41:55 ----A---- C:\windows\system32\ieetwcollector.exe
2014-12-10 17:41:54 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-12-10 17:41:54 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-12-10 17:41:54 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2014-12-10 17:41:54 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-12-10 17:41:54 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 17:41:54 ----A---- C:\windows\system32\iernonce.dll
2014-12-10 17:41:54 ----A---- C:\windows\system32\ie4uinit.exe
2014-12-10 17:41:53 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-12-10 17:41:53 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-12-10 17:41:51 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-12-10 17:41:51 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-12-10 17:41:51 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-12-10 17:41:51 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-12-10 17:41:51 ----A---- C:\windows\system32\urlmon.dll
2014-12-10 17:41:51 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-12-10 17:41:51 ----A---- C:\windows\system32\iedkcs32.dll
2014-12-10 17:41:50 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-12-10 17:41:50 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-12-10 17:41:50 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-12-10 17:41:50 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-12-10 17:41:50 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-12-10 17:41:50 ----A---- C:\windows\system32\msfeeds.dll
2014-12-10 17:41:50 ----A---- C:\windows\system32\dxtrans.dll
2014-12-10 17:41:49 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-12-10 17:41:49 ----A---- C:\windows\system32\iesetup.dll
2014-12-10 17:41:49 ----A---- C:\windows\system32\ieapfltr.dll
2014-12-10 17:41:47 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-12-10 17:41:47 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-12-10 17:41:47 ----A---- C:\windows\system32\iertutil.dll
2014-12-10 17:41:46 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-12-10 17:41:46 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-12-10 17:41:46 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-12-10 17:41:46 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2014-12-10 17:41:46 ----A---- C:\windows\system32\jsproxy.dll
2014-12-10 17:41:46 ----A---- C:\windows\system32\ieUnatt.exe
2014-12-10 17:41:45 ----A---- C:\windows\system32\dxtmsft.dll
2014-12-10 17:41:44 ----A---- C:\windows\system32\ieui.dll
2014-12-10 17:41:44 ----A---- C:\windows\system32\ieframe.dll
2014-12-10 17:41:43 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-12-10 17:41:43 ----A---- C:\windows\system32\mshtmled.dll
2014-12-10 17:41:43 ----A---- C:\windows\system32\jscript9diag.dll
2014-12-10 17:41:42 ----A---- C:\windows\system32\wininet.dll
2014-12-10 17:41:42 ----A---- C:\windows\system32\vbscript.dll
2014-12-10 17:41:42 ----A---- C:\windows\system32\jscript9.dll
2014-12-10 17:41:41 ----A---- C:\windows\system32\msrating.dll
2014-12-10 17:41:41 ----A---- C:\windows\system32\MshtmlDac.dll
2014-12-10 17:41:40 ----A---- C:\windows\system32\mshtml.dll
2014-12-10 17:38:20 ----A---- C:\windows\SYSWOW64\WsmSvc.dll
2014-12-10 17:38:20 ----A---- C:\windows\SYSWOW64\charmap.exe
2014-12-10 17:38:20 ----A---- C:\windows\system32\WsmSvc.dll
2014-12-10 17:38:20 ----A---- C:\windows\system32\charmap.exe
2014-12-10 17:38:19 ----A---- C:\windows\SYSWOW64\WsmWmiPl.dll
2014-12-10 17:38:19 ----A---- C:\windows\SYSWOW64\WsmAuto.dll
2014-12-10 17:38:19 ----A---- C:\windows\SYSWOW64\WSManMigrationPlugin.dll
2014-12-10 17:38:19 ----A---- C:\windows\SYSWOW64\WSManHTTPConfig.exe
2014-12-10 17:38:19 ----A---- C:\windows\system32\WsmWmiPl.dll
2014-12-10 17:38:19 ----A---- C:\windows\system32\WsmAuto.dll
2014-12-10 17:38:19 ----A---- C:\windows\system32\WSManMigrationPlugin.dll
2014-12-10 17:38:19 ----A---- C:\windows\system32\WSManHTTPConfig.exe
2014-12-10 17:38:16 ----A---- C:\windows\SYSWOW64\tzres.dll
2014-12-10 17:38:16 ----A---- C:\windows\system32\tzres.dll
2014-12-09 22:31:17 ----A---- C:\windows\system32\drivers\{b3226d6b-57d1-49c8-8124-68272ad024dd}Gw64.sys
2014-12-09 16:13:36 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-12-08 16:37:33 ----D---- C:\ProgramData\HandSetService
2014-12-08 16:37:32 ----D---- C:\ProgramData\HiSuiteOuc
2014-12-08 16:37:27 ----D---- C:\ProgramData\HiSuiteDataSvc
2014-12-08 16:37:06 ----A---- C:\windows\system32\drivers\WUDFUpdate_01009.dll
2014-12-08 16:37:06 ----A---- C:\windows\system32\drivers\winusbcoinstaller2.dll
2014-12-08 16:37:06 ----A---- C:\windows\system32\drivers\WdfCoInstaller01009.dll
2014-12-08 15:42:19 ----A---- C:\windows\system32\drivers\{2ca68fa5-d304-4b84-9dd2-a6dc1c1d2ca6}Gw64.sys
2014-12-06 20:50:33 ----A---- C:\windows\system32\drivers\{dc44f1f8-14f7-4ddf-ac43-5ffa6e2f23b0}Gw64.sys
2014-12-01 19:34:11 ----A---- C:\windows\system32\drivers\{b0109f98-ffef-4d31-b74c-3e84ac22f0b4}Gw64.sys
2014-11-30 18:14:17 ----A---- C:\windows\system32\drivers\{1127f7b9-aef0-49e9-9436-f7da80d05cc5}Gw64.sys
2014-11-29 07:50:29 ----A---- C:\windows\system32\drivers\{1436291c-76ca-4bbc-8653-740485c8638f}Gw64.sys
2014-11-27 12:39:44 ----A---- C:\windows\system32\drivers\{42a2840c-2909-43d5-95e6-bca1040a0c50}Gw64.sys
2014-11-26 15:26:23 ----A---- C:\windows\system32\drivers\{c4ad9507-436a-4c53-b644-35e1d46ce848}Gw64.sys
2014-11-22 18:54:42 ----A---- C:\windows\system32\drivers\{c3338013-10e4-4bfa-977c-d3f18abe6f4f}Gw64.sys
2014-11-20 16:53:52 ----A---- C:\windows\system32\drivers\{bf802226-c4fc-40f2-b1b7-41a835c1b386}Gw64.sys
2014-11-19 14:18:22 ----A---- C:\windows\SYSWOW64\pku2u.dll
2014-11-19 14:18:22 ----A---- C:\windows\SYSWOW64\kerberos.dll
2014-11-19 14:18:22 ----A---- C:\windows\system32\pku2u.dll
2014-11-19 14:18:22 ----A---- C:\windows\system32\kerberos.dll
2014-11-17 18:43:27 ----A---- C:\windows\system32\drivers\{e223215e-2f9f-47a5-8264-4b12e6d7c1d7}Gw64.sys
======List of files/folders modified in the last 1 month======
2014-12-15 14:38:06 ----D---- C:\Program Files\trend micro
2014-12-15 14:38:05 ----D---- C:\windows\Temp
2014-12-15 14:33:40 ----D---- C:\windows\system32\catroot2
2014-12-14 20:11:15 ----A---- C:\windows\SYSWOW64\log.txt
2014-12-14 20:10:32 ----D---- C:\Users\Honza23\AppData\Roaming\Spotify
2014-12-14 20:09:52 ----HD---- C:\ASUS.DAT
2014-12-14 20:09:19 ----D---- C:\windows\winsxs
2014-12-14 20:08:43 ----D---- C:\windows\system32\config
2014-12-14 20:07:53 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-12-14 20:07:53 ----D---- C:\windows\SysWOW64
2014-12-14 20:07:53 ----D---- C:\windows\system32\cs-CZ
2014-12-14 20:07:53 ----D---- C:\windows\System32
2014-12-14 19:24:40 ----D---- C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c
2014-12-14 11:59:41 ----SHD---- C:\System Volume Information
2014-12-14 11:59:19 ----D---- C:\Program Files (x86)\Ttessab
2014-12-13 22:14:07 ----D---- C:\windows\system32\drivers
2014-12-13 22:10:00 ----A---- C:\windows\win.ini
2014-12-13 22:03:38 ----D---- C:\windows\inf
2014-12-13 22:03:38 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-12-11 19:05:50 ----D---- C:\windows\rescache
2014-12-11 18:19:05 ----A---- C:\windows\system32\AutoRunFilter.ini
2014-12-11 18:17:20 ----D---- C:\Windows
2014-12-11 18:17:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-11 18:12:48 ----SD---- C:\windows\system32\CompatTel
2014-12-11 18:12:48 ----SD---- C:\ProgramData\Microsoft
2014-12-11 18:12:48 ----D---- C:\windows\AppCompat
2014-12-11 18:12:46 ----D---- C:\windows\SYSWOW64\en-US
2014-12-11 18:12:46 ----D---- C:\windows\system32\en-US
2014-12-11 18:12:46 ----D---- C:\windows\PolicyDefinitions
2014-12-11 18:12:46 ----D---- C:\Program Files\Internet Explorer
2014-12-11 18:12:45 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-11 17:53:00 ----D---- C:\windows\system32\MRT
2014-12-11 17:43:44 ----D---- C:\windows\debug
2014-12-11 17:43:39 ----A---- C:\windows\system32\MRT.exe
2014-12-11 17:42:09 ----D---- C:\windows\system32\catroot
2014-12-09 23:43:55 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-12-09 22:31:24 ----D---- C:\Program Files (x86)\Mozilla Firefox.bak
2014-12-09 22:31:23 ----RD---- C:\Program Files (x86)
2014-12-08 16:37:33 ----HD---- C:\ProgramData
2014-12-08 16:37:06 ----D---- C:\windows\system32\DriverStore
2014-12-01 19:35:12 ----D---- C:\windows\system32\Tasks
2014-11-26 19:24:22 ----D---- C:\windows\Prefetch
2014-11-17 12:11:16 ----D---- C:\windows\SoftwareDistribution
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2014-07-24 65776]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2014-07-24 224896]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2014-07-24 93568]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2014-11-22 1041168]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2014-07-24 427360]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-02-15 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 aswHwid;avast! HardwareID; C:\windows\system32\drivers\aswHwid.sys [2014-07-24 29208]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2014-07-24 79184]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2014-07-24 92008]
R3 asmthub3;ASMedia USB3 Hub Service; C:\windows\system32\DRIVERS\asmthub3.sys [2011-11-23 130024]
R3 asmtxhci;ASMEDIA XHCI Service; C:\windows\system32\DRIVERS\asmtxhci.sys [2011-11-23 395752]
R3 ETD;ELAN PS/2 Port Input Device; C:\windows\system32\DRIVERS\ETD.sys [2010-12-31 138024]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-11-03 12310112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2011-09-06 3074536]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2011-11-03 317440]
R3 kbfiltr;Keyboard Filter; C:\windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-08-24 76912]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2013-04-09 2430224]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2014-02-15 868848]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 AmUStor;AM USB Stroage Driver; C:\windows\system32\drivers\AmUStor.SYS [2011-03-18 74840]
S3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2012-06-27 80384]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\windows\system32\drivers\ssudbus.sys [2011-10-27 95928]
S3 dot4;MS IEEE-1284.4 Driver; C:\windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 hwdatacard;ZD DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ZDDriver.sys [2010-01-20 122496]
S3 NLNdisMP;NLNdisMP; C:\windows\system32\DRIVERS\nlndis.sys []
S3 NLNdisPT;NetLimiter Ndis Protocol Service; C:\windows\system32\DRIVERS\nlndis.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2012-01-09 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2012-01-09 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-11 26112]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-01-09 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2014-07-29 33280]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-01-09 9216]
S3 WinUsb;Android USB Driver; C:\windows\system32\DRIVERS\WinUSB.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-04 64704]
R2 AFBAgent;AFBAgent; C:\windows\system32\FBAgent.exe [2011-03-04 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2011-11-21 80512]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2012-04-13 277120]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-24 50344]
R2 HiSuiteOuc64.exe;HiSuiteOuc64.exe; C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe [2014-09-05 138272]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [2014-09-05 219680]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
R2 MaintainerSvc2.69.9464532;MaintainerSvc2.69.9464532; C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe [2014-12-14 123672]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
R2 Update Ttessab;Update Ttessab; C:\Program Files (x86)\Ttessab\updateTtessab.exe [2014-12-13 524056]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-03 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-09 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-03 116648]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-11-22 114688]
S3 Installer Service;Installer Service; C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{0C808377-8C23-44ED-9016-05F42E6D4900}\Installer\InstallerService.exe [2013-09-17 125288]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-12-09 114800]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-06-11 724376]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2013-05-23 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Honza23 at 2014-12-15 14:38:03
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 114 GB (60%) free of 191 GB
Total RAM: 6048 MB (51% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:38:07, on 15.12.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
E:\MyHeritage\Bin\FTBCheckUpdates.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
C:\Program Files\trend micro\Honza23.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rts.dsrlte.com?affID=na
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ttessab 1.0.0.5 - {e3a06b08-18fc-45fd-9922-38b48d04d699} - C:\Program Files (x86)\Ttessab\TtessabBHO.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Family Tree Builder Update] E:\MyHeritage\Bin\FTBCheckUpdates.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Spotify] "C:\Users\Honza23\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Yahoo! Search] C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: FancyStart daemon.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - E:\Karty\Poker\PokerStarsUpdate.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AFBAgent - Unknown owner - C:\windows\system32\FBAgent.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HiSuiteOuc64.exe - Unknown owner - C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Installer Service - Unknown owner - C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{0C808377-8C23-44ED-9016-05F42E6D4900}\Installer\InstallerService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MaintainerSvc2.69.9464532 - Unknown owner - C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Update Ttessab - Unknown owner - C:\Program Files (x86)\Ttessab\updateTtessab.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 12412 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\servicing\TrustedInstaller.exe
C:\windows\system32\svchost.exe -k NetworkService
"C:\windows\system32\FBAgent.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe"
"C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe" -/service
"C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe" -/service
"C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Ttessab\updateTtessab.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2268
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\windows\system32\wbem\wmiprvse.exe
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\Explorer.EXE
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe"
ATKOSD.exe
taskeng.exe {13C37CD9-DDD9-4D75-9042-C6C8BE91D71B}
taskeng.exe {4990B21D-055E-4012-AF25-F7AF416F2A19}
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
KBFiltr.exe
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
WDC.exe
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
C:\Windows\SysWOW64\ACEngSvr.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SF3
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
"C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe" /S
"C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe"
C:\windows\System32\svchost.exe -k LocalServicePeerNet
"E:\MyHeritage\Bin\FTBCheckUpdates.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\windows\system32\wbem\unsecapp.exe -Embedding
C:\windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\windows\system32\sppsvc.exe
C:\windows\System32\svchost.exe -k secsvcs
taskeng.exe {4E9EC3C0-3061-43CC-B76D-009C3BA31E61}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=5940.204f9820.1738143565 "C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 5940 "\\.\pipe\gecko-crash-server-pipe.5940" plugin
"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe" --proxy-stub-channel=Flash2548.61716188.29429 --host-broker-channel=Flash2548.61716188.23114 --host-pid=2548 --host-npapi-version=27 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll"
"C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe" --channel=2876.003FF390.706486763 --proxy-stub-channel=Flash2548.61716188.29429 --plugin-path="C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll" --host-npapi-version=27 --type=renderer
"C:\Users\Honza23\Desktop\RSITx64.exe"
C:\windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Scheduled tasks folder======
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/?clid=22668"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.246 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=E:\Picaso\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\Sony\Media Go\npmediago.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.246 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\searchplugins\
dsrlte.xml
seznam-avast.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-07-24 612248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-07-24 457712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29 441216]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e3a06b08-18fc-45fd-9922-38b48d04d699}]
Ttessab 1.0.0.5 - C:\Program Files (x86)\Ttessab\TtessabBHO.dll [2014-12-11 250136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\windows\system32\igfxtray.exe [2011-11-03 167704]
"HotKeysCmds"=C:\windows\system32\hkcmd.exe [2011-11-03 392472]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2010-12-31 2587944]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-03-21 361984]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2011-08-16 2277480]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"Spotify"=C:\Users\Honza23\AppData\Roaming\Spotify\Spotify.exe [2014-09-22 6342200]
"Spotify Web Helper"=C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [2014-09-22 1245752]
"Yahoo! Search"=C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe [2014-12-01 533352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACMON]
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-06-07 90832]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [2014-09-04 40336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2010-08-20 107816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2011-09-05 12850792]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2012-06-27 3331312]
"ASUSWebStorage"=C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe [2012-05-17 3417984]
"SonicMasterTray"=C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [2010-07-10 984400]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-26 322208]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2012-06-19 174752]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"Family Tree Builder Update"=E:\MyHeritage\Bin\FTBCheckUpdates.exe [2013-11-12 2532864]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-29 4085896]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
FancyStart daemon.lnk - C:\windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2011-11-03 390144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoRun"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-12-13 22:14:07 ----A---- C:\windows\system32\drivers\{4351033a-acd6-47da-b89b-8a65492c9234}Gw64.sys
2014-12-11 18:12:48 ----D---- C:\windows\system32\appraiser
2014-12-11 17:42:06 ----A---- C:\windows\SYSWOW64\rrinstaller.exe
2014-12-11 17:42:06 ----A---- C:\windows\SYSWOW64\mfps.dll
2014-12-11 17:42:06 ----A---- C:\windows\SYSWOW64\mfpmp.exe
2014-12-11 17:42:06 ----A---- C:\windows\SYSWOW64\mferror.dll
2014-12-11 17:42:06 ----A---- C:\windows\system32\rrinstaller.exe
2014-12-11 17:42:06 ----A---- C:\windows\system32\mfpmp.exe
2014-12-11 17:42:06 ----A---- C:\windows\system32\mferror.dll
2014-12-11 17:42:05 ----A---- C:\windows\SYSWOW64\mf.dll
2014-12-11 17:42:05 ----A---- C:\windows\system32\mfps.dll
2014-12-11 17:42:05 ----A---- C:\windows\system32\mf.dll
2014-12-10 17:42:37 ----A---- C:\windows\system32\appraiser.dll
2014-12-10 17:42:37 ----A---- C:\windows\system32\aitstatic.exe
2014-12-10 17:42:37 ----A---- C:\windows\system32\aepic.dll
2014-12-10 17:42:37 ----A---- C:\windows\system32\aeinv.dll
2014-12-10 17:42:36 ----A---- C:\windows\system32\invagent.dll
2014-12-10 17:42:36 ----A---- C:\windows\system32\generaltel.dll
2014-12-10 17:42:36 ----A---- C:\windows\system32\devinv.dll
2014-12-10 17:42:35 ----A---- C:\windows\system32\aepdu.dll
2014-12-10 17:42:01 ----A---- C:\windows\system32\WindowsCodecs.dll
2014-12-10 17:42:00 ----A---- C:\windows\SYSWOW64\WindowsCodecs.dll
2014-12-10 17:41:58 ----A---- C:\windows\system32\drivers\tdx.sys
2014-12-10 17:41:55 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-12-10 17:41:55 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-12-10 17:41:55 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-12-10 17:41:55 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-12-10 17:41:55 ----A---- C:\windows\system32\ieetwcollector.exe
2014-12-10 17:41:54 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-12-10 17:41:54 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-12-10 17:41:54 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2014-12-10 17:41:54 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-12-10 17:41:54 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 17:41:54 ----A---- C:\windows\system32\iernonce.dll
2014-12-10 17:41:54 ----A---- C:\windows\system32\ie4uinit.exe
2014-12-10 17:41:53 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-12-10 17:41:53 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-12-10 17:41:51 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-12-10 17:41:51 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-12-10 17:41:51 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-12-10 17:41:51 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-12-10 17:41:51 ----A---- C:\windows\system32\urlmon.dll
2014-12-10 17:41:51 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-12-10 17:41:51 ----A---- C:\windows\system32\iedkcs32.dll
2014-12-10 17:41:50 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-12-10 17:41:50 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-12-10 17:41:50 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-12-10 17:41:50 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-12-10 17:41:50 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-12-10 17:41:50 ----A---- C:\windows\system32\msfeeds.dll
2014-12-10 17:41:50 ----A---- C:\windows\system32\dxtrans.dll
2014-12-10 17:41:49 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-12-10 17:41:49 ----A---- C:\windows\system32\iesetup.dll
2014-12-10 17:41:49 ----A---- C:\windows\system32\ieapfltr.dll
2014-12-10 17:41:47 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-12-10 17:41:47 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-12-10 17:41:47 ----A---- C:\windows\system32\iertutil.dll
2014-12-10 17:41:46 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-12-10 17:41:46 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-12-10 17:41:46 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-12-10 17:41:46 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2014-12-10 17:41:46 ----A---- C:\windows\system32\jsproxy.dll
2014-12-10 17:41:46 ----A---- C:\windows\system32\ieUnatt.exe
2014-12-10 17:41:45 ----A---- C:\windows\system32\dxtmsft.dll
2014-12-10 17:41:44 ----A---- C:\windows\system32\ieui.dll
2014-12-10 17:41:44 ----A---- C:\windows\system32\ieframe.dll
2014-12-10 17:41:43 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-12-10 17:41:43 ----A---- C:\windows\system32\mshtmled.dll
2014-12-10 17:41:43 ----A---- C:\windows\system32\jscript9diag.dll
2014-12-10 17:41:42 ----A---- C:\windows\system32\wininet.dll
2014-12-10 17:41:42 ----A---- C:\windows\system32\vbscript.dll
2014-12-10 17:41:42 ----A---- C:\windows\system32\jscript9.dll
2014-12-10 17:41:41 ----A---- C:\windows\system32\msrating.dll
2014-12-10 17:41:41 ----A---- C:\windows\system32\MshtmlDac.dll
2014-12-10 17:41:40 ----A---- C:\windows\system32\mshtml.dll
2014-12-10 17:38:20 ----A---- C:\windows\SYSWOW64\WsmSvc.dll
2014-12-10 17:38:20 ----A---- C:\windows\SYSWOW64\charmap.exe
2014-12-10 17:38:20 ----A---- C:\windows\system32\WsmSvc.dll
2014-12-10 17:38:20 ----A---- C:\windows\system32\charmap.exe
2014-12-10 17:38:19 ----A---- C:\windows\SYSWOW64\WsmWmiPl.dll
2014-12-10 17:38:19 ----A---- C:\windows\SYSWOW64\WsmAuto.dll
2014-12-10 17:38:19 ----A---- C:\windows\SYSWOW64\WSManMigrationPlugin.dll
2014-12-10 17:38:19 ----A---- C:\windows\SYSWOW64\WSManHTTPConfig.exe
2014-12-10 17:38:19 ----A---- C:\windows\system32\WsmWmiPl.dll
2014-12-10 17:38:19 ----A---- C:\windows\system32\WsmAuto.dll
2014-12-10 17:38:19 ----A---- C:\windows\system32\WSManMigrationPlugin.dll
2014-12-10 17:38:19 ----A---- C:\windows\system32\WSManHTTPConfig.exe
2014-12-10 17:38:16 ----A---- C:\windows\SYSWOW64\tzres.dll
2014-12-10 17:38:16 ----A---- C:\windows\system32\tzres.dll
2014-12-09 22:31:17 ----A---- C:\windows\system32\drivers\{b3226d6b-57d1-49c8-8124-68272ad024dd}Gw64.sys
2014-12-09 16:13:36 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-12-08 16:37:33 ----D---- C:\ProgramData\HandSetService
2014-12-08 16:37:32 ----D---- C:\ProgramData\HiSuiteOuc
2014-12-08 16:37:27 ----D---- C:\ProgramData\HiSuiteDataSvc
2014-12-08 16:37:06 ----A---- C:\windows\system32\drivers\WUDFUpdate_01009.dll
2014-12-08 16:37:06 ----A---- C:\windows\system32\drivers\winusbcoinstaller2.dll
2014-12-08 16:37:06 ----A---- C:\windows\system32\drivers\WdfCoInstaller01009.dll
2014-12-08 15:42:19 ----A---- C:\windows\system32\drivers\{2ca68fa5-d304-4b84-9dd2-a6dc1c1d2ca6}Gw64.sys
2014-12-06 20:50:33 ----A---- C:\windows\system32\drivers\{dc44f1f8-14f7-4ddf-ac43-5ffa6e2f23b0}Gw64.sys
2014-12-01 19:34:11 ----A---- C:\windows\system32\drivers\{b0109f98-ffef-4d31-b74c-3e84ac22f0b4}Gw64.sys
2014-11-30 18:14:17 ----A---- C:\windows\system32\drivers\{1127f7b9-aef0-49e9-9436-f7da80d05cc5}Gw64.sys
2014-11-29 07:50:29 ----A---- C:\windows\system32\drivers\{1436291c-76ca-4bbc-8653-740485c8638f}Gw64.sys
2014-11-27 12:39:44 ----A---- C:\windows\system32\drivers\{42a2840c-2909-43d5-95e6-bca1040a0c50}Gw64.sys
2014-11-26 15:26:23 ----A---- C:\windows\system32\drivers\{c4ad9507-436a-4c53-b644-35e1d46ce848}Gw64.sys
2014-11-22 18:54:42 ----A---- C:\windows\system32\drivers\{c3338013-10e4-4bfa-977c-d3f18abe6f4f}Gw64.sys
2014-11-20 16:53:52 ----A---- C:\windows\system32\drivers\{bf802226-c4fc-40f2-b1b7-41a835c1b386}Gw64.sys
2014-11-19 14:18:22 ----A---- C:\windows\SYSWOW64\pku2u.dll
2014-11-19 14:18:22 ----A---- C:\windows\SYSWOW64\kerberos.dll
2014-11-19 14:18:22 ----A---- C:\windows\system32\pku2u.dll
2014-11-19 14:18:22 ----A---- C:\windows\system32\kerberos.dll
2014-11-17 18:43:27 ----A---- C:\windows\system32\drivers\{e223215e-2f9f-47a5-8264-4b12e6d7c1d7}Gw64.sys
======List of files/folders modified in the last 1 month======
2014-12-15 14:38:06 ----D---- C:\Program Files\trend micro
2014-12-15 14:38:05 ----D---- C:\windows\Temp
2014-12-15 14:33:40 ----D---- C:\windows\system32\catroot2
2014-12-14 20:11:15 ----A---- C:\windows\SYSWOW64\log.txt
2014-12-14 20:10:32 ----D---- C:\Users\Honza23\AppData\Roaming\Spotify
2014-12-14 20:09:52 ----HD---- C:\ASUS.DAT
2014-12-14 20:09:19 ----D---- C:\windows\winsxs
2014-12-14 20:08:43 ----D---- C:\windows\system32\config
2014-12-14 20:07:53 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-12-14 20:07:53 ----D---- C:\windows\SysWOW64
2014-12-14 20:07:53 ----D---- C:\windows\system32\cs-CZ
2014-12-14 20:07:53 ----D---- C:\windows\System32
2014-12-14 19:24:40 ----D---- C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c
2014-12-14 11:59:41 ----SHD---- C:\System Volume Information
2014-12-14 11:59:19 ----D---- C:\Program Files (x86)\Ttessab
2014-12-13 22:14:07 ----D---- C:\windows\system32\drivers
2014-12-13 22:10:00 ----A---- C:\windows\win.ini
2014-12-13 22:03:38 ----D---- C:\windows\inf
2014-12-13 22:03:38 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-12-11 19:05:50 ----D---- C:\windows\rescache
2014-12-11 18:19:05 ----A---- C:\windows\system32\AutoRunFilter.ini
2014-12-11 18:17:20 ----D---- C:\Windows
2014-12-11 18:17:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-11 18:12:48 ----SD---- C:\windows\system32\CompatTel
2014-12-11 18:12:48 ----SD---- C:\ProgramData\Microsoft
2014-12-11 18:12:48 ----D---- C:\windows\AppCompat
2014-12-11 18:12:46 ----D---- C:\windows\SYSWOW64\en-US
2014-12-11 18:12:46 ----D---- C:\windows\system32\en-US
2014-12-11 18:12:46 ----D---- C:\windows\PolicyDefinitions
2014-12-11 18:12:46 ----D---- C:\Program Files\Internet Explorer
2014-12-11 18:12:45 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-11 17:53:00 ----D---- C:\windows\system32\MRT
2014-12-11 17:43:44 ----D---- C:\windows\debug
2014-12-11 17:43:39 ----A---- C:\windows\system32\MRT.exe
2014-12-11 17:42:09 ----D---- C:\windows\system32\catroot
2014-12-09 23:43:55 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-12-09 22:31:24 ----D---- C:\Program Files (x86)\Mozilla Firefox.bak
2014-12-09 22:31:23 ----RD---- C:\Program Files (x86)
2014-12-08 16:37:33 ----HD---- C:\ProgramData
2014-12-08 16:37:06 ----D---- C:\windows\system32\DriverStore
2014-12-01 19:35:12 ----D---- C:\windows\system32\Tasks
2014-11-26 19:24:22 ----D---- C:\windows\Prefetch
2014-11-17 12:11:16 ----D---- C:\windows\SoftwareDistribution
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\windows\system32\drivers\aswRvrt.sys [2014-07-24 65776]
R0 aswVmm;avast! VM Monitor; C:\windows\system32\drivers\aswVmm.sys [2014-07-24 224896]
R0 iaStor;Intel AHCI Controller; C:\windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr2.sys [2014-07-24 93568]
R1 aswSnx;aswSnx; C:\windows\system32\drivers\aswSnx.sys [2014-11-22 1041168]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2014-07-24 427360]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-02-15 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-03 15416]
R2 aswHwid;avast! HardwareID; C:\windows\system32\drivers\aswHwid.sys [2014-07-24 29208]
R2 aswMonFlt;aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [2014-07-24 79184]
R2 aswStm;aswStm; C:\windows\system32\drivers\aswStm.sys [2014-07-24 92008]
R3 asmthub3;ASMedia USB3 Hub Service; C:\windows\system32\DRIVERS\asmthub3.sys [2011-11-23 130024]
R3 asmtxhci;ASMEDIA XHCI Service; C:\windows\system32\DRIVERS\asmtxhci.sys [2011-11-23 395752]
R3 ETD;ELAN PS/2 Port Input Device; C:\windows\system32\DRIVERS\ETD.sys [2010-12-31 138024]
R3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2011-11-03 12310112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2011-09-06 3074536]
R3 IntcDAud;Intel(R) Display Audio; C:\windows\system32\DRIVERS\IntcDAud.sys [2011-11-03 317440]
R3 kbfiltr;Keyboard Filter; C:\windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-08-24 76912]
R3 MEIx64;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\windows\system32\DRIVERS\netr28x.sys [2013-04-09 2430224]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S0 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2014-02-15 868848]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 AmUStor;AM USB Stroage Driver; C:\windows\system32\drivers\AmUStor.SYS [2011-03-18 74840]
S3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2012-06-27 80384]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\windows\system32\drivers\ssudbus.sys [2011-10-27 95928]
S3 dot4;MS IEEE-1284.4 Driver; C:\windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 hwdatacard;ZD DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ZDDriver.sys [2010-01-20 122496]
S3 NLNdisMP;NLNdisMP; C:\windows\system32\DRIVERS\nlndis.sys []
S3 NLNdisPT;NetLimiter Ndis Protocol Service; C:\windows\system32\DRIVERS\nlndis.sys []
S3 nmwcd;Nokia USB Phone Parent Driver; C:\windows\system32\drivers\ccdcmbx64.sys [2012-01-09 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\windows\system32\drivers\ccdcmbox64.sys [2012-01-09 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\windows\system32\drivers\nmwcdnsucx64.sys [2012-01-09 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\windows\system32\drivers\nmwcdnsux64.sys [2012-01-09 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfdx64.sys [2012-06-11 26112]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 TPM;TPM; C:\windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerfltx64.sys [2012-01-09 9216]
S3 usb_rndisx;Adaptér USB RNDIS; C:\windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2014-07-29 33280]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2012-01-09 9216]
S3 WinUsb;Android USB Driver; C:\windows\system32\DRIVERS\WinUSB.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-04 64704]
R2 AFBAgent;AFBAgent; C:\windows\system32\FBAgent.exe [2011-03-04 379520]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2011-11-21 80512]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2012-04-13 277120]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-07-24 50344]
R2 HiSuiteOuc64.exe;HiSuiteOuc64.exe; C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe [2014-09-05 138272]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [2014-09-05 219680]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
R2 MaintainerSvc2.69.9464532;MaintainerSvc2.69.9464532; C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe [2014-12-14 123672]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-21 2656280]
R2 Update Ttessab;Update Ttessab; C:\Program Files (x86)\Ttessab\updateTtessab.exe [2014-12-13 524056]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-29 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-03 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-09 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-03 116648]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-11-22 114688]
S3 Installer Service;Installer Service; C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{0C808377-8C23-44ED-9016-05F42E6D4900}\Installer\InstallerService.exe [2013-09-17 125288]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-12-09 114800]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2012-06-11 724376]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2013-02-04 155824]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2013-05-23 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
-----------------EOF-----------------
Re: Asi tu mám hosta
Zdravim 
Vas odhad je spravny... hosta tam mate 
V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).
Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/





- ukoncete vsechny programy
- kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
- kliknete na Scan, pote na Clean
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Asi tu mám hosta
# AdwCleaner v4.105 - Report created 15/12/2014 at 15:16:07
# Updated 08/12/2014 by Xplode
# Database : 2014-12-13.4 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Honza23 - HONZA23-PC
# Running from : C:\Users\Honza23\Desktop\adwcleaner_4.105.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : Update Ttessab
Service Deleted : {01ff3855-4a35-4386-a9e5-851a17533db4}Gw64
Service Deleted : {02a30246-1cec-4c49-8e7b-6b926efec85d}Gw64
Service Deleted : {1127f7b9-aef0-49e9-9436-f7da80d05cc5}Gw64
Service Deleted : {1436291c-76ca-4bbc-8653-740485c8638f}Gw64
Service Deleted : {2ca68fa5-d304-4b84-9dd2-a6dc1c1d2ca6}Gw64
Service Deleted : {408fcd28-f599-4b29-ada2-d72e26c39377}Gw64
Service Deleted : {42a2840c-2909-43d5-95e6-bca1040a0c50}Gw64
Service Deleted : {4351033a-acd6-47da-b89b-8a65492c9234}Gw64
Service Deleted : {4ecd3e68-eb27-40aa-b12d-5667ae0c0fc1}Gw64
Service Deleted : {692f148e-d2a7-4a97-a191-14c1f8d82587}Gw64
Service Deleted : {96611316-9343-40cf-a1ee-299e0bfa2140}Gw64
Service Deleted : {a98718a8-7722-4905-8d33-34677b352dba}Gw64
Service Deleted : {ac3b0a72-88bc-4124-9f74-c1d5bfa77944}Gw64
Service Deleted : {b0109f98-ffef-4d31-b74c-3e84ac22f0b4}Gw64
Service Deleted : {b3226d6b-57d1-49c8-8124-68272ad024dd}Gw64
Service Deleted : {bf802226-c4fc-40f2-b1b7-41a835c1b386}Gw64
Service Deleted : {c3338013-10e4-4bfa-977c-d3f18abe6f4f}Gw64
Service Deleted : {c4ad9507-436a-4c53-b644-35e1d46ce848}Gw64
Service Deleted : {dc44f1f8-14f7-4ddf-ac43-5ffa6e2f23b0}Gw64
Service Deleted : {e223215e-2f9f-47a5-8264-4b12e6d7c1d7}Gw64
Service Deleted : {fd5c71b0-bdaa-439c-8465-15717d777458}Gw64
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\Ttessab
Folder Deleted : C:\Users\Honza23\AppData\Local\pay-by-ads
Folder Deleted : C:\Users\Honza23\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Honza23\AppData\Local\GetnowUninstall
File Deleted : C:\windows\System32\drivers\{01ff3855-4a35-4386-a9e5-851a17533db4}Gw64.sys
File Deleted : C:\windows\System32\drivers\{02a30246-1cec-4c49-8e7b-6b926efec85d}Gw64.sys
File Deleted : C:\windows\System32\drivers\{1127f7b9-aef0-49e9-9436-f7da80d05cc5}Gw64.sys
File Deleted : C:\windows\System32\drivers\{1436291c-76ca-4bbc-8653-740485c8638f}Gw64.sys
File Deleted : C:\windows\System32\drivers\{2ca68fa5-d304-4b84-9dd2-a6dc1c1d2ca6}Gw64.sys
File Deleted : C:\windows\System32\drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys
File Deleted : C:\windows\System32\drivers\{42a2840c-2909-43d5-95e6-bca1040a0c50}Gw64.sys
File Deleted : C:\windows\System32\drivers\{4351033a-acd6-47da-b89b-8a65492c9234}Gw64.sys
File Deleted : C:\windows\System32\drivers\{4ecd3e68-eb27-40aa-b12d-5667ae0c0fc1}Gw64.sys
File Deleted : C:\windows\System32\drivers\{692f148e-d2a7-4a97-a191-14c1f8d82587}Gw64.sys
File Deleted : C:\windows\System32\drivers\{96611316-9343-40cf-a1ee-299e0bfa2140}Gw64.sys
File Deleted : C:\windows\System32\drivers\{a98718a8-7722-4905-8d33-34677b352dba}Gw64.sys
File Deleted : C:\windows\System32\drivers\{ac3b0a72-88bc-4124-9f74-c1d5bfa77944}Gw64.sys
File Deleted : C:\windows\System32\drivers\{b0109f98-ffef-4d31-b74c-3e84ac22f0b4}Gw64.sys
File Deleted : C:\windows\System32\drivers\{b3226d6b-57d1-49c8-8124-68272ad024dd}Gw64.sys
File Deleted : C:\windows\System32\drivers\{bf802226-c4fc-40f2-b1b7-41a835c1b386}Gw64.sys
File Deleted : C:\windows\System32\drivers\{c3338013-10e4-4bfa-977c-d3f18abe6f4f}Gw64.sys
File Deleted : C:\windows\System32\drivers\{c4ad9507-436a-4c53-b644-35e1d46ce848}Gw64.sys
File Deleted : C:\windows\System32\drivers\{dc44f1f8-14f7-4ddf-ac43-5ffa6e2f23b0}Gw64.sys
File Deleted : C:\windows\System32\drivers\{e223215e-2f9f-47a5-8264-4b12e6d7c1d7}Gw64.sys
File Deleted : C:\windows\System32\drivers\{fd5c71b0-bdaa-439c-8465-15717d777458}Gw64.sys
File Deleted : C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\searchplugins\dsrlte.xml
***** [ Scheduled Tasks ] *****
Task Deleted : Yahoo! Search
Task Deleted : Yahoo! Search Updater
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Classes\keepmysearch
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update Ttessab
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util Ttessab
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{e3a06b08-18fc-45fd-9922-38b48d04d699}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56535AA3-E5F8-4B14-9674-23558B4043C5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8be9dc07-c862-4563-9d3f-f7db5f1a1456}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e3a06b08-18fc-45fd-9922-38b48d04d699}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{56535AA3-E5F8-4B14-9674-23558B4043C5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{8DCB7100-DF86-4384-8842-8FA844297B3F}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Ttessab
Key Deleted : HKLM\SOFTWARE\Iminent
Key Deleted : HKLM\SOFTWARE\Ttessab
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Search
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ttessab
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v34.0.5 (x86 cs)
[giqmo9xt.default\prefs.js] - Line Deleted : user_pref("extensions.zonealarm.hmpgUrl", "hxxp://search.zonealarm.com/?src=hp&tbid=HFA5&Lan=EN&gu=1a383843c62147adb332e383e75abfad&tu=10G9y00ED2D20F0&sku=&tstsId=&ver=&");
[giqmo9xt.default\prefs.js] - Line Deleted : user_pref("extensions.zonealarm.newTabUrl", "hxxp://search.zonealarm.com/?src=nt&tbid=HFA5&Lan=EN&gu=1a383843c62147adb332e383e75abfad&tu=10G9y00ED2D20F0&sku=&tstsId=&ver=&");
[giqmo9xt.default\prefs.js] - Line Deleted : user_pref("extensions.zonealarm.tlbrSrchUrl", "hxxp://search.zonealarm.com/search?src=tb&tbid=HFA5&Lan={dfltLng}&gu=1a383843c62147adb332e383e75abfad&tu=10G9y00ED2D20F0&sku=&tstsId=&ver=&&q=");
-\\ Google Chrome v39.0.2171.95
*************************
AdwCleaner[R0].txt - [4406 octets] - [10/03/2014 18:12:45]
AdwCleaner[R1].txt - [1200 octets] - [19/05/2014 18:12:48]
AdwCleaner[R2].txt - [4063 octets] - [10/09/2014 20:57:57]
AdwCleaner[R3].txt - [8153 octets] - [15/12/2014 15:13:25]
AdwCleaner[S0].txt - [4518 octets] - [10/03/2014 18:14:29]
AdwCleaner[S1].txt - [1225 octets] - [19/05/2014 18:14:04]
AdwCleaner[S2].txt - [4032 octets] - [10/09/2014 20:59:41]
AdwCleaner[S3].txt - [7873 octets] - [15/12/2014 15:16:07]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [7933 octets] ##########
# Updated 08/12/2014 by Xplode
# Database : 2014-12-13.4 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Honza23 - HONZA23-PC
# Running from : C:\Users\Honza23\Desktop\adwcleaner_4.105.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : Update Ttessab
Service Deleted : {01ff3855-4a35-4386-a9e5-851a17533db4}Gw64
Service Deleted : {02a30246-1cec-4c49-8e7b-6b926efec85d}Gw64
Service Deleted : {1127f7b9-aef0-49e9-9436-f7da80d05cc5}Gw64
Service Deleted : {1436291c-76ca-4bbc-8653-740485c8638f}Gw64
Service Deleted : {2ca68fa5-d304-4b84-9dd2-a6dc1c1d2ca6}Gw64
Service Deleted : {408fcd28-f599-4b29-ada2-d72e26c39377}Gw64
Service Deleted : {42a2840c-2909-43d5-95e6-bca1040a0c50}Gw64
Service Deleted : {4351033a-acd6-47da-b89b-8a65492c9234}Gw64
Service Deleted : {4ecd3e68-eb27-40aa-b12d-5667ae0c0fc1}Gw64
Service Deleted : {692f148e-d2a7-4a97-a191-14c1f8d82587}Gw64
Service Deleted : {96611316-9343-40cf-a1ee-299e0bfa2140}Gw64
Service Deleted : {a98718a8-7722-4905-8d33-34677b352dba}Gw64
Service Deleted : {ac3b0a72-88bc-4124-9f74-c1d5bfa77944}Gw64
Service Deleted : {b0109f98-ffef-4d31-b74c-3e84ac22f0b4}Gw64
Service Deleted : {b3226d6b-57d1-49c8-8124-68272ad024dd}Gw64
Service Deleted : {bf802226-c4fc-40f2-b1b7-41a835c1b386}Gw64
Service Deleted : {c3338013-10e4-4bfa-977c-d3f18abe6f4f}Gw64
Service Deleted : {c4ad9507-436a-4c53-b644-35e1d46ce848}Gw64
Service Deleted : {dc44f1f8-14f7-4ddf-ac43-5ffa6e2f23b0}Gw64
Service Deleted : {e223215e-2f9f-47a5-8264-4b12e6d7c1d7}Gw64
Service Deleted : {fd5c71b0-bdaa-439c-8465-15717d777458}Gw64
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\Ttessab
Folder Deleted : C:\Users\Honza23\AppData\Local\pay-by-ads
Folder Deleted : C:\Users\Honza23\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Honza23\AppData\Local\GetnowUninstall
File Deleted : C:\windows\System32\drivers\{01ff3855-4a35-4386-a9e5-851a17533db4}Gw64.sys
File Deleted : C:\windows\System32\drivers\{02a30246-1cec-4c49-8e7b-6b926efec85d}Gw64.sys
File Deleted : C:\windows\System32\drivers\{1127f7b9-aef0-49e9-9436-f7da80d05cc5}Gw64.sys
File Deleted : C:\windows\System32\drivers\{1436291c-76ca-4bbc-8653-740485c8638f}Gw64.sys
File Deleted : C:\windows\System32\drivers\{2ca68fa5-d304-4b84-9dd2-a6dc1c1d2ca6}Gw64.sys
File Deleted : C:\windows\System32\drivers\{408fcd28-f599-4b29-ada2-d72e26c39377}Gw64.sys
File Deleted : C:\windows\System32\drivers\{42a2840c-2909-43d5-95e6-bca1040a0c50}Gw64.sys
File Deleted : C:\windows\System32\drivers\{4351033a-acd6-47da-b89b-8a65492c9234}Gw64.sys
File Deleted : C:\windows\System32\drivers\{4ecd3e68-eb27-40aa-b12d-5667ae0c0fc1}Gw64.sys
File Deleted : C:\windows\System32\drivers\{692f148e-d2a7-4a97-a191-14c1f8d82587}Gw64.sys
File Deleted : C:\windows\System32\drivers\{96611316-9343-40cf-a1ee-299e0bfa2140}Gw64.sys
File Deleted : C:\windows\System32\drivers\{a98718a8-7722-4905-8d33-34677b352dba}Gw64.sys
File Deleted : C:\windows\System32\drivers\{ac3b0a72-88bc-4124-9f74-c1d5bfa77944}Gw64.sys
File Deleted : C:\windows\System32\drivers\{b0109f98-ffef-4d31-b74c-3e84ac22f0b4}Gw64.sys
File Deleted : C:\windows\System32\drivers\{b3226d6b-57d1-49c8-8124-68272ad024dd}Gw64.sys
File Deleted : C:\windows\System32\drivers\{bf802226-c4fc-40f2-b1b7-41a835c1b386}Gw64.sys
File Deleted : C:\windows\System32\drivers\{c3338013-10e4-4bfa-977c-d3f18abe6f4f}Gw64.sys
File Deleted : C:\windows\System32\drivers\{c4ad9507-436a-4c53-b644-35e1d46ce848}Gw64.sys
File Deleted : C:\windows\System32\drivers\{dc44f1f8-14f7-4ddf-ac43-5ffa6e2f23b0}Gw64.sys
File Deleted : C:\windows\System32\drivers\{e223215e-2f9f-47a5-8264-4b12e6d7c1d7}Gw64.sys
File Deleted : C:\windows\System32\drivers\{fd5c71b0-bdaa-439c-8465-15717d777458}Gw64.sys
File Deleted : C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\searchplugins\dsrlte.xml
***** [ Scheduled Tasks ] *****
Task Deleted : Yahoo! Search
Task Deleted : Yahoo! Search Updater
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKCU\Software\Classes\keepmysearch
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update Ttessab
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util Ttessab
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{e3a06b08-18fc-45fd-9922-38b48d04d699}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{56535AA3-E5F8-4B14-9674-23558B4043C5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8be9dc07-c862-4563-9d3f-f7db5f1a1456}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e3a06b08-18fc-45fd-9922-38b48d04d699}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{237FDFDB-3722-470E-8BA8-90196DABE967}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{56535AA3-E5F8-4B14-9674-23558B4043C5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2CE3E00-F94A-4740-988E-03DC2F38C34F}
Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{8DCB7100-DF86-4384-8842-8FA844297B3F}]
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Ttessab
Key Deleted : HKLM\SOFTWARE\Iminent
Key Deleted : HKLM\SOFTWARE\Ttessab
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Search
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ttessab
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v34.0.5 (x86 cs)
[giqmo9xt.default\prefs.js] - Line Deleted : user_pref("extensions.zonealarm.hmpgUrl", "hxxp://search.zonealarm.com/?src=hp&tbid=HFA5&Lan=EN&gu=1a383843c62147adb332e383e75abfad&tu=10G9y00ED2D20F0&sku=&tstsId=&ver=&");
[giqmo9xt.default\prefs.js] - Line Deleted : user_pref("extensions.zonealarm.newTabUrl", "hxxp://search.zonealarm.com/?src=nt&tbid=HFA5&Lan=EN&gu=1a383843c62147adb332e383e75abfad&tu=10G9y00ED2D20F0&sku=&tstsId=&ver=&");
[giqmo9xt.default\prefs.js] - Line Deleted : user_pref("extensions.zonealarm.tlbrSrchUrl", "hxxp://search.zonealarm.com/search?src=tb&tbid=HFA5&Lan={dfltLng}&gu=1a383843c62147adb332e383e75abfad&tu=10G9y00ED2D20F0&sku=&tstsId=&ver=&&q=");
-\\ Google Chrome v39.0.2171.95
*************************
AdwCleaner[R0].txt - [4406 octets] - [10/03/2014 18:12:45]
AdwCleaner[R1].txt - [1200 octets] - [19/05/2014 18:12:48]
AdwCleaner[R2].txt - [4063 octets] - [10/09/2014 20:57:57]
AdwCleaner[R3].txt - [8153 octets] - [15/12/2014 15:13:25]
AdwCleaner[S0].txt - [4518 octets] - [10/03/2014 18:14:29]
AdwCleaner[S1].txt - [1225 octets] - [19/05/2014 18:14:04]
AdwCleaner[S2].txt - [4032 octets] - [10/09/2014 20:59:41]
AdwCleaner[S3].txt - [7873 octets] - [15/12/2014 15:16:07]
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [7933 octets] ##########
Re: Asi tu mám hosta

Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Asi tu mám hosta
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-12-2014 01
Ran by Honza23 (administrator) on HONZA23-PC on 15-12-2014 15:44:59
Running from C:\Users\Honza23\Desktop
Loaded Profile: Honza23 (Available profiles: Honza23)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
() C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
() C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
() C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Spotify Ltd) C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(MyHeritage) E:\MyHeritage\Bin\FTBCheckUpdates.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-06-27] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe [3417984 2012-05-17] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-06-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-06-19] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Family Tree Builder Update] => E:\MyHeritage\Bin\FTBCheckUpdates.exe [2532864 2013-11-12] (MyHeritage)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-29] (AVAST Software)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [Spotify] => C:\Users\Honza23\AppData\Roaming\Spotify\Spotify.exe [6342200 2014-09-22] (Spotify Ltd)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [Spotify Web Helper] => C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-22] (Spotify Ltd)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [Yahoo! Search] => C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {2dc9cb8e-967e-11e3-867b-50465ddb6ba6} - I:\autorun.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {3f99195e-c7a7-11e2-9436-50465ddb6ba6} - D:\Startme.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bebe-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bec0-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {e52b6a48-51be-11e2-918a-806e6f6e6963} - F:\AUTORUN.EXE
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {f0ffce42-eb0b-11e2-94c0-50465ddb6ba6} - D:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [1CryptoProviderIcons] -> {24808826-C2BF-4269-B3BA-89D1D5F431A4} => No File
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default
FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF SearchEngineOrder.1: Seznam
FF SelectedSearchEngine: Seznam
FF Homepage: https://www.seznam.cz/?clid=22668
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> E:\Picaso\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\searchplugins\seznam-avast.xml
FF Extension: Ttessab 1.0.1 - C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\Extensions\{b3226d6b-57d1-49c8-8124-68272ad024dd}.xpi [2014-12-11]
FF Extension: Adblock Plus - C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-15]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-31]
FF Extension: No Name - wrc@avast.com [Not Found]
Chrome:
=======
CHR StartupUrls: Default -> "https://www.seznam.cz/?clid=22668"
CHR DefaultSearchKeyword: Default -> seznam
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Media Go Detector) - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (Picasa) - E:\Picaso\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Profile: C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Ttessab) - C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default\Extensions\nanmbhilcdheddmaghbodjfpjbjabdhi [2014-11-24]
CHR Extension: (Peněženka Google) - C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-24]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-24] (AVAST Software)
R2 HiSuiteOuc64.exe; C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe [138272 2014-09-05] ()
R2 HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [219680 2014-09-05] ()
S3 Installer Service; C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{0C808377-8C23-44ED-9016-05F42E6D4900}\Installer\InstallerService.exe [125288 2013-09-17] ()
R2 MaintainerSvc2.69.9464532; C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe [123672 2014-12-15] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-24] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-24] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-24] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-24] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-02-15] (Disc Soft Ltd)
S3 hwdatacard; C:\Windows\System32\DRIVERS\ZDDriver.sys [122496 2010-01-20] (ZD Secret Incorporated)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2014-07-29] (Huawei Technologies Co., Ltd.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 Secdrv; C:\windows\SysWOW64\drivers\SECDRV.SYS [11616 2001-08-03] () [File not signed]
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2014-02-15] (Duplex Secure Ltd.)
S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X]
S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-15 15:44 - 2014-12-15 15:45 - 00018421 _____ () C:\Users\Honza23\Desktop\FRST.txt
2014-12-15 15:44 - 2014-12-15 15:45 - 00000000 ____D () C:\FRST
2014-12-15 15:42 - 2014-12-15 15:42 - 02119168 _____ (Farbar) C:\Users\Honza23\Desktop\FRST64.exe
2014-12-15 15:12 - 2014-12-15 15:12 - 02166272 _____ () C:\Users\Honza23\Desktop\adwcleaner_4.105.exe
2014-12-12 16:03 - 2009-03-23 19:48 - 00016896 _____ () C:\Users\Honza23\Desktop\DODAK malý.xls
2014-12-11 18:17 - 2014-12-15 15:18 - 00000656 _____ () C:\windows\PFRO.log
2014-12-11 18:12 - 2014-12-11 18:12 - 00000000 ____D () C:\windows\system32\appraiser
2014-12-11 17:45 - 2014-12-11 17:45 - 86433477 _____ () C:\Users\Honza23\Downloads\jak-na-to-opel-vectra-c-signum.rar
2014-12-11 17:42 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2014-12-11 17:42 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2014-12-11 17:42 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2014-12-11 17:42 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2014-12-11 17:42 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2014-12-11 17:42 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2014-12-11 17:42 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2014-12-11 17:42 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2014-12-11 17:42 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2014-12-11 17:42 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2014-12-10 19:07 - 2014-12-10 19:07 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf
2014-12-10 17:42 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2014-12-10 17:42 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-12-10 17:42 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2014-12-10 17:42 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-12-10 17:42 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2014-12-10 17:41 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-12-10 17:41 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-12-10 17:41 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-12-10 17:41 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-12-10 17:41 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-12-10 17:41 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-12-10 17:41 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-12-10 17:41 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-12-10 17:41 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-12-10 17:41 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-12-10 17:41 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-12-10 17:41 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-12-10 17:41 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-12-10 17:41 - 2014-11-22 03:35 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-12-10 17:41 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-12-10 17:41 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-12-10 17:41 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-12-10 17:41 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-12-10 17:41 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-12-10 17:41 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-12-10 17:41 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-12-10 17:41 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 17:41 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-12-10 17:41 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-12-10 17:41 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-12-10 17:41 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-12-10 17:41 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-12-10 17:41 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-12-10 17:41 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-12-10 17:41 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-12-10 17:41 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-12-10 17:41 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-12-10 17:41 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-12-10 17:41 - 2014-11-22 02:55 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-12-10 17:41 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-12-10 17:41 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-12-10 17:41 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-12-10 17:41 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-12-10 17:41 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-12-10 17:41 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-12-10 17:41 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-12-10 17:41 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 17:41 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-12-10 17:41 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-12-10 17:41 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-12-10 17:41 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-12-10 17:41 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-12-10 17:41 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-12-10 17:41 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-12-10 17:41 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-12-10 17:41 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-12-10 17:41 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-12-10 17:41 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-12-10 17:41 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-12-10 17:41 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-12-10 17:41 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-12-10 17:41 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2014-12-10 17:38 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2014-12-10 17:38 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2014-12-10 17:38 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2014-12-10 17:38 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\charmap.exe
2014-12-10 17:38 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2014-12-10 17:38 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2014-12-10 17:38 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2014-12-10 17:38 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2014-12-10 17:38 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2014-12-10 17:38 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2014-12-10 17:38 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-10 17:38 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2014-12-10 17:38 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2014-12-10 17:38 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2014-12-09 16:13 - 2014-12-09 16:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-08 16:37 - 2014-12-08 16:37 - 00000536 _____ () C:\Users\Public\Desktop\HiSuite.lnk
2014-12-08 16:37 - 2014-12-08 16:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite
2014-12-08 16:37 - 2014-12-08 16:37 - 00000000 ____D () C:\ProgramData\HiSuiteOuc
2014-12-08 16:37 - 2014-12-08 16:37 - 00000000 ____D () C:\ProgramData\HiSuiteDataSvc
2014-12-08 16:37 - 2014-12-08 16:37 - 00000000 ____D () C:\ProgramData\HandSetService
2014-12-08 16:37 - 2014-07-29 09:16 - 02152176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFUpdate_01009.dll
2014-12-08 16:37 - 2014-07-29 09:16 - 01721576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfCoInstaller01009.dll
2014-12-08 16:37 - 2014-07-29 09:16 - 01002728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\winusbcoinstaller2.dll
2014-12-07 01:00 - 2014-12-15 15:18 - 00007282 _____ () C:\windows\setupact.log
2014-12-07 01:00 - 2014-12-07 01:00 - 00000000 _____ () C:\windows\setuperr.log
2014-11-26 15:37 - 2014-11-26 15:38 - 00000000 ____D () C:\Users\Honza23\AppData\Local\{812D870F-20C4-4DA8-8A15-D2BAF0532518}
2014-11-23 10:13 - 2014-11-23 10:13 - 00000000 ____D () C:\Users\Honza23\Desktop\VeCe manual
2014-11-19 14:18 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-11-19 14:18 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2014-11-19 14:18 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-11-19 14:18 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\windows\SysWOW64\pku2u.dll
2014-11-18 18:57 - 2014-11-18 18:57 - 12552672 _____ () C:\Users\Honza23\Downloads\Manual_VeCe.zip
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-15 15:27 - 2009-07-14 05:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-15 15:27 - 2009-07-14 05:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-15 15:25 - 2012-12-29 14:42 - 01354617 _____ () C:\windows\WindowsUpdate.log
2014-12-15 15:24 - 2012-06-27 13:17 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-12-15 15:21 - 2014-09-03 10:17 - 00000000 ____D () C:\Users\Honza23\AppData\Roaming\Spotify
2014-12-15 15:20 - 2014-03-27 17:01 - 00000948 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-15 15:20 - 2013-05-16 22:18 - 00000380 _____ () C:\Users\Honza23\AppData\Roaming\sp_data.sys
2014-12-15 15:20 - 2013-05-16 22:18 - 00000000 ___HD () C:\ASUS.DAT
2014-12-15 15:18 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-12-15 15:17 - 2014-03-10 18:12 - 00000000 ____D () C:\AdwCleaner
2014-12-15 14:52 - 2014-03-27 17:01 - 00000952 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-15 14:39 - 2014-10-28 07:11 - 00000000 ____D () C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c
2014-12-15 14:38 - 2014-03-10 15:33 - 00000000 ____D () C:\Program Files\trend micro
2014-12-14 11:59 - 2014-05-31 07:38 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-12-13 22:10 - 2009-07-14 03:34 - 00000612 _____ () C:\windows\win.ini
2014-12-13 22:03 - 2011-02-19 06:36 - 00669116 _____ () C:\windows\system32\perfh005.dat
2014-12-13 22:03 - 2011-02-19 06:36 - 00141744 _____ () C:\windows\system32\perfc005.dat
2014-12-13 22:03 - 2009-07-14 06:13 - 01584554 _____ () C:\windows\system32\PerfStringBackup.INI
2014-12-11 19:05 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2014-12-11 18:19 - 2012-12-29 15:04 - 00002164 _____ () C:\windows\system32\AutoRunFilter.ini
2014-12-11 18:17 - 2013-05-22 20:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-11 18:12 - 2014-05-07 15:54 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-12-11 18:12 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-12-11 18:12 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\AppCompat
2014-12-11 17:53 - 2013-08-17 06:46 - 00000000 ____D () C:\windows\system32\MRT
2014-12-11 17:43 - 2013-05-23 17:18 - 112710672 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-12-09 23:43 - 2012-06-27 13:17 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-12-09 23:43 - 2012-06-27 13:17 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-09 23:43 - 2012-06-27 13:17 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-12-09 22:31 - 2014-11-14 18:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2014-12-08 16:37 - 2014-01-22 16:49 - 00000000 ____D () C:\Users\Honza23\AppData\Local\HiSuite
2014-12-02 19:56 - 2013-05-22 20:52 - 00001141 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-12-02 19:56 - 2013-05-22 20:52 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-28 16:58 - 2013-05-16 22:18 - 00000000 ____D () C:\Users\Honza23
2014-11-22 07:09 - 2014-05-31 07:38 - 01041168 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2014-11-15 20:47 - 2013-06-03 13:27 - 00003948 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-15 20:47 - 2013-06-03 13:27 - 00003696 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
Some content of TEMP:
====================
C:\Users\Honza23\AppData\Local\Temp\Quarantine.exe
C:\Users\Honza23\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-11 18:58
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-12-2014 01
Ran by Honza23 at 2014-12-15 15:45:52
Running from C:\Users\Honza23\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
„Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Mesh ActiveX“ nuotolinių ryšių valdiklis (HKLM-x32\...\{9024FE65-46B8-4C8A-9D98-8DCB6BD5F598}) (Version: 15.4.5722.2 - Microsoft Corporation)
„Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
µTorrent (HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\uTorrent) (Version: 3.4.2.31536 - BitTorrent Inc.)
3G HSDPA Modem (HKLM-x32\...\3G HSDPA Modem) (Version: 1.0.0.1 - 3G HSDPA Modem) <==== ATTENTION!
ActiveX контрола на Windows Live Mesh за отдалечени връзки (HKLM-x32\...\{B3BA4D1C-23EF-4859-9C11-1B2CCB7FADBB}) (Version: 15.4.5722.2 - Microsoft Corporation)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Reader X (10.1.12) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.12 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.4.0 - Asmedia Technology)
ASUS FancyStart (HKLM-x32\...\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}) (Version: 1.1.1 - ASUSTeK Computer Inc.)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.3 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.7 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.2 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0002 - ASUS)
ASUS WebStorage Sync Agent (HKLM-x32\...\ASUS WebStorage) (Version: 1.1.2.97 - ASUS Cloud Corporation)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.12.309 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0020 - ASUS)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
Balíček ovladače systému Windows - Nokia Modem (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Balíček ovladače systému Windows - Nokia Modem (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Battle.net (HKLM-x32\...\Battle.net) (Version: - )
Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: 7.3.124.0 - Microsoft Corporation)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.66.1075 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
Control ActiveX Windows Live Mesh pentru conexiuni la distanță (HKLM-x32\...\{260E3D78-94E6-47EC-8E29-46301572BB1E}) (Version: 15.4.5722.2 - Microsoft Corporation)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1126 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media)
Diablo (HKLM-x32\...\Diablo) (Version: - )
Diablo II (HKLM-x32\...\Diablo II) (Version: - )
Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media)
ETDWare PS/2-X64 8.0.5.1_WHQL (HKLM\...\Elantech) (Version: 8.0.5.1 - ELAN Microelectronic Corp.)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
HiSuite (HKLM-x32\...\Hi Suite) (Version: 32.610.28.00.06 - Huawei Technologies Co.,Ltd)
InstantOn for NB (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.3.3 - ASUS)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kontrola Windows Live Mesh ActiveX za daljinske veze (HKLM-x32\...\{19CBDE24-2761-49A5-816B-D2BA65D0CA8D}) (Version: 15.4.5722.2 - Microsoft Corporation)
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (HKLM-x32\...\{CA227A9D-09BE-4BFB-9764-48FED2DA5454}) (Version: 15.4.5722.2 - Microsoft Corporation)
Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media)
Malwarebytes Anti-Malware verze 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Media Go (HKLM-x32\...\{362AB21A-E2C4-40CE-81C2-8C4D62B0635A}) (Version: 2.4.256 - Sony)
Media Go Video Playback Engine 1.116.104.02020 (HKLM-x32\...\{54215B8A-6212-8DB8-39B4-98EE2BB98BD1}) (Version: 1.116.104.02020 - Sony)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Age of Empires II (HKLM-x32\...\Age of Empires 2.0) (Version: - )
Microsoft Age of Empires II: The Conquerors Expansion (HKLM-x32\...\Age of Empires II: The Conquerors Expansion 1.0) (Version: - )
Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 34.0.5 (x86 cs) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 cs)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
myBitCast 1.0.0.4 (HKLM\...\myBitCast) (Version: 1.0.0.4 - ASUS Cloud Corporation)
MyHeritage Family Tree Builder (HKLM-x32\...\Family Tree Builder) (Version: 7.0.0.7128 - MyHeritage.com)
Nokia Connectivity Cable Driver (HKLM-x32\...\{A57025CC-5F2E-4D01-B387-06DB10500D43}) (Version: 7.1.78.0 - Nokia)
Nokia PC Suite (HKLM-x32\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
Nokia PC Suite (x32 Version: 7.1.180.94 - Nokia) Hidden
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation)
PC Connectivity Solution (HKLM-x32\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
Pharaoh (HKLM-x32\...\Pharaoh) (Version: - )
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media)
PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.14.6.15183 - Sony Computer Entertainment Inc.)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
PokerStars.net (HKLM-x32\...\PokerStars.net) (Version: - PokerStars.net) <==== ATTENTION!
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
rajče průvodce verze 1.59.48.263 (HKLM-x32\...\rajče.net_is1) (Version: - rajče.net)
Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}) (Version: 1.2.0.40 - Ralink)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6454 - Realtek Semiconductor Corp.)
Seznam Software (HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\SeznamInstall) (Version: - Seznam.cz)
Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
Sony Ericsson Update Engine (HKLM-x32\...\Update Engine) (Version: 2.13.6.201305161305 - Sony Ericsson Communications AB)
Sony PC Companion 2.10.206 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.206 - Sony)
Spotify (HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Spotify) (Version: 0.9.13.24.g5dbb3103 - Spotify AB)
The KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: - )
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH)
Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX kontrola za daljinske veze (HKLM-x32\...\{8985AE5E-622A-4980-8BF8-0A1830643220}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX vadīkla attālajiem savienojumiem (HKLM-x32\...\{A3A775C9-5A63-4C55-8FDD-427A5B8F5D2B}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-i juhtelement kaugühendustele (HKLM-x32\...\{216ACEC1-4556-4717-A8DE-3F7F5F9C6F63}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM-x32\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.1 - ASUS)
Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.32 - ASUS)
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
13-11-2014 15:10:37 Windows Update
18-11-2014 13:53:19 Windows Update
20-11-2014 15:53:38 Windows Update
25-11-2014 15:11:07 Windows Update
02-12-2014 18:11:21 Windows Update
06-12-2014 19:48:57 Windows Update
11-12-2014 16:39:58 Windows Update
11-12-2014 17:11:55 Windows Update
14-12-2014 10:59:15 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0096EEE7-756E-48F7-BA44-4D698386714A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-03] (Google Inc.)
Task: {1A8474FA-6862-4966-95DB-D87C0B3BEEA4} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-05-15] (ASUS)
Task: {20EC82D1-A0D2-40D6-A35B-FB890B417F0C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-09] (Adobe Systems Incorporated)
Task: {2724D7B5-FE8C-46C7-BFE0-E2E65B2EF1D4} - System32\Tasks\Security Center Update - 4209252972 => C:\Users\Honza23\AppData\Roaming\Wyevzena\ceapro.exe <==== ATTENTION
Task: {2818EF84-13E5-4F6C-B7E5-735CAD0BB6B1} - System32\Tasks\{C52F011B-8983-4AB7-9013-50A878EC80A0} => C:\Users\Honza23\Downloads\Nokia_PC_Suite_ALL.exe [2013-05-23] ()
Task: {2A821617-A068-4B35-A773-80CE06B6AF9A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-03] (Google Inc.)
Task: {42062429-B81A-4233-A7B9-3FAD216385D3} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2012-09-27] ()
Task: {434F761C-9A6F-41B8-8073-C096168C0B83} - System32\Tasks\{19494ED3-405A-4563-9276-5DC6A3BAD89A} => C:\Users\Honza23\Downloads\Nokia_PC_Suite_ALL.exe [2013-05-23] ()
Task: {43BB3455-845F-41C6-83A4-19936A1FD065} - System32\Tasks\{D4109F31-A24F-48D8-9BF7-195929BE504C} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {464BD720-7D04-4F96-982A-4A45E5EA4322} - System32\Tasks\{1B964C43-BDC8-4CE6-B029-36A84C506C22} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {5583816C-8AD5-4B18-ABB7-021BD83E9114} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-07-11] (ASUSTeK Computer Inc.)
Task: {595CF607-E84D-4563-889D-98A0237AEC91} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-26] (ASUSTek Computer Inc.)
Task: {62F6934B-B3C2-45CC-98F7-AE073B6D05B1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {6A5C8C15-A964-4ACE-8F68-CC4459C602AD} - System32\Tasks\{111349EA-DB34-460D-97C9-033316DF8DC4} => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-07-11] (ASUSTeK Computer Inc.)
Task: {7A4DFE23-3213-4082-A2F2-BA588E8EBAD5} - System32\Tasks\{83388A5B-6ADD-4697-93AF-DDDC7723EB0D} => pcalua.exe -a C:\windows\system32\pcwrun.exe -c "C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe"
Task: {7CFFD3A0-4EB2-42E8-A063-68A27BC97162} - System32\Tasks\{50848112-E467-4994-94B2-9141DBF125AD} => pcalua.exe -a C:\Users\Honza23\Downloads\Nokia_PC_Suite_ALL.exe -d C:\Users\Honza23\Downloads
Task: {7E285B64-0885-4878-9D49-37A3AFD37398} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-06-21] (ASUSTeK Computer Inc.)
Task: {7F0F5A1A-5528-4E01-AB18-D99AD71584C0} - System32\Tasks\{FDC82A4D-0583-4404-9D0F-83B4FA84B271} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {81B83B70-C236-49E5-B427-B13CF0EEE1BA} - System32\Tasks\{D4F7C290-60E9-4592-8CAC-9BF4BE16B187} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {8D08DD06-415A-4D14-9307-847537CBC604} - System32\Tasks\{075FCC47-23E3-4B64-976A-3D8A23CAB056} => pcalua.exe -a "E:\Filmy\Vlk z Wall Street\The Wolf of Wall Street 2013\WMP x264 Codec Pack.exe" -d "E:\Filmy\Vlk z Wall Street\The Wolf of Wall Street 2013"
Task: {9492046B-6840-4474-80C1-8C3BDE0705D4} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-24] (AVAST Software)
Task: {985D1402-81DB-4972-8CB7-81B54BF8D0BB} - System32\Tasks\{5F7BB92A-A13E-4E3F-AAC4-54C68ABB03F0} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {A35DBAA5-6DB7-4CEE-94C6-3E5055CC295B} - System32\Tasks\{83C4A4D3-14C4-4DA7-940B-41A87A95B7AE} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {C5B68A18-5D63-454B-B215-983DE7792AB8} - System32\Tasks\{B64216B4-14F2-485E-AE3C-6B75DE096E13} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {E580C377-879A-4880-A84A-26A95215BF6E} - System32\Tasks\{928F114D-7A82-4ADE-A7A3-2E6ACA7EE4B8} => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-07-11] (ASUSTeK Computer Inc.)
Task: {F0189561-A568-435E-898F-DE400F2ADDB4} - System32\Tasks\{66241A78-0513-45DA-ABA2-B53364604118} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {F42BC3E7-7934-4CF2-97EB-1586ADD933B7} - System32\Tasks\{132F5DB5-9051-4531-B8EA-F6308BD31AAB} => pcalua.exe -a C:\Users\Honza23\Downloads\mozilla-firefox-lista-centrumcz.exe -d C:\Users\Honza23\Downloads
Task: {F704115B-F865-47D9-9724-27C12563A3C6} - System32\Tasks\{55E66DE4-D0E2-4D83-9254-129E44C375BC} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-12-08 16:37 - 2014-09-05 08:40 - 00138272 _____ () C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
2014-12-08 16:37 - 2014-09-05 08:40 - 00219680 _____ () C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
2014-10-28 04:20 - 2014-12-15 14:39 - 00123672 _____ () C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2014-07-24 16:42 - 2014-07-24 16:42 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-12-15 14:31 - 2014-12-15 14:31 - 02908160 _____ () C:\Program Files\AVAST Software\Avast\defs\14121500\algo.dll
2012-06-07 23:12 - 2012-06-07 23:12 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2014-07-24 16:42 - 2014-07-24 16:42 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-12-09 16:13 - 2014-12-09 16:13 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-12-09 23:43 - 2014-12-09 23:43 - 16841392 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
========================= Accounts: ==========================
Administrator (S-1-5-21-1544955830-4211015516-3942192515-500 - Administrator - Disabled)
Guest (S-1-5-21-1544955830-4211015516-3942192515-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1544955830-4211015516-3942192515-1002 - Limited - Enabled)
Honza23 (S-1-5-21-1544955830-4211015516-3942192515-1000 - Administrator - Enabled) => C:\Users\Honza23
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/14/2014 08:10:15 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: )
Description: Služba Šifrování neinicializovala databázi katalogu. Chyba součásti ESENT: -1305.
Error: (12/11/2014 06:11:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 34.0.5.5443, časové razítko: 0x5475dd5d
Název chybujícího modulu: mozalloc.dll, verze: 34.0.5.5443, časové razítko: 0x5475d664
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x6f8
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/11/2014 05:41:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 34.0.5.5443, časové razítko: 0x5475dd5d
Název chybujícího modulu: mozalloc.dll, verze: 34.0.5.5443, časové razítko: 0x5475d664
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x18e0
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/10/2014 07:00:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 34.0.5.5443, časové razítko: 0x5475dd5d
Název chybujícího modulu: mozalloc.dll, verze: 34.0.5.5443, časové razítko: 0x5475d664
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x66c
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/10/2014 07:00:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program firefox.exe verze 34.0.5.5443 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: 1e04
Čas spuštění: 01d0149f9f6537ea
Čas ukončení: 271
Cesta k aplikaci: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
ID hlášení: 57b73104-8096-11e4-84fe-50465ddb6ba6
Error: (12/07/2014 02:13:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 33.1.0.5423, časové razítko: 0x545c0a59
Název chybujícího modulu: mozalloc.dll, verze: 33.1.0.5423, časové razítko: 0x545be5ee
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x13b8
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/07/2014 02:13:38 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program firefox.exe verze 33.1.0.5423 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: ef4
Čas spuštění: 01d0118b70394e6c
Čas ukončení: 76
Cesta k aplikaci: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
ID hlášení: 407099f3-7dae-11e4-84fe-50465ddb6ba6
Error: (12/03/2014 06:31:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 33.1.0.5423, časové razítko: 0x545c0a59
Název chybujícího modulu: mozalloc.dll, verze: 33.1.0.5423, časové razítko: 0x545be5ee
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x14c0
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/02/2014 07:01:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 33.1.0.5423, časové razítko: 0x545c0a59
Název chybujícího modulu: mozalloc.dll, verze: 33.1.0.5423, časové razítko: 0x545be5ee
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x14ec
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/01/2014 07:35:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 33.1.0.5423, časové razítko: 0x545c0a59
Název chybujícího modulu: mozalloc.dll, verze: 33.1.0.5423, časové razítko: 0x545be5ee
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x1158
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
System errors:
=============
Error: (12/15/2014 03:19:17 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
sptd
Error: (12/15/2014 03:18:35 PM) (Source: sptd) (EventID: 4) (User: )
Description: Ovladač zjistil interní chybu ve vlastní struktuře dat u .
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba MaintainerSvc2.69.9464532 byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Presentation Foundation Font Cache 3.0.0.0 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Management and Security Application User Notification Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Intel(R) Management and Security Application Local Management Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Live ID Sign-in Assistant byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Update Ttessab byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 5000 milisekund: Restartovat službu.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU B820 @ 1.70GHz
Percentage of memory in use: 32%
Total physical RAM: 6048.13 MB
Available physical RAM: 4074.27 MB
Total Pagefile: 12094.43 MB
Available Pagefile: 9859.5 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:111.93 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (DATA) (Fixed) (Total:254.36 GB) (Free:237.33 GB) NTFS
Drive f: (DIABLO) (CDROM) (Total:0.6 GB) (Free:0 GB) CDFS
Drive i: (Pharaoh) (CDROM) (Total:0.64 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 982AE9F6)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=186.3 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=254.4 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Ran by Honza23 (administrator) on HONZA23-PC on 15-12-2014 15:44:59
Running from C:\Users\Honza23\Desktop
Loaded Profile: Honza23 (Available profiles: Honza23)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
() C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
() C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
() C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Spotify Ltd) C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(MyHeritage) E:\MyHeritage\Bin\FTBCheckUpdates.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-31] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-03-21] (Alcor Micro Corp.)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277480 2011-08-16] (Realtek Semiconductor)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3331312 2012-06-27] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\AsusWSPanel.exe [3417984 2012-05-17] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-06-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-06-19] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM-x32\...\Run: [Family Tree Builder Update] => E:\MyHeritage\Bin\FTBCheckUpdates.exe [2532864 2013-11-12] (MyHeritage)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-29] (AVAST Software)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [Spotify] => C:\Users\Honza23\AppData\Roaming\Spotify\Spotify.exe [6342200 2014-09-22] (Spotify Ltd)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [Spotify Web Helper] => C:\Users\Honza23\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-22] (Spotify Ltd)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [Yahoo! Search] => C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {2dc9cb8e-967e-11e3-867b-50465ddb6ba6} - I:\autorun.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {3f99195e-c7a7-11e2-9436-50465ddb6ba6} - D:\Startme.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bebe-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bec0-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {e52b6a48-51be-11e2-918a-806e6f6e6963} - F:\AUTORUN.EXE
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {f0ffce42-eb0b-11e2-94c0-50465ddb6ba6} - D:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}\_77B5857C27147149171BE7.exe ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [1CryptoProviderIcons] -> {24808826-C2BF-4269-B3BA-89D1D5F431A4} => No File
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.2.97\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus.msn.com
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default
FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF SearchEngineOrder.1: Seznam
FF SelectedSearchEngine: Seznam
FF Homepage: https://www.seznam.cz/?clid=22668
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> E:\Picaso\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\searchplugins\seznam-avast.xml
FF Extension: Ttessab 1.0.1 - C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\Extensions\{b3226d6b-57d1-49c8-8124-68272ad024dd}.xpi [2014-12-11]
FF Extension: Adblock Plus - C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-15]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-05-31]
FF Extension: No Name - wrc@avast.com [Not Found]
Chrome:
=======
CHR StartupUrls: Default -> "https://www.seznam.cz/?clid=22668"
CHR DefaultSearchKeyword: Default -> seznam
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Media Go Detector) - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (Picasa) - E:\Picaso\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Profile: C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Ttessab) - C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default\Extensions\nanmbhilcdheddmaghbodjfpjbjabdhi [2014-11-24]
CHR Extension: (Peněženka Google) - C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-24]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-24] (AVAST Software)
R2 HiSuiteOuc64.exe; C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe [138272 2014-09-05] ()
R2 HuaweiHiSuiteService64.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe [219680 2014-09-05] ()
S3 Installer Service; C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{0C808377-8C23-44ED-9016-05F42E6D4900}\Installer\InstallerService.exe [125288 2013-09-17] ()
R2 MaintainerSvc2.69.9464532; C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe [123672 2014-12-15] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-24] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-24] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-24] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-24] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-11-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-24] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-24] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-24] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-02-15] (Disc Soft Ltd)
S3 hwdatacard; C:\Windows\System32\DRIVERS\ZDDriver.sys [122496 2010-01-20] (ZD Secret Incorporated)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2014-07-29] (Huawei Technologies Co., Ltd.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
S3 Secdrv; C:\windows\SysWOW64\drivers\SECDRV.SYS [11616 2001-08-03] () [File not signed]
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [868848 2014-02-15] (Duplex Secure Ltd.)
S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X]
S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-15 15:44 - 2014-12-15 15:45 - 00018421 _____ () C:\Users\Honza23\Desktop\FRST.txt
2014-12-15 15:44 - 2014-12-15 15:45 - 00000000 ____D () C:\FRST
2014-12-15 15:42 - 2014-12-15 15:42 - 02119168 _____ (Farbar) C:\Users\Honza23\Desktop\FRST64.exe
2014-12-15 15:12 - 2014-12-15 15:12 - 02166272 _____ () C:\Users\Honza23\Desktop\adwcleaner_4.105.exe
2014-12-12 16:03 - 2009-03-23 19:48 - 00016896 _____ () C:\Users\Honza23\Desktop\DODAK malý.xls
2014-12-11 18:17 - 2014-12-15 15:18 - 00000656 _____ () C:\windows\PFRO.log
2014-12-11 18:12 - 2014-12-11 18:12 - 00000000 ____D () C:\windows\system32\appraiser
2014-12-11 17:45 - 2014-12-11 17:45 - 86433477 _____ () C:\Users\Honza23\Downloads\jak-na-to-opel-vectra-c-signum.rar
2014-12-11 17:42 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2014-12-11 17:42 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2014-12-11 17:42 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2014-12-11 17:42 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2014-12-11 17:42 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2014-12-11 17:42 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2014-12-11 17:42 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2014-12-11 17:42 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2014-12-11 17:42 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2014-12-11 17:42 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2014-12-10 19:07 - 2014-12-10 19:07 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf
2014-12-10 17:42 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-12-10 17:42 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2014-12-10 17:42 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-12-10 17:42 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\windows\system32\aitstatic.exe
2014-12-10 17:42 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-12-10 17:42 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\windows\SysWOW64\WindowsCodecs.dll
2014-12-10 17:41 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-12-10 17:41 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-12-10 17:41 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-12-10 17:41 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-12-10 17:41 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-12-10 17:41 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-12-10 17:41 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-12-10 17:41 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-12-10 17:41 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-12-10 17:41 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-12-10 17:41 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-12-10 17:41 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-12-10 17:41 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-12-10 17:41 - 2014-11-22 03:35 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-12-10 17:41 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-12-10 17:41 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-12-10 17:41 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-12-10 17:41 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-12-10 17:41 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-12-10 17:41 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-12-10 17:41 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-12-10 17:41 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 17:41 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-12-10 17:41 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-12-10 17:41 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-12-10 17:41 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-12-10 17:41 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-12-10 17:41 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-12-10 17:41 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-12-10 17:41 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-12-10 17:41 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-12-10 17:41 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-12-10 17:41 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-12-10 17:41 - 2014-11-22 02:55 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-12-10 17:41 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-12-10 17:41 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-12-10 17:41 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-12-10 17:41 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-12-10 17:41 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-12-10 17:41 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-12-10 17:41 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-12-10 17:41 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 17:41 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-12-10 17:41 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-12-10 17:41 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-12-10 17:41 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-12-10 17:41 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-12-10 17:41 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-12-10 17:41 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-12-10 17:41 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-12-10 17:41 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-12-10 17:41 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-12-10 17:41 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-12-10 17:41 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-12-10 17:41 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-12-10 17:41 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-12-10 17:41 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tdx.sys
2014-12-10 17:38 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2014-12-10 17:38 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2014-12-10 17:38 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\windows\system32\charmap.exe
2014-12-10 17:38 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\windows\SysWOW64\charmap.exe
2014-12-10 17:38 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\windows\system32\WsmSvc.dll
2014-12-10 17:38 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\windows\system32\WSManMigrationPlugin.dll
2014-12-10 17:38 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\windows\system32\WsmWmiPl.dll
2014-12-10 17:38 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\windows\system32\WsmAuto.dll
2014-12-10 17:38 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\windows\system32\WSManHTTPConfig.exe
2014-12-10 17:38 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmSvc.dll
2014-12-10 17:38 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-10 17:38 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmWmiPl.dll
2014-12-10 17:38 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\WsmAuto.dll
2014-12-10 17:38 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSManHTTPConfig.exe
2014-12-09 16:13 - 2014-12-09 16:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-08 16:37 - 2014-12-08 16:37 - 00000536 _____ () C:\Users\Public\Desktop\HiSuite.lnk
2014-12-08 16:37 - 2014-12-08 16:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HiSuite
2014-12-08 16:37 - 2014-12-08 16:37 - 00000000 ____D () C:\ProgramData\HiSuiteOuc
2014-12-08 16:37 - 2014-12-08 16:37 - 00000000 ____D () C:\ProgramData\HiSuiteDataSvc
2014-12-08 16:37 - 2014-12-08 16:37 - 00000000 ____D () C:\ProgramData\HandSetService
2014-12-08 16:37 - 2014-07-29 09:16 - 02152176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WUDFUpdate_01009.dll
2014-12-08 16:37 - 2014-07-29 09:16 - 01721576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdfCoInstaller01009.dll
2014-12-08 16:37 - 2014-07-29 09:16 - 01002728 _____ (Microsoft Corporation) C:\windows\system32\Drivers\winusbcoinstaller2.dll
2014-12-07 01:00 - 2014-12-15 15:18 - 00007282 _____ () C:\windows\setupact.log
2014-12-07 01:00 - 2014-12-07 01:00 - 00000000 _____ () C:\windows\setuperr.log
2014-11-26 15:37 - 2014-11-26 15:38 - 00000000 ____D () C:\Users\Honza23\AppData\Local\{812D870F-20C4-4DA8-8A15-D2BAF0532518}
2014-11-23 10:13 - 2014-11-23 10:13 - 00000000 ____D () C:\Users\Honza23\Desktop\VeCe manual
2014-11-19 14:18 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2014-11-19 14:18 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\windows\system32\pku2u.dll
2014-11-19 14:18 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2014-11-19 14:18 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\windows\SysWOW64\pku2u.dll
2014-11-18 18:57 - 2014-11-18 18:57 - 12552672 _____ () C:\Users\Honza23\Downloads\Manual_VeCe.zip
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-15 15:27 - 2009-07-14 05:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-15 15:27 - 2009-07-14 05:45 - 00018736 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-15 15:25 - 2012-12-29 14:42 - 01354617 _____ () C:\windows\WindowsUpdate.log
2014-12-15 15:24 - 2012-06-27 13:17 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-12-15 15:21 - 2014-09-03 10:17 - 00000000 ____D () C:\Users\Honza23\AppData\Roaming\Spotify
2014-12-15 15:20 - 2014-03-27 17:01 - 00000948 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-15 15:20 - 2013-05-16 22:18 - 00000380 _____ () C:\Users\Honza23\AppData\Roaming\sp_data.sys
2014-12-15 15:20 - 2013-05-16 22:18 - 00000000 ___HD () C:\ASUS.DAT
2014-12-15 15:18 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-12-15 15:17 - 2014-03-10 18:12 - 00000000 ____D () C:\AdwCleaner
2014-12-15 14:52 - 2014-03-27 17:01 - 00000952 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-15 14:39 - 2014-10-28 07:11 - 00000000 ____D () C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c
2014-12-15 14:38 - 2014-03-10 15:33 - 00000000 ____D () C:\Program Files\trend micro
2014-12-14 11:59 - 2014-05-31 07:38 - 00004182 _____ () C:\windows\System32\Tasks\avast! Emergency Update
2014-12-13 22:10 - 2009-07-14 03:34 - 00000612 _____ () C:\windows\win.ini
2014-12-13 22:03 - 2011-02-19 06:36 - 00669116 _____ () C:\windows\system32\perfh005.dat
2014-12-13 22:03 - 2011-02-19 06:36 - 00141744 _____ () C:\windows\system32\perfc005.dat
2014-12-13 22:03 - 2009-07-14 06:13 - 01584554 _____ () C:\windows\system32\PerfStringBackup.INI
2014-12-11 19:05 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2014-12-11 18:19 - 2012-12-29 15:04 - 00002164 _____ () C:\windows\system32\AutoRunFilter.ini
2014-12-11 18:17 - 2013-05-22 20:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-11 18:12 - 2014-05-07 15:54 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-12-11 18:12 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\PolicyDefinitions
2014-12-11 18:12 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\AppCompat
2014-12-11 17:53 - 2013-08-17 06:46 - 00000000 ____D () C:\windows\system32\MRT
2014-12-11 17:43 - 2013-05-23 17:18 - 112710672 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-12-09 23:43 - 2012-06-27 13:17 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-12-09 23:43 - 2012-06-27 13:17 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-09 23:43 - 2012-06-27 13:17 - 00003768 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-12-09 22:31 - 2014-11-14 18:23 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2014-12-08 16:37 - 2014-01-22 16:49 - 00000000 ____D () C:\Users\Honza23\AppData\Local\HiSuite
2014-12-02 19:56 - 2013-05-22 20:52 - 00001141 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-12-02 19:56 - 2013-05-22 20:52 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-28 16:58 - 2013-05-16 22:18 - 00000000 ____D () C:\Users\Honza23
2014-11-22 07:09 - 2014-05-31 07:38 - 01041168 _____ (AVAST Software) C:\windows\system32\Drivers\aswsnx.sys
2014-11-15 20:47 - 2013-06-03 13:27 - 00003948 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-15 20:47 - 2013-06-03 13:27 - 00003696 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
Some content of TEMP:
====================
C:\Users\Honza23\AppData\Local\Temp\Quarantine.exe
C:\Users\Honza23\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-11 18:58
==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-12-2014 01
Ran by Honza23 at 2014-12-15 15:45:52
Running from C:\Users\Honza23\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
„Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden
„Windows Live Mesh ActiveX“ nuotolinių ryšių valdiklis (HKLM-x32\...\{9024FE65-46B8-4C8A-9D98-8DCB6BD5F598}) (Version: 15.4.5722.2 - Microsoft Corporation)
„Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden
„Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
µTorrent (HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\uTorrent) (Version: 3.4.2.31536 - BitTorrent Inc.)
3G HSDPA Modem (HKLM-x32\...\3G HSDPA Modem) (Version: 1.0.0.1 - 3G HSDPA Modem) <==== ATTENTION!
ActiveX контрола на Windows Live Mesh за отдалечени връзки (HKLM-x32\...\{B3BA4D1C-23EF-4859-9C11-1B2CCB7FADBB}) (Version: 15.4.5722.2 - Microsoft Corporation)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Reader X (10.1.12) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.12 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.2.0117.08443 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.0117.08443 - Alcor Micro Corp.) Hidden
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.4.0 - Asmedia Technology)
ASUS FancyStart (HKLM-x32\...\{C944B4C5-1C4D-4D95-8AC0-7CEF13914131}) (Version: 1.1.1 - ASUSTeK Computer Inc.)
ASUS Instant Connect (HKLM-x32\...\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.2 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.3 - ASUS)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.7 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.2.2 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0002 - ASUS)
ASUS WebStorage Sync Agent (HKLM-x32\...\ASUS WebStorage) (Version: 1.1.2.97 - ASUS Cloud Corporation)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.12.309 - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0020 - ASUS)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
Balíček ovladače systému Windows - Nokia Modem (02/25/2011 4.7) (HKLM\...\E0AC723A3DE3A04256288CADBBB011B112AED454) (Version: 02/25/2011 4.7 - Nokia)
Balíček ovladače systému Windows - Nokia Modem (02/25/2011 7.01.0.9) (HKLM\...\72A50F48CC5601190B9C4E74D81161693133E7F7) (Version: 02/25/2011 7.01.0.9 - Nokia)
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Battle.net (HKLM-x32\...\Battle.net) (Version: - )
Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: 7.3.124.0 - Microsoft Corporation)
BS.Player FREE (HKLM-x32\...\BSPlayerf) (Version: 2.66.1075 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
Control ActiveX Windows Live Mesh pentru conexiuni la distanță (HKLM-x32\...\{260E3D78-94E6-47EC-8E29-46301572BB1E}) (Version: 15.4.5722.2 - Microsoft Corporation)
CyberLink LabelPrint (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.3624 - CyberLink Corp.)
CyberLink Media Suite (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2926 - CyberLink Corp.)
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1126 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Deadtime Stories (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}) (Version: - Oberon Media)
Diablo (HKLM-x32\...\Diablo) (Version: - )
Diablo II (HKLM-x32\...\Diablo II) (Version: - )
Dream Day First Home (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}) (Version: - Oberon Media)
Dream Vacation Solitaire (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}) (Version: - Oberon Media)
ETDWare PS/2-X64 8.0.5.1_WHQL (HKLM\...\Elantech) (Version: 8.0.5.1 - ELAN Microelectronic Corp.)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galapago (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}) (Version: - Oberon Media)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 39.0.2171.95 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
HiSuite (HKLM-x32\...\Hi Suite) (Version: 32.610.28.00.06 - Huawei Technologies Co.,Ltd)
InstantOn for NB (HKLM-x32\...\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 2.3.3 - ASUS)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2559 - Intel Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kontrola Windows Live Mesh ActiveX za daljinske veze (HKLM-x32\...\{19CBDE24-2761-49A5-816B-D2BA65D0CA8D}) (Version: 15.4.5722.2 - Microsoft Corporation)
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (HKLM-x32\...\{CA227A9D-09BE-4BFB-9764-48FED2DA5454}) (Version: 15.4.5722.2 - Microsoft Corporation)
Mahjong Memoirs (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}) (Version: - Oberon Media)
Malwarebytes Anti-Malware verze 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Media Go (HKLM-x32\...\{362AB21A-E2C4-40CE-81C2-8C4D62B0635A}) (Version: 2.4.256 - Sony)
Media Go Video Playback Engine 1.116.104.02020 (HKLM-x32\...\{54215B8A-6212-8DB8-39B4-98EE2BB98BD1}) (Version: 1.116.104.02020 - Sony)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Age of Empires II (HKLM-x32\...\Age of Empires 2.0) (Version: - )
Microsoft Age of Empires II: The Conquerors Expansion (HKLM-x32\...\Age of Empires II: The Conquerors Expansion 1.0) (Version: - )
Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 34.0.5 (x86 cs) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 cs)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
myBitCast 1.0.0.4 (HKLM\...\myBitCast) (Version: 1.0.0.4 - ASUS Cloud Corporation)
MyHeritage Family Tree Builder (HKLM-x32\...\Family Tree Builder) (Version: 7.0.0.7128 - MyHeritage.com)
Nokia Connectivity Cable Driver (HKLM-x32\...\{A57025CC-5F2E-4D01-B387-06DB10500D43}) (Version: 7.1.78.0 - Nokia)
Nokia PC Suite (HKLM-x32\...\Nokia PC Suite) (Version: 7.1.180.94 - Nokia)
Nokia PC Suite (x32 Version: 7.1.180.94 - Nokia) Hidden
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation)
PC Connectivity Solution (HKLM-x32\...\{644F4910-E812-49AD-93EC-86828CB81A0D}) (Version: 12.0.27.0 - Nokia)
Pharaoh (HKLM-x32\...\Pharaoh) (Version: - )
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Plants vs Zombies (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}) (Version: - Oberon Media)
PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.14.6.15183 - Sony Computer Entertainment Inc.)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
PokerStars.net (HKLM-x32\...\PokerStars.net) (Version: - PokerStars.net) <==== ATTENTION!
Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
rajče průvodce verze 1.59.48.263 (HKLM-x32\...\rajče.net_is1) (Version: - rajče.net)
Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}) (Version: 1.2.0.40 - Ralink)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6454 - Realtek Semiconductor Corp.)
Seznam Software (HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\SeznamInstall) (Version: - Seznam.cz)
Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys )
Sony Ericsson Update Engine (HKLM-x32\...\Update Engine) (Version: 2.13.6.201305161305 - Sony Ericsson Communications AB)
Sony PC Companion 2.10.206 (HKLM-x32\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.206 - Sony)
Spotify (HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Spotify) (Version: 0.9.13.24.g5dbb3103 - Spotify AB)
The KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: - )
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH)
Turbo Fiesta (HKLM-x32\...\{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}) (Version: - Oberon Media)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX kontrola za daljinske veze (HKLM-x32\...\{8985AE5E-622A-4980-8BF8-0A1830643220}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX vadīkla attālajiem savienojumiem (HKLM-x32\...\{A3A775C9-5A63-4C55-8FDD-427A5B8F5D2B}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-i juhtelement kaugühendustele (HKLM-x32\...\{216ACEC1-4556-4717-A8DE-3F7F5F9C6F63}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM-x32\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.1 - ASUS)
Wireless Console 3 (HKLM-x32\...\{19EA33FB-B34E-40EA-8B8A-61743AEB795A}) (Version: 3.0.32 - ASUS)
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
13-11-2014 15:10:37 Windows Update
18-11-2014 13:53:19 Windows Update
20-11-2014 15:53:38 Windows Update
25-11-2014 15:11:07 Windows Update
02-12-2014 18:11:21 Windows Update
06-12-2014 19:48:57 Windows Update
11-12-2014 16:39:58 Windows Update
11-12-2014 17:11:55 Windows Update
14-12-2014 10:59:15 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {0096EEE7-756E-48F7-BA44-4D698386714A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-03] (Google Inc.)
Task: {1A8474FA-6862-4966-95DB-D87C0B3BEEA4} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-05-15] (ASUS)
Task: {20EC82D1-A0D2-40D6-A35B-FB890B417F0C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-09] (Adobe Systems Incorporated)
Task: {2724D7B5-FE8C-46C7-BFE0-E2E65B2EF1D4} - System32\Tasks\Security Center Update - 4209252972 => C:\Users\Honza23\AppData\Roaming\Wyevzena\ceapro.exe <==== ATTENTION
Task: {2818EF84-13E5-4F6C-B7E5-735CAD0BB6B1} - System32\Tasks\{C52F011B-8983-4AB7-9013-50A878EC80A0} => C:\Users\Honza23\Downloads\Nokia_PC_Suite_ALL.exe [2013-05-23] ()
Task: {2A821617-A068-4B35-A773-80CE06B6AF9A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-06-03] (Google Inc.)
Task: {42062429-B81A-4233-A7B9-3FAD216385D3} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2012-09-27] ()
Task: {434F761C-9A6F-41B8-8073-C096168C0B83} - System32\Tasks\{19494ED3-405A-4563-9276-5DC6A3BAD89A} => C:\Users\Honza23\Downloads\Nokia_PC_Suite_ALL.exe [2013-05-23] ()
Task: {43BB3455-845F-41C6-83A4-19936A1FD065} - System32\Tasks\{D4109F31-A24F-48D8-9BF7-195929BE504C} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {464BD720-7D04-4F96-982A-4A45E5EA4322} - System32\Tasks\{1B964C43-BDC8-4CE6-B029-36A84C506C22} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {5583816C-8AD5-4B18-ABB7-021BD83E9114} - System32\Tasks\ASUS Wireless Console 3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-07-11] (ASUSTeK Computer Inc.)
Task: {595CF607-E84D-4563-889D-98A0237AEC91} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-26] (ASUSTek Computer Inc.)
Task: {62F6934B-B3C2-45CC-98F7-AE073B6D05B1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {6A5C8C15-A964-4ACE-8F68-CC4459C602AD} - System32\Tasks\{111349EA-DB34-460D-97C9-033316DF8DC4} => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-07-11] (ASUSTeK Computer Inc.)
Task: {7A4DFE23-3213-4082-A2F2-BA588E8EBAD5} - System32\Tasks\{83388A5B-6ADD-4697-93AF-DDDC7723EB0D} => pcalua.exe -a C:\windows\system32\pcwrun.exe -c "C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe"
Task: {7CFFD3A0-4EB2-42E8-A063-68A27BC97162} - System32\Tasks\{50848112-E467-4994-94B2-9141DBF125AD} => pcalua.exe -a C:\Users\Honza23\Downloads\Nokia_PC_Suite_ALL.exe -d C:\Users\Honza23\Downloads
Task: {7E285B64-0885-4878-9D49-37A3AFD37398} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-06-21] (ASUSTeK Computer Inc.)
Task: {7F0F5A1A-5528-4E01-AB18-D99AD71584C0} - System32\Tasks\{FDC82A4D-0583-4404-9D0F-83B4FA84B271} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {81B83B70-C236-49E5-B427-B13CF0EEE1BA} - System32\Tasks\{D4F7C290-60E9-4592-8CAC-9BF4BE16B187} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {8D08DD06-415A-4D14-9307-847537CBC604} - System32\Tasks\{075FCC47-23E3-4B64-976A-3D8A23CAB056} => pcalua.exe -a "E:\Filmy\Vlk z Wall Street\The Wolf of Wall Street 2013\WMP x264 Codec Pack.exe" -d "E:\Filmy\Vlk z Wall Street\The Wolf of Wall Street 2013"
Task: {9492046B-6840-4474-80C1-8C3BDE0705D4} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-24] (AVAST Software)
Task: {985D1402-81DB-4972-8CB7-81B54BF8D0BB} - System32\Tasks\{5F7BB92A-A13E-4E3F-AAC4-54C68ABB03F0} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {A35DBAA5-6DB7-4CEE-94C6-3E5055CC295B} - System32\Tasks\{83C4A4D3-14C4-4DA7-940B-41A87A95B7AE} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {C5B68A18-5D63-454B-B215-983DE7792AB8} - System32\Tasks\{B64216B4-14F2-485E-AE3C-6B75DE096E13} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {E580C377-879A-4880-A84A-26A95215BF6E} - System32\Tasks\{928F114D-7A82-4ADE-A7A3-2E6ACA7EE4B8} => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-07-11] (ASUSTeK Computer Inc.)
Task: {F0189561-A568-435E-898F-DE400F2ADDB4} - System32\Tasks\{66241A78-0513-45DA-ABA2-B53364604118} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: {F42BC3E7-7934-4CF2-97EB-1586ADD933B7} - System32\Tasks\{132F5DB5-9051-4531-B8EA-F6308BD31AAB} => pcalua.exe -a C:\Users\Honza23\Downloads\mozilla-firefox-lista-centrumcz.exe -d C:\Users\Honza23\Downloads
Task: {F704115B-F865-47D9-9724-27C12563A3C6} - System32\Tasks\{55E66DE4-D0E2-4D83-9254-129E44C375BC} => C:\Program Files (x86)\3G HSDPA Modem\3G HSDPA Modem.exe [2013-02-20] ()
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-12-08 16:37 - 2014-09-05 08:40 - 00138272 _____ () C:\ProgramData\HiSuiteOuc\HiSuiteOuc64.exe
2014-12-08 16:37 - 2014-09-05 08:40 - 00219680 _____ () C:\ProgramData\HandSetService\HuaweiHiSuiteService64.exe
2014-10-28 04:20 - 2014-12-15 14:39 - 00123672 _____ () C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2014-07-24 16:42 - 2014-07-24 16:42 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-12-15 14:31 - 2014-12-15 14:31 - 02908160 _____ () C:\Program Files\AVAST Software\Avast\defs\14121500\algo.dll
2012-06-07 23:12 - 2012-06-07 23:12 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2012-01-31 18:25 - 2012-01-31 18:25 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-20 18:57 - 2010-08-20 18:57 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2014-07-24 16:42 - 2014-07-24 16:42 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-12-09 16:13 - 2014-12-09 16:13 - 03758192 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-12-09 23:43 - 2014-12-09 23:43 - 16841392 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: mcui_exe => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
========================= Accounts: ==========================
Administrator (S-1-5-21-1544955830-4211015516-3942192515-500 - Administrator - Disabled)
Guest (S-1-5-21-1544955830-4211015516-3942192515-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1544955830-4211015516-3942192515-1002 - Limited - Enabled)
Honza23 (S-1-5-21-1544955830-4211015516-3942192515-1000 - Administrator - Enabled) => C:\Users\Honza23
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/14/2014 08:10:15 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: )
Description: Služba Šifrování neinicializovala databázi katalogu. Chyba součásti ESENT: -1305.
Error: (12/11/2014 06:11:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 34.0.5.5443, časové razítko: 0x5475dd5d
Název chybujícího modulu: mozalloc.dll, verze: 34.0.5.5443, časové razítko: 0x5475d664
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x6f8
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/11/2014 05:41:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 34.0.5.5443, časové razítko: 0x5475dd5d
Název chybujícího modulu: mozalloc.dll, verze: 34.0.5.5443, časové razítko: 0x5475d664
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x18e0
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/10/2014 07:00:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 34.0.5.5443, časové razítko: 0x5475dd5d
Název chybujícího modulu: mozalloc.dll, verze: 34.0.5.5443, časové razítko: 0x5475d664
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x66c
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/10/2014 07:00:22 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program firefox.exe verze 34.0.5.5443 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: 1e04
Čas spuštění: 01d0149f9f6537ea
Čas ukončení: 271
Cesta k aplikaci: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
ID hlášení: 57b73104-8096-11e4-84fe-50465ddb6ba6
Error: (12/07/2014 02:13:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 33.1.0.5423, časové razítko: 0x545c0a59
Název chybujícího modulu: mozalloc.dll, verze: 33.1.0.5423, časové razítko: 0x545be5ee
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x13b8
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/07/2014 02:13:38 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program firefox.exe verze 33.1.0.5423 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: ef4
Čas spuštění: 01d0118b70394e6c
Čas ukončení: 76
Cesta k aplikaci: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
ID hlášení: 407099f3-7dae-11e4-84fe-50465ddb6ba6
Error: (12/03/2014 06:31:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 33.1.0.5423, časové razítko: 0x545c0a59
Název chybujícího modulu: mozalloc.dll, verze: 33.1.0.5423, časové razítko: 0x545be5ee
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x14c0
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/02/2014 07:01:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 33.1.0.5423, časové razítko: 0x545c0a59
Název chybujícího modulu: mozalloc.dll, verze: 33.1.0.5423, časové razítko: 0x545be5ee
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x14ec
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (12/01/2014 07:35:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 33.1.0.5423, časové razítko: 0x545c0a59
Název chybujícího modulu: mozalloc.dll, verze: 33.1.0.5423, časové razítko: 0x545be5ee
Kód výjimky: 0x80000003
Posun chyby: 0x00001425
ID chybujícího procesu: 0x1158
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
System errors:
=============
Error: (12/15/2014 03:19:17 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
sptd
Error: (12/15/2014 03:18:35 PM) (Source: sptd) (EventID: 4) (User: )
Description: Ovladač zjistil interní chybu ve vlastní struktuře dat u .
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba MaintainerSvc2.69.9464532 byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Presentation Foundation Font Cache 3.0.0.0 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Management and Security Application User Notification Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Intel(R) Management and Security Application Local Management Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:55 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Live ID Sign-in Assistant byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.
Error: (12/15/2014 03:17:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Update Ttessab byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 5000 milisekund: Restartovat službu.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU B820 @ 1.70GHz
Percentage of memory in use: 32%
Total physical RAM: 6048.13 MB
Available physical RAM: 4074.27 MB
Total Pagefile: 12094.43 MB
Available Pagefile: 9859.5 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:111.93 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (DATA) (Fixed) (Total:254.36 GB) (Free:237.33 GB) NTFS
Drive f: (DIABLO) (CDROM) (Total:0.6 GB) (Free:0 GB) CDFS
Drive i: (Pharaoh) (CDROM) (Total:0.64 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 982AE9F6)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=100 MB) - (Type=27)
Partition 3: (Not Active) - (Size=186.3 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=254.4 GB) - (Type=07 NTFS)
==================== End Of Log ============================
Re: Asi tu mám hosta

- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu na Vas vyskoci fixlog (pripadne bude ulozen na Plose), jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation) HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [Yahoo! Search] => C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {2dc9cb8e-967e-11e3-867b-50465ddb6ba6} - I:\autorun.exe HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {3f99195e-c7a7-11e2-9436-50465ddb6ba6} - D:\Startme.exe HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bebe-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bec0-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {e52b6a48-51be-11e2-918a-806e6f6e6963} - F:\AUTORUN.EXE HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {f0ffce42-eb0b-11e2-94c0-50465ddb6ba6} - D:\setup.exe ShellIconOverlayIdentifiers: [1CryptoProviderIcons] -> {24808826-C2BF-4269-B3BA-89D1D5F431A4} => No File ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}& FF SearchEngineOrder.1: Seznam FF SelectedSearchEngine: Seznam FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}& FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Extension: Ttessab 1.0.1 - C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\Extensions\{b3226d6b-57d1-49c8-8124-68272ad024dd}.xpi [2014-12-11] FF Extension: No Name - wrc@avast.com [Not Found] CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fulltext_ff?phrase={searchTerms} CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File CHR Extension: (Ttessab) - C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default\Extensions\nanmbhilcdheddmaghbodjfpjbjabdhi [2014-11-24] R2 MaintainerSvc2.69.9464532; C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe [123672 2014-12-15] () S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X] S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X] C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c 2014-12-15 15:12 - 2014-12-15 15:12 - 02166272 _____ () C:\Users\Honza23\Desktop\adwcleaner_4.105.exe 2014-12-15 15:17 - 2014-03-10 18:12 - 00000000 ____D () C:\AdwCleaner 2014-12-15 14:38 - 2014-03-10 15:33 - 00000000 ____D () C:\Program Files\trend micro Task: {2724D7B5-FE8C-46C7-BFE0-E2E65B2EF1D4} - System32\Tasks\Security Center Update - 4209252972 => C:\Users\Honza23\AppData\Roaming\Wyevzena\ceapro.exe <==== ATTENTION Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe C:\Users\Honza23\AppData\Roaming\Wyevzena Folder: C:\Users\Honza23\AppData\Local\{812D870F-20C4-4DA8-8A15-D2BAF0532518} Hosts: EmptyTemp: End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Asi tu mám hosta
je to asi toto:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-12-2014 01
Ran by Honza23 at 2014-12-15 18:17:07 Run:1
Running from C:\Users\Honza23\Desktop
Loaded Profile: Honza23 (Available profiles: Honza23)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [Yahoo! Search] => C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {2dc9cb8e-967e-11e3-867b-50465ddb6ba6} - I:\autorun.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {3f99195e-c7a7-11e2-9436-50465ddb6ba6} - D:\Startme.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bebe-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bec0-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {e52b6a48-51be-11e2-918a-806e6f6e6963} - F:\AUTORUN.EXE
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {f0ffce42-eb0b-11e2-94c0-50465ddb6ba6} - D:\setup.exe
ShellIconOverlayIdentifiers: [1CryptoProviderIcons] -> {24808826-C2BF-4269-B3BA-89D1D5F431A4} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF SearchEngineOrder.1: Seznam
FF SelectedSearchEngine: Seznam
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Extension: Ttessab 1.0.1 - C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\Extensions\{b3226d6b-57d1-49c8-8124-68272ad024dd}.xpi [2014-12-11]
FF Extension: No Name - wrc@avast.com [Not Found]
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (Ttessab) - C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default\Extensions\nanmbhilcdheddmaghbodjfpjbjabdhi [2014-11-24]
R2 MaintainerSvc2.69.9464532; C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe [123672 2014-12-15] ()
S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X]
S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X]
C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c
2014-12-15 15:12 - 2014-12-15 15:12 - 02166272 _____ () C:\Users\Honza23\Desktop\adwcleaner_4.105.exe
2014-12-15 15:17 - 2014-03-10 18:12 - 00000000 ____D () C:\AdwCleaner
2014-12-15 14:38 - 2014-03-10 15:33 - 00000000 ____D () C:\Program Files\trend micro
Task: {2724D7B5-FE8C-46C7-BFE0-E2E65B2EF1D4} - System32\Tasks\Security Center Update - 4209252972 => C:\Users\Honza23\AppData\Roaming\Wyevzena\ceapro.exe <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Users\Honza23\AppData\Roaming\Wyevzena
Folder: C:\Users\Honza23\AppData\Local\{812D870F-20C4-4DA8-8A15-D2BAF0532518}
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully.
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Yahoo! Search => value deleted successfully.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2dc9cb8e-967e-11e3-867b-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{2dc9cb8e-967e-11e3-867b-50465ddb6ba6}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3f99195e-c7a7-11e2-9436-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{3f99195e-c7a7-11e2-9436-50465ddb6ba6}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8246bebe-da02-11e2-94a0-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{8246bebe-da02-11e2-94a0-50465ddb6ba6}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8246bec0-da02-11e2-94a0-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{8246bec0-da02-11e2-94a0-50465ddb6ba6}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e52b6a48-51be-11e2-918a-806e6f6e6963}" => Key deleted successfully.
"HKCR\CLSID\{e52b6a48-51be-11e2-918a-806e6f6e6963}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0ffce42-eb0b-11e2-94c0-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{f0ffce42-eb0b-11e2-94c0-50465ddb6ba6}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\1CryptoProviderIcons" => Key deleted successfully.
"HKCR\CLSID\{24808826-C2BF-4269-B3BA-89D1D5F431A4}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1" => Key deleted successfully.
"HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2" => Key deleted successfully.
"HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3" => Key deleted successfully.
"HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4" => Key deleted successfully.
"HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
C:\windows\system32\GroupPolicy\Machine => Moved successfully.
C:\windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
Firefox DefaultSearchUrl deleted successfully.
Firefox SearchEngineOrder.1 deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
Firefox Keyword.URL deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\Extensions\{b3226d6b-57d1-49c8-8124-68272ad024dd}.xpi => Moved successfully.
FF Extension: No Name - wrc@avast.com [Not Found] not found.
Chrome DefaultSuggestURL not detected.
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll not found.
C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll not found.
C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll not found.
C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll not found.
C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll not found.
c:\progra~2\mcafee\msc\npmcsn~1.dll not found.
C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default\Extensions\nanmbhilcdheddmaghbodjfpjbjabdhi => Moved successfully.
MaintainerSvc2.69.9464532 => Service deleted successfully.
NLNdisMP => Service deleted successfully.
NLNdisPT => Service deleted successfully.
C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c => Moved successfully.
C:\Users\Honza23\Desktop\adwcleaner_4.105.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2724D7B5-FE8C-46C7-BFE0-E2E65B2EF1D4}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2724D7B5-FE8C-46C7-BFE0-E2E65B2EF1D4}" => Key deleted successfully.
C:\Windows\System32\Tasks\Security Center Update - 4209252972 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 4209252972" => Key deleted successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Users\Honza23\AppData\Roaming\Wyevzena => Moved successfully.
========================= Folder: C:\Users\Honza23\AppData\Local\{812D870F-20C4-4DA8-8A15-D2BAF0532518} ========================
====== End of Folder: ======
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 83.7 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-12-2014 01
Ran by Honza23 at 2014-12-15 18:17:07 Run:1
Running from C:\Users\Honza23\Desktop
Loaded Profile: Honza23 (Available profiles: Honza23)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\Run: [Yahoo! Search] => C:\Users\Honza23\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {2dc9cb8e-967e-11e3-867b-50465ddb6ba6} - I:\autorun.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {3f99195e-c7a7-11e2-9436-50465ddb6ba6} - D:\Startme.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bebe-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {8246bec0-da02-11e2-94a0-50465ddb6ba6} - D:\setup.exe
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {e52b6a48-51be-11e2-918a-806e6f6e6963} - F:\AUTORUN.EXE
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\...\MountPoints2: {f0ffce42-eb0b-11e2-94c0-50465ddb6ba6} - D:\setup.exe
ShellIconOverlayIdentifiers: [1CryptoProviderIcons] -> {24808826-C2BF-4269-B3BA-89D1D5F431A4} => No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
FF DefaultSearchUrl: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF SearchEngineOrder.1: Seznam
FF SelectedSearchEngine: Seznam
FF Keyword.URL: hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}&
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Extension: Ttessab 1.0.1 - C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\Extensions\{b3226d6b-57d1-49c8-8124-68272ad024dd}.xpi [2014-12-11]
FF Extension: No Name - wrc@avast.com [Not Found]
CHR DefaultSuggestURL: Default -> http://suggest.fulltext.seznam.cz/fullt ... earchTerms}
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Shockwave Flash) - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (Ttessab) - C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default\Extensions\nanmbhilcdheddmaghbodjfpjbjabdhi [2014-11-24]
R2 MaintainerSvc2.69.9464532; C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c\maintainer.exe [123672 2014-12-15] ()
S3 NLNdisMP; system32\DRIVERS\nlndis.sys [X]
S3 NLNdisPT; system32\DRIVERS\nlndis.sys [X]
C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c
2014-12-15 15:12 - 2014-12-15 15:12 - 02166272 _____ () C:\Users\Honza23\Desktop\adwcleaner_4.105.exe
2014-12-15 15:17 - 2014-03-10 18:12 - 00000000 ____D () C:\AdwCleaner
2014-12-15 14:38 - 2014-03-10 15:33 - 00000000 ____D () C:\Program Files\trend micro
Task: {2724D7B5-FE8C-46C7-BFE0-E2E65B2EF1D4} - System32\Tasks\Security Center Update - 4209252972 => C:\Users\Honza23\AppData\Roaming\Wyevzena\ceapro.exe <==== ATTENTION
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Users\Honza23\AppData\Roaming\Wyevzena
Folder: C:\Users\Honza23\AppData\Local\{812D870F-20C4-4DA8-8A15-D2BAF0532518}
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value deleted successfully.
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Yahoo! Search => value deleted successfully.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2dc9cb8e-967e-11e3-867b-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{2dc9cb8e-967e-11e3-867b-50465ddb6ba6}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3f99195e-c7a7-11e2-9436-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{3f99195e-c7a7-11e2-9436-50465ddb6ba6}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8246bebe-da02-11e2-94a0-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{8246bebe-da02-11e2-94a0-50465ddb6ba6}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8246bec0-da02-11e2-94a0-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{8246bec0-da02-11e2-94a0-50465ddb6ba6}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e52b6a48-51be-11e2-918a-806e6f6e6963}" => Key deleted successfully.
"HKCR\CLSID\{e52b6a48-51be-11e2-918a-806e6f6e6963}" => Key not found.
"HKU\S-1-5-21-1544955830-4211015516-3942192515-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0ffce42-eb0b-11e2-94c0-50465ddb6ba6}" => Key deleted successfully.
"HKCR\CLSID\{f0ffce42-eb0b-11e2-94c0-50465ddb6ba6}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\1CryptoProviderIcons" => Key deleted successfully.
"HKCR\CLSID\{24808826-C2BF-4269-B3BA-89D1D5F431A4}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt1" => Key deleted successfully.
"HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt2" => Key deleted successfully.
"HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt3" => Key deleted successfully.
"HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\DropboxExt4" => Key deleted successfully.
"HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" => Key not found.
C:\windows\system32\GroupPolicy\Machine => Moved successfully.
C:\windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
Firefox DefaultSearchUrl deleted successfully.
Firefox SearchEngineOrder.1 deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
Firefox Keyword.URL deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
C:\Users\Honza23\AppData\Roaming\Mozilla\Firefox\Profiles\giqmo9xt.default\Extensions\{b3226d6b-57d1-49c8-8124-68272ad024dd}.xpi => Moved successfully.
FF Extension: No Name - wrc@avast.com [Not Found] not found.
Chrome DefaultSuggestURL not detected.
C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll not found.
C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll not found.
C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll not found.
C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll not found.
C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll not found.
c:\progra~2\mcafee\msc\npmcsn~1.dll not found.
C:\Users\Honza23\AppData\Local\Google\Chrome\User Data\Default\Extensions\nanmbhilcdheddmaghbodjfpjbjabdhi => Moved successfully.
MaintainerSvc2.69.9464532 => Service deleted successfully.
NLNdisMP => Service deleted successfully.
NLNdisPT => Service deleted successfully.
C:\ProgramData\843b4758-3acb-424f-b9d5-728e4257d28c => Moved successfully.
C:\Users\Honza23\Desktop\adwcleaner_4.105.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2724D7B5-FE8C-46C7-BFE0-E2E65B2EF1D4}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2724D7B5-FE8C-46C7-BFE0-E2E65B2EF1D4}" => Key deleted successfully.
C:\Windows\System32\Tasks\Security Center Update - 4209252972 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Security Center Update - 4209252972" => Key deleted successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Users\Honza23\AppData\Roaming\Wyevzena => Moved successfully.
========================= Folder: C:\Users\Honza23\AppData\Local\{812D870F-20C4-4DA8-8A15-D2BAF0532518} ========================
====== End of Folder: ======
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 83.7 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: Asi tu mám hosta
Takze jeste uklidime.
- Stahnete a spustte DelFix - https://toolslib.net/downloads/viewdownload/2-delfix/
- Oznacte jen moznost "Remove disinfection tools"
- kliknete na Run
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Asi tu mám hosta
Je to vše, moc děkuji za rady - super
Re: Asi tu mám hosta
Nemate zac, rad jsem pomohl 
Preju Vam prijemny vecer... mejte se a treba zase nekdy

Preju Vam prijemny vecer... mejte se a treba zase nekdy

Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.