nevyžádané pop-up okna

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
TIVL
Návštěvník
Návštěvník
Příspěvky: 97
Registrován: 20 Led 2007 20:20
Kontaktovat uživatele:

nevyžádané pop-up okna

#1 Příspěvek od TIVL »

Zdravim,
na NB vyskakují neustále pop-up okna s reklamami, našel jsem program "pay-by-ads"(nedopatřením instalovaný) - ten jsem smazal, registry také.
Pop-up okna se ukazují i po použití adwcleaneru, byla snaha pročistit hdd programem glary utilities.
Řešení neuspěšné, proto se vracím pro pomoc.

Děkuji za odpověď.

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: nevyžádané pop-up okna

#2 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TIVL
Návštěvník
Návštěvník
Příspěvky: 97
Registrován: 20 Led 2007 20:20
Kontaktovat uživatele:

Re: nevyžádané pop-up okna

#3 Příspěvek od TIVL »

zde je log z FRST:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-12-2014
Ran by Honza (administrator) on JANA on 20-12-2014 20:13:01
Running from C:\Users\Honza\Downloads
Loaded Profile: Honza (Available profiles: Honza)
Platform: Windows 8.1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\ProgramData\0ff72d80-af9b-4907-86eb-cf468c2dfc75\maintainer.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
() C:\Program Files (x86)\EnhanceEmpire\bin\utilEnhanceEmpire.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\Integrator.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Bytemobile, Inc.) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\bmctl.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\EnhanceEmpire\bin\EnhanceEmpire.PurBrowse64.exe
() C:\Program Files (x86)\EnhanceEmpire\bin\EnhanceEmpire.expext.exe
() C:\Program Files (x86)\EnhanceEmpire\bin\EnhanceEmpire.BrowserAdapter.exe
() C:\Program Files (x86)\EnhanceEmpire\bin\EnhanceEmpire.BrowserAdapter64.exe
() C:\Program Files (x86)\EnhanceEmpire\updateEnhanceEmpire.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2014-02-10] (IDT, Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285832 2013-11-10] (Intel Corporation)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-24] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => c:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2012-08-31] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => c:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe [167024 2012-08-31] (CyberLink Corp.)
HKLM-x32\...\Run: [BtTray] => C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [371976 2012-09-19] (IVT Corporation)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [683656 2013-06-05] (PDF Complete Inc)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [337184 2013-10-16] (Hewlett-Packard Company)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [RemoveNetSoftware] => C:\Program Files\NetSoftware\\rmNetSoftware.exe [1186800 2014-02-10] (Gemius)
HKLM-x32\...\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [252928 2010-04-28] (Vodafone)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-12-02] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-12-08] (Glarysoft Ltd)
BootExecute: autocheck autochk *

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.seznam.cz
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seznam.cz
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.seznam.cz
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seznam.cz
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-21-3949523431-268354437-2035300158-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKU\S-1-5-21-3949523431-268354437-2035300158-1002 -> {9D324E57-F2BE-40BD-B401-DEB97203BE11} URL = http://rts.dsrlte.com/?affID=na&q={searchTerms}&r=298
BHO-x32: EnhanceEmpire 1.0.0.6 -> {e39519a5-9d10-478c-98d8-9c486f3190a4} -> C:\Program Files (x86)\EnhanceEmpire\EnhanceEmpireBHO.dll (EnhanceEmpire)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{E161744B-45CA-405F-9125-2943A35B6173}: [NameServer] 217.77.161.134,217.77.165.81

FireFox:
========
FF ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default
FF NewTab:
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SelectedSearchEngine: Yahoo! Search
FF Homepage: https://www.seznam.cz/
FF Keyword.URL:
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default\searchplugins\dsrlte.xml
FF Extension: EnhanceEmpire 1.0.1 - C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default\Extensions\{3655ec02-5936-4d49-865a-01a969dc2792}.xpi [2014-11-27]
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon
FF Extension: Bytemobile Optimization Client - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon [2014-08-31]

Chrome:
=======
CHR Profile: C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-16]
CHR Extension: (Disk Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-16]
CHR Extension: (YouTube) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-16]
CHR Extension: (Vyhledávání Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-16]
CHR Extension: (Peněženka Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-05]
CHR Extension: (Gmail) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1612552 2012-09-26] (IVT Corporation)
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [146184 2012-09-19] (IVT Corporation)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [85504 2012-08-15] (Hewlett-Packard Company) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [681760 2013-10-16] (Hewlett-Packard Company)
R3 hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [1006424 2013-01-23] (Hewlett-Packard Company) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131032 2013-11-10] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-11-10] (Intel Corporation)
R2 MaintainerSvc4.20.6197480; C:\ProgramData\0ff72d80-af9b-4907-86eb-cf468c2dfc75\maintainer.exe [123688 2014-12-20] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1143432 2013-06-05] (PDF Complete Inc)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2014-02-10] (IDT, Inc.) [File not signed]
R2 Update EnhanceEmpire; C:\Program Files (x86)\EnhanceEmpire\updateEnhanceEmpire.exe [519464 2014-12-20] ()
R2 Util EnhanceEmpire; C:\Program Files (x86)\EnhanceEmpire\bin\utilEnhanceEmpire.exe [519464 2014-12-20] ()
R2 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [9216 2010-04-28] (Vodafone) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 adusbser; C:\Windows\system32\DRIVERS\adusbser.sys [123392 2010-12-20] (QUALCOMM Incorporated)
R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2014-08-31] (Bytemobile, Inc.) [File not signed]
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
U4 BthAvrcpTg; No ImagePath
U4 BthHFEnum; No ImagePath
U4 bthhfhid; No ImagePath
R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48608 2012-10-02] (Ralink Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 FcSerial; C:\Windows\system32\DRIVERS\FcSerial.sys [221568 2013-01-30] (Flash Card.)
S3 ggqldxnl; C:\Windows\System32\Drivers\ggqldxnl.sys [423240 2014-04-27] (AVAST Software)
R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [20160 2014-12-20] (Glarysoft Ltd)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-02] (Ralink Technology, Corp.)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-15] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-15] (Synaptics Incorporated)
R3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [1866080 2012-11-20] ()
R1 tcpipBM; C:\WINDOWS\system32\drivers\tcpipBM.sys [39552 2014-08-31] (Bytemobile, Inc.) [File not signed]
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
R3 wmbclass; C:\Windows\system32\DRIVERS\wmbclass.sys [268288 2013-11-01] (Microsoft Corporation)
R1 {0caa56ce-9994-49e8-960b-5cce0891ad1e}Gw64; C:\Windows\System32\drivers\{0caa56ce-9994-49e8-960b-5cce0891ad1e}Gw64.sys [48840 2014-11-07] (StdLib)
R1 {1bc4eab7-7c96-47df-8ff8-f8a5e54aaead}Gw64; C:\Windows\System32\drivers\{1bc4eab7-7c96-47df-8ff8-f8a5e54aaead}Gw64.sys [48840 2014-11-22] (StdLib)
R1 {3655ec02-5936-4d49-865a-01a969dc2792}Gw64; C:\Windows\System32\drivers\{3655ec02-5936-4d49-865a-01a969dc2792}Gw64.sys [48840 2014-11-26] (StdLib)
R1 {42f92479-605e-4068-bbe7-dd390341c759}Gw64; C:\Windows\System32\drivers\{42f92479-605e-4068-bbe7-dd390341c759}Gw64.sys [48840 2014-11-30] (StdLib)
R1 {5a159ab2-27b5-487a-b9ab-bbd404fff160}Gw64; C:\Windows\System32\drivers\{5a159ab2-27b5-487a-b9ab-bbd404fff160}Gw64.sys [48840 2014-11-28] (StdLib)
R1 {5d0c6ce3-24e2-42ca-be13-3acdb0c018fe}Gw64; C:\Windows\System32\drivers\{5d0c6ce3-24e2-42ca-be13-3acdb0c018fe}Gw64.sys [48840 2014-12-15] (StdLib)
R1 {7271984b-2173-40a5-b785-07b6fd570c17}Gw64; C:\Windows\System32\drivers\{7271984b-2173-40a5-b785-07b6fd570c17}Gw64.sys [48840 2014-11-18] (StdLib)
R1 {77ab2b23-fd73-4698-a7ef-7e28b53de1b8}Gw64; C:\Windows\System32\drivers\{77ab2b23-fd73-4698-a7ef-7e28b53de1b8}Gw64.sys [48840 2014-12-12] (StdLib)
R1 {8b0b721a-e2cb-4be2-8e77-0477d5b81db9}Gw64; C:\Windows\System32\drivers\{8b0b721a-e2cb-4be2-8e77-0477d5b81db9}Gw64.sys [48840 2014-11-17] (StdLib)
R1 {8b14f607-2d75-4286-8c41-805eb6993e17}Gw64; C:\Windows\System32\drivers\{8b14f607-2d75-4286-8c41-805eb6993e17}Gw64.sys [48840 2014-12-04] (StdLib)
R1 {920c46be-03fd-48e2-8d53-597a7ee47ada}Gw64; C:\Windows\System32\drivers\{920c46be-03fd-48e2-8d53-597a7ee47ada}Gw64.sys [48840 2014-12-06] (StdLib)
R1 {b407786c-81cc-49c6-a3bd-77314482151d}Gw64; C:\Windows\System32\drivers\{b407786c-81cc-49c6-a3bd-77314482151d}Gw64.sys [48840 2014-11-04] (StdLib)
R1 {c0f74fd9-1792-427c-8ed9-9eb06bfa155f}Gw64; C:\Windows\System32\drivers\{c0f74fd9-1792-427c-8ed9-9eb06bfa155f}Gw64.sys [48840 2014-12-19] (StdLib)
R1 {c2673602-7cef-4cff-8325-083e5a1c07de}Gw64; C:\Windows\System32\drivers\{c2673602-7cef-4cff-8325-083e5a1c07de}Gw64.sys [48840 2014-11-12] (StdLib)
R1 {d04a85b1-9940-4f02-bcf9-cccce4ad86db}Gw64; C:\Windows\System32\drivers\{d04a85b1-9940-4f02-bcf9-cccce4ad86db}Gw64.sys [48840 2014-12-09] (StdLib)
R1 {d7f1efb4-b1fb-4135-aecb-cd6ad3ef2746}Gw64; C:\Windows\System32\drivers\{d7f1efb4-b1fb-4135-aecb-cd6ad3ef2746}Gw64.sys [48840 2014-11-25] (StdLib)
R1 {d8aa22df-f67e-4355-957a-3caa033aac2b}Gw64; C:\Windows\System32\drivers\{d8aa22df-f67e-4355-957a-3caa033aac2b}Gw64.sys [48840 2014-11-29] (StdLib)
R1 {e73998c3-bf7c-42fc-9cf2-00fca17934a8}Gw64; C:\Windows\System32\drivers\{e73998c3-bf7c-42fc-9cf2-00fca17934a8}Gw64.sys [48840 2014-11-10] (StdLib)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-20 19:30 - 2014-12-20 19:31 - 07699024 _____ (TeamViewer GmbH) C:\Users\Honza\Downloads\TeamViewer_Setup_cs.exe
2014-12-20 19:18 - 2014-12-20 19:18 - 00000039 _____ () C:\WINDOWS\setupact.log
2014-12-20 19:18 - 2014-12-20 19:18 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-12-20 19:12 - 2014-12-20 19:12 - 00000782 _____ () C:\WINDOWS\PFRO.log
2014-12-20 18:52 - 2014-12-20 18:52 - 00000000 ____D () C:\ProgramData\GlarySoft
2014-12-20 18:36 - 2014-12-20 19:14 - 00000338 _____ () C:\WINDOWS\Tasks\GlaryInitialize 5.job
2014-12-20 18:36 - 2014-12-20 18:36 - 00020160 _____ (Glarysoft Ltd) C:\WINDOWS\system32\Drivers\GUBootStartup.sys
2014-12-20 18:36 - 2014-12-20 18:36 - 00002964 _____ () C:\WINDOWS\System32\Tasks\GU5SkipUAC
2014-12-20 18:36 - 2014-12-20 18:36 - 00002606 _____ () C:\WINDOWS\System32\Tasks\GlaryInitialize 5
2014-12-20 18:36 - 2014-12-20 18:36 - 00001106 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\GlarySoft
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\DiskDefrag
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 5
2014-12-20 18:19 - 2014-12-20 18:19 - 00001144 _____ () C:\Users\Honza\Desktop\Live PC Help.lnk
2014-12-20 17:58 - 2014-12-20 17:58 - 00000000 ____D () C:\Users\Honza\AppData\Local\Evernote
2014-12-19 18:44 - 2014-12-19 05:52 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{c0f74fd9-1792-427c-8ed9-9eb06bfa155f}Gw64.sys
2014-12-17 16:13 - 2014-12-17 16:13 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2014-12-17 15:43 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-12-17 15:43 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-12-17 15:43 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-12-17 15:43 - 2014-11-22 03:49 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-12-17 15:43 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-12-17 15:43 - 2014-11-22 03:35 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-12-17 15:43 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-12-17 15:43 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-12-17 15:43 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-12-17 15:43 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-12-17 15:43 - 2014-11-22 03:06 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2014-12-17 15:43 - 2014-11-22 03:06 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-12-17 15:43 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-12-17 15:43 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-12-17 15:43 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-12-17 15:43 - 2014-11-22 02:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2014-12-17 15:43 - 2014-11-22 02:55 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-12-17 15:43 - 2014-11-22 02:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2014-12-17 15:43 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-12-17 15:43 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-12-17 15:43 - 2014-11-22 02:49 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-12-17 15:43 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-12-17 15:43 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-12-17 15:43 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-12-17 15:43 - 2014-11-22 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2014-12-17 15:43 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-12-17 15:43 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-12-17 15:43 - 2014-11-22 02:29 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2014-12-17 15:43 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-12-17 15:43 - 2014-11-22 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2014-12-17 15:43 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-12-17 15:43 - 2014-11-22 02:23 - 00326656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-12-17 15:43 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-12-17 15:43 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-12-17 15:43 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-12-17 15:43 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-12-17 15:43 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-12-17 15:43 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-12-17 15:43 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-12-17 15:42 - 2014-12-04 00:37 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-12-17 15:42 - 2014-12-04 00:09 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 01083392 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 00740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 00396288 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2014-12-17 15:41 - 2014-11-07 05:16 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2014-12-17 15:41 - 2014-11-07 04:26 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2014-12-17 15:41 - 2014-11-01 00:57 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-12-17 15:41 - 2014-11-01 00:47 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2014-12-17 15:41 - 2014-10-31 00:39 - 01970432 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2014-12-17 15:41 - 2014-10-31 00:38 - 01612992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2014-12-17 15:10 - 2014-11-10 03:29 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupStatusProvider.dll
2014-12-17 15:10 - 2014-11-10 02:51 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceSetupStatusProvider.dll
2014-12-17 15:10 - 2014-10-13 03:43 - 00238912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2014-12-17 15:10 - 2014-10-13 03:43 - 00153920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2014-12-17 15:10 - 2014-10-13 03:43 - 00086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2014-12-17 15:10 - 2014-10-13 03:43 - 00039744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2014-12-16 16:24 - 2014-12-15 23:53 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{5d0c6ce3-24e2-42ca-be13-3acdb0c018fe}Gw64.sys
2014-12-13 06:36 - 2014-12-12 17:56 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{77ab2b23-fd73-4698-a7ef-7e28b53de1b8}Gw64.sys
2014-12-09 21:47 - 2014-12-09 21:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-09 21:29 - 2014-12-09 11:52 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{d04a85b1-9940-4f02-bcf9-cccce4ad86db}Gw64.sys
2014-12-07 07:22 - 2014-12-06 18:48 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{920c46be-03fd-48e2-8d53-597a7ee47ada}Gw64.sys
2014-12-05 11:29 - 2014-12-04 13:55 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{8b14f607-2d75-4286-8c41-805eb6993e17}Gw64.sys
2014-12-01 06:01 - 2014-11-30 12:47 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{42f92479-605e-4068-bbe7-dd390341c759}Gw64.sys
2014-11-30 15:51 - 2014-11-29 23:47 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{d8aa22df-f67e-4355-957a-3caa033aac2b}Gw64.sys
2014-11-28 20:35 - 2014-11-28 08:46 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{5a159ab2-27b5-487a-b9ab-bbd404fff160}Gw64.sys
2014-11-27 14:49 - 2014-11-26 23:45 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{3655ec02-5936-4d49-865a-01a969dc2792}Gw64.sys
2014-11-25 22:13 - 2014-11-25 11:29 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{d7f1efb4-b1fb-4135-aecb-cd6ad3ef2746}Gw64.sys
2014-11-22 16:47 - 2014-11-22 05:31 - 00048840 _____ (StdLib) C:\WINDOWS\system32\Drivers\{1bc4eab7-7c96-47df-8ff8-f8a5e54aaead}Gw64.sys

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-20 20:13 - 2014-11-04 16:43 - 00000000 ____D () C:\ProgramData\0ff72d80-af9b-4907-86eb-cf468c2dfc75
2014-12-20 20:13 - 2014-04-21 08:11 - 00019252 _____ () C:\Users\Honza\Downloads\FRST.txt
2014-12-20 20:13 - 2014-03-16 15:35 - 00000000 ____D () C:\FRST
2014-12-20 20:11 - 2014-07-06 19:18 - 00000000 ____D () C:\Users\Honza\Downloads\FRST-OlderVersion
2014-12-20 20:11 - 2014-04-21 08:10 - 02122240 _____ (Farbar) C:\Users\Honza\Downloads\FRST64.exe
2014-12-20 20:07 - 2014-09-04 15:49 - 00000000 ____D () C:\Program Files (x86)\EnhanceEmpire
2014-12-20 20:04 - 2013-12-30 07:14 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Skype
2014-12-20 20:01 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-12-20 20:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-12-20 19:51 - 2014-08-31 11:39 - 01126815 _____ () C:\WINDOWS\WindowsUpdate.log
2014-12-20 19:41 - 2013-11-07 19:20 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-12-20 19:18 - 2013-11-14 13:40 - 01938474 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-20 19:18 - 2013-11-14 13:24 - 00803244 _____ () C:\WINDOWS\system32\perfh005.dat
2014-12-20 19:18 - 2013-11-14 13:24 - 00184236 _____ () C:\WINDOWS\system32\perfc005.dat
2014-12-20 19:18 - 2013-08-22 14:25 - 00000194 _____ () C:\WINDOWS\win.ini
2014-12-20 19:17 - 2012-09-26 09:53 - 00000950 _____ () C:\WINDOWS\SysWOW64\bscs.ini
2014-12-20 19:14 - 2013-11-10 16:56 - 00003620 _____ () C:\WINDOWS\SysWOW64\LOCALSERVICE.INI
2014-12-20 19:14 - 2013-11-10 16:56 - 00000043 _____ () C:\WINDOWS\SysWOW64\LOCALDEVICE.INI
2014-12-20 19:12 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-12-20 19:12 - 2012-11-22 04:49 - 00000000 ____D () C:\ProgramData\PDFC
2014-12-20 19:11 - 2014-03-16 14:47 - 00000000 ____D () C:\AdwCleaner
2014-12-20 18:50 - 2013-10-24 02:35 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3949523431-268354437-2035300158-1002
2014-12-20 18:41 - 2012-11-22 04:47 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-12-20 18:20 - 2014-08-31 13:35 - 00000000 ____D () C:\ProgramData\Vodafone
2014-12-20 18:04 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-12-20 18:02 - 2014-01-14 18:33 - 00000000 ____D () C:\Program Files (x86)\MyHeritage
2014-12-20 18:02 - 2013-12-30 07:14 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-20 18:02 - 2013-11-10 20:01 - 00003156 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForHonza
2014-12-20 18:02 - 2013-11-10 20:01 - 00000342 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForHonza.job
2014-12-20 18:00 - 2012-11-22 04:49 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2014-12-20 14:39 - 2014-01-14 14:59 - 00003954 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{DA3C9BDD-9D8C-42BC-851D-E81AC4AAD560}
2014-12-17 16:15 - 2013-11-03 11:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-17 16:13 - 2014-07-12 06:03 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-12-17 16:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-RS
2014-12-17 16:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-CS
2014-12-17 16:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-12-17 15:48 - 2013-11-04 17:52 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-12-17 15:46 - 2013-11-04 17:52 - 112710672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-12-17 11:24 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-12-15 06:46 - 2013-11-09 11:53 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log
2014-12-15 06:45 - 2013-11-10 14:25 - 00000000 _____ () C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-12-09 21:43 - 2013-11-07 19:20 - 00003802 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-11-20 21:51 - 2014-05-19 17:26 - 00714208 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-11-20 21:51 - 2014-05-19 17:26 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-20 06:27 - 2013-08-22 15:44 - 00346768 _____ () C:\WINDOWS\system32\FNTCACHE.DAT

Some content of TEMP:
====================
C:\Users\Honza\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-20 19:42

==================== End Of Log ============================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: nevyžádané pop-up okna

#4 Příspěvek od vyosek »

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Po spusteni probehne stazeni databaze
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TIVL
Návštěvník
Návštěvník
Příspěvky: 97
Registrován: 20 Led 2007 20:20
Kontaktovat uživatele:

Re: nevyžádané pop-up okna

#5 Příspěvek od TIVL »

log z adw

# AdwCleaner v4.105 - Report created 20/12/2014 at 20:52:25
# Updated 08/12/2014 by Xplode
# Database : 2014-12-16.1 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : Honza - JANA
# Running from : C:\Users\Honza\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : Update EnhanceEmpire
[#] Service Deleted : Util EnhanceEmpire
Service Deleted : {0caa56ce-9994-49e8-960b-5cce0891ad1e}Gw64
Service Deleted : {1bc4eab7-7c96-47df-8ff8-f8a5e54aaead}Gw64
Service Deleted : {3655ec02-5936-4d49-865a-01a969dc2792}Gw64
Service Deleted : {42f92479-605e-4068-bbe7-dd390341c759}Gw64
Service Deleted : {5a159ab2-27b5-487a-b9ab-bbd404fff160}Gw64
Service Deleted : {5d0c6ce3-24e2-42ca-be13-3acdb0c018fe}Gw64
Service Deleted : {7271984b-2173-40a5-b785-07b6fd570c17}Gw64
Service Deleted : {77ab2b23-fd73-4698-a7ef-7e28b53de1b8}Gw64
Service Deleted : {8b0b721a-e2cb-4be2-8e77-0477d5b81db9}Gw64
Service Deleted : {8b14f607-2d75-4286-8c41-805eb6993e17}Gw64
Service Deleted : {920c46be-03fd-48e2-8d53-597a7ee47ada}Gw64
Service Deleted : {b407786c-81cc-49c6-a3bd-77314482151d}Gw64
Service Deleted : {c0f74fd9-1792-427c-8ed9-9eb06bfa155f}Gw64
Service Deleted : {c2673602-7cef-4cff-8325-083e5a1c07de}Gw64
Service Deleted : {d04a85b1-9940-4f02-bcf9-cccce4ad86db}Gw64
Service Deleted : {d7f1efb4-b1fb-4135-aecb-cd6ad3ef2746}Gw64
Service Deleted : {d8aa22df-f67e-4355-957a-3caa033aac2b}Gw64
Service Deleted : {e73998c3-bf7c-42fc-9cf2-00fca17934a8}Gw64

***** [ Files / Folders ] *****

[!] Folder Deleted : C:\Program Files (x86)\EnhanceEmpire
Folder Deleted : C:\Users\Honza\AppData\Local\pay-by-ads
File Deleted : C:\WINDOWS\System32\roboot64.exe
File Deleted : C:\WINDOWS\System32\drivers\{0caa56ce-9994-49e8-960b-5cce0891ad1e}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{1bc4eab7-7c96-47df-8ff8-f8a5e54aaead}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{3655ec02-5936-4d49-865a-01a969dc2792}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{42f92479-605e-4068-bbe7-dd390341c759}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{5a159ab2-27b5-487a-b9ab-bbd404fff160}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{5d0c6ce3-24e2-42ca-be13-3acdb0c018fe}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{7271984b-2173-40a5-b785-07b6fd570c17}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{77ab2b23-fd73-4698-a7ef-7e28b53de1b8}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{8b0b721a-e2cb-4be2-8e77-0477d5b81db9}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{8b14f607-2d75-4286-8c41-805eb6993e17}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{920c46be-03fd-48e2-8d53-597a7ee47ada}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{b407786c-81cc-49c6-a3bd-77314482151d}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{c0f74fd9-1792-427c-8ed9-9eb06bfa155f}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{c2673602-7cef-4cff-8325-083e5a1c07de}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{d04a85b1-9940-4f02-bcf9-cccce4ad86db}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{d7f1efb4-b1fb-4135-aecb-cd6ad3ef2746}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{d8aa22df-f67e-4355-957a-3caa033aac2b}Gw64.sys
File Deleted : C:\WINDOWS\System32\drivers\{e73998c3-bf7c-42fc-9cf2-00fca17934a8}Gw64.sys
File Deleted : C:\Users\Honza\Desktop\Live PC Help.lnk
File Deleted : C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default\searchplugins\dsrlte.xml

***** [ Scheduled Tasks ] *****

Task Deleted : PC SpeedUp Service Deactivator

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update EnhanceEmpire
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util EnhanceEmpire
Key Deleted : HKEY_USERS\.DEFAULT\Software\Microsoft\.NETFramework\SQM\Apps\updateEnhanceEmpire.exe
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{e39519a5-9d10-478c-98d8-9c486f3190a4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{375D4D68-E576-449F-B588-A1E17C29F32D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{046f59b8-3ab5-445c-b397-b7cff9a1b2a3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e39519a5-9d10-478c-98d8-9c486f3190a4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{e39519a5-9d10-478c-98d8-9c486f3190a4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{AA760BA8-5862-4BC5-9263-4452CBC0B264}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{375D4D68-E576-449F-B588-A1E17C29F32D}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9D324E57-F2BE-40BD-B401-DEB97203BE11}
Key Deleted : HKCU\Software\EnhanceEmpire
Key Deleted : HKLM\SOFTWARE\EnhanceEmpire
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EnhanceEmpire

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Mozilla Firefox v34.0.5 (x86 cs)


-\\ Google Chrome v39.0.2171.95


*************************

AdwCleaner[R0].txt - [1711 octets] - [16/03/2014 14:47:29]
AdwCleaner[R1].txt - [1891 octets] - [27/04/2014 09:55:50]
AdwCleaner[R2].txt - [9293 octets] - [22/08/2014 19:32:14]
AdwCleaner[R3].txt - [1655 octets] - [31/08/2014 10:58:51]
AdwCleaner[R4].txt - [2531 octets] - [20/12/2014 19:09:23]
AdwCleaner[R5].txt - [7595 octets] - [20/12/2014 20:49:29]
AdwCleaner[S0].txt - [1792 octets] - [16/03/2014 14:50:36]
AdwCleaner[S1].txt - [8579 octets] - [22/08/2014 19:33:01]
AdwCleaner[S2].txt - [1550 octets] - [31/08/2014 11:37:44]
AdwCleaner[S3].txt - [2543 octets] - [20/12/2014 19:11:25]
AdwCleaner[S4].txt - [7234 octets] - [20/12/2014 20:52:25]

########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [7294 octets] ##########

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: nevyžádané pop-up okna

#6 Příspěvek od vyosek »

Pokracujte Zoek-em
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TIVL
Návštěvník
Návštěvník
Příspěvky: 97
Registrován: 20 Led 2007 20:20
Kontaktovat uživatele:

Re: nevyžádané pop-up okna

#7 Příspěvek od TIVL »

log ze zoek:


Zoek.exe v5.0.0.0 Updated 20-December-2014
Tool run by Honza on so 20. 12. 2014 at 21:24:56,86.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Honza\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

20. 12. 2014 21:25:50 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\MyHeritage deleted successfully
C:\PROGRA~2\COMMON~1\InstallShield deleted successfully
C:\PROGRA~3\Validity deleted successfully
C:\Users\Honza\AppData\Roaming\DiskDefrag deleted successfully
C:\Users\Honza\AppData\Roaming\Nico Mak Computing deleted successfully
C:\Users\Honza\AppData\Local\Adobe deleted successfully
C:\Users\Honza\AppData\Local\HP Quick Start deleted successfully
C:\Users\Honza\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3949523431-268354437-2035300158-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-3949523431-268354437-2035300158-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MaintainerSvc4.20.6197480 deleted successfully

==== FireFox Fix ======================

Deleted from C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.selectedEngine", "Yahoo! Search");
user_pref("keyword.URL", "");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default

user.js not found
---- Lines AtuZi removed from prefs.js ----
user_pref("extensions.AtuZi.asul", "1409487701306");
user_pref("extensions.AtuZi.aul", "1409286909153");
user_pref("extensions.AtuZi.irl", true);
user_pref("extensions.AtuZi.is", "cbslugp8");
user_pref("extensions.AtuZi.ug", "D1844D14-879C-4B33-A08C-18DF8ED4D82D");
---- Lines EnhanceEmpire removed from prefs.js ----
user_pref("extensions.EnhanceEmpire.asul", "1419082674004");
user_pref("extensions.EnhanceEmpire.aul", "1419082618307");
user_pref("extensions.EnhanceEmpire.irl", true);
user_pref("extensions.EnhanceEmpire.is", "kmpp1cz");
user_pref("extensions.EnhanceEmpire.ug", "619BFAE2-2640-4B37-8A40-5C5B538203BC");
---- FireFox user.js and prefs.js backups ----

prefs_201416.03._1505_.backup
prefs_201420.12._2137_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~3\0ff72d80-af9b-4907-86eb-cf468c2dfc75 deleted
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Browse and Search the Internet.lnk deleted
C:\WINDOWS\SysNative\config\systemprofile\Searches deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"ff-bmboc@bytemobile.com"="C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon" [31. 08. 2014 13:35]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default
- Undetermined - {3655ec02-5936-4d49-865a-01a969dc2792}
- EnhanceEmpire 1.0.1 - %ProfilePath%\extensions\{3655ec02-5936-4d49-865a-01a969dc2792}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default
9860727E477F17B88E39AF8B69B0407A - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll - Shockwave Flash


==== Chromium Look ======================


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.seznam.cz"
"Search Page"="http://www.seznam.cz"
"Default_Page_URL"="http://www.seznam.cz"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.seznam.cz"
"Start Page"="http://www.seznam.cz"
"Search Page"="http://www.seznam.cz"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.seznam.cz"
"Start Page"="http://www.seznam.cz"
"Search Page"="http://www.seznam.cz"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.seznam.cz"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... {startPage}"

==== Reset Google Chrome ======================

C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Honza\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Honza\AppData\Local\Mozilla\Firefox\Profiles\jbqukk6j.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=11 folders=4 294013 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Honza\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Honza\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on so 20. 12. 2014 at 21:40:56,44 ======================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: nevyžádané pop-up okna

#8 Příspěvek od vyosek »

Poprosim o novy log z FRST
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TIVL
Návštěvník
Návštěvník
Příspěvky: 97
Registrován: 20 Led 2007 20:20
Kontaktovat uživatele:

Re: nevyžádané pop-up okna

#9 Příspěvek od TIVL »

nový log z frst

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-12-2014
Ran by Honza (administrator) on JANA on 20-12-2014 22:04:32
Running from C:\Users\Honza\Downloads
Loaded Profile: Honza (Available profiles: Honza)
Platform: Windows 8.1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Validity Sensors, Inc.) C:\Windows\System32\vcsFPService.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(IVT Corporation) C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe
(Glarysoft Ltd) C:\Program Files (x86)\Glary Utilities 5\Integrator.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe
(Vodafone) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Bytemobile, Inc.) C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\bmctl.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2014-02-10] (IDT, Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285832 2013-11-10] (Intel Corporation)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-24] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => c:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2012-08-31] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => c:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe [167024 2012-08-31] (CyberLink Corp.)
HKLM-x32\...\Run: [BtTray] => C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BtTray.exe [371976 2012-09-19] (IVT Corporation)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [683656 2013-06-05] (PDF Complete Inc)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [337184 2013-10-16] (Hewlett-Packard Company)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [RemoveNetSoftware] => C:\Program Files\NetSoftware\\rmNetSoftware.exe [1186800 2014-02-10] (Gemius)
HKLM-x32\...\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [252928 2010-04-28] (Vodafone)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-12-02] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-12-08] (Glarysoft Ltd)
BootExecute: autocheck autochk *

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3949523431-268354437-2035300158-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3949523431-268354437-2035300158-1002 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3949523431-268354437-2035300158-1002 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{E161744B-45CA-405F-9125-2943A35B6173}: [NameServer] 217.77.161.134,217.77.165.81

FireFox:
========
FF ProfilePath: C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Extension: EnhanceEmpire 1.0.1 - C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default\Extensions\{3655ec02-5936-4d49-865a-01a969dc2792}.xpi [2014-11-27]
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon
FF Extension: Bytemobile Optimization Client - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon [2014-08-31]

Chrome:
=======
CHR Profile: C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-16]
CHR Extension: (Disk Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-16]
CHR Extension: (YouTube) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-16]
CHR Extension: (Vyhledávání Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-16]
CHR Extension: (Peněženka Google) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-05]
CHR Extension: (Gmail) - C:\Users\Honza\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 BlueSoleilCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BlueSoleilCS.exe [1612552 2012-09-26] (IVT Corporation)
R3 BsHelpCS; C:\Program Files (x86)\Ralink Corporation\Ralink Bluetooth Stack\BsHelpCS.exe [146184 2012-09-19] (IVT Corporation)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [85504 2012-08-15] (Hewlett-Packard Company) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [681760 2013-10-16] (Hewlett-Packard Company)
R3 hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [1006424 2013-01-23] (Hewlett-Packard Company) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131032 2013-11-10] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-11-10] (Intel Corporation)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1143432 2013-06-05] (PDF Complete Inc)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2014-02-10] (IDT, Inc.) [File not signed]
R2 VmbService; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [9216 2010-04-28] (Vodafone) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 adusbser; C:\Windows\system32\DRIVERS\adusbser.sys [123392 2010-12-20] (QUALCOMM Incorporated)
R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2014-08-31] (Bytemobile, Inc.) [File not signed]
R3 BtAudioBusSrv; C:\Windows\System32\Drivers\BtAudioBus.sys [23136 2012-06-15] (IVT Corporation)
U4 BthAvrcpTg; No ImagePath
U4 BthHFEnum; No ImagePath
U4 bthhfhid; No ImagePath
R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [56904 2012-07-19] (Ralink Corporation)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 btUrbFilterDrv; C:\Windows\System32\Drivers\IvtUrbBtFlt.sys [48608 2012-10-02] (Ralink Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 FcSerial; C:\Windows\system32\DRIVERS\FcSerial.sys [221568 2013-01-30] (Flash Card.)
S3 ggqldxnl; C:\Windows\System32\Drivers\ggqldxnl.sys [423240 2014-04-27] (AVAST Software)
R1 GUBootStartup; C:\WINDOWS\System32\drivers\GUBootStartup.sys [20160 2014-12-20] (Glarysoft Ltd)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1204424 2013-12-02] (Ralink Technology, Corp.)
R3 SensorsServiceDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-15] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-15] (Synaptics Incorporated)
R3 SNP2UVC; C:\Windows\system32\DRIVERS\snp2uvc.sys [1866080 2012-11-20] ()
R1 tcpipBM; C:\WINDOWS\system32\drivers\tcpipBM.sys [39552 2014-08-31] (Bytemobile, Inc.) [File not signed]
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
R3 wmbclass; C:\Windows\system32\DRIVERS\wmbclass.sys [268288 2013-11-01] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-20 21:41 - 2014-12-20 21:41 - 00000000 ____D () C:\Users\Honza\AppData\Local\VirtualStore
2014-12-20 21:40 - 2014-12-20 21:40 - 00000000 ____D () C:\ProgramData\Validity
2014-12-20 21:39 - 2014-12-20 21:24 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-12-20 21:25 - 2014-12-20 21:40 - 00010733 _____ () C:\zoek-results.log
2014-12-20 20:47 - 2014-12-20 20:47 - 02166272 _____ () C:\Users\Honza\Downloads\AdwCleaner.exe
2014-12-20 20:42 - 2014-12-20 20:42 - 00000198 _____ () C:\Users\Honza\Documents\sekunda.txt
2014-12-20 20:40 - 2014-12-20 20:40 - 01295360 _____ () C:\Users\Honza\Downloads\zoek.exe
2014-12-20 20:13 - 2014-12-20 20:14 - 00030609 _____ () C:\Users\Honza\Downloads\Addition.txt
2014-12-20 19:30 - 2014-12-20 19:31 - 07699024 _____ (TeamViewer GmbH) C:\Users\Honza\Downloads\TeamViewer_Setup_cs.exe
2014-12-20 19:18 - 2014-12-20 19:18 - 00000039 _____ () C:\WINDOWS\setupact.log
2014-12-20 19:18 - 2014-12-20 19:18 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-12-20 19:12 - 2014-12-20 21:40 - 00001434 _____ () C:\WINDOWS\PFRO.log
2014-12-20 18:52 - 2014-12-20 18:52 - 00000000 ____D () C:\ProgramData\GlarySoft
2014-12-20 18:36 - 2014-12-20 21:41 - 00000338 _____ () C:\WINDOWS\Tasks\GlaryInitialize 5.job
2014-12-20 18:36 - 2014-12-20 18:36 - 00020160 _____ (Glarysoft Ltd) C:\WINDOWS\system32\Drivers\GUBootStartup.sys
2014-12-20 18:36 - 2014-12-20 18:36 - 00002964 _____ () C:\WINDOWS\System32\Tasks\GU5SkipUAC
2014-12-20 18:36 - 2014-12-20 18:36 - 00002606 _____ () C:\WINDOWS\System32\Tasks\GlaryInitialize 5
2014-12-20 18:36 - 2014-12-20 18:36 - 00001106 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\GlarySoft
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 5
2014-12-20 17:58 - 2014-12-20 17:58 - 00000000 ____D () C:\Users\Honza\AppData\Local\Evernote
2014-12-17 16:13 - 2014-12-17 16:13 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2014-12-17 15:43 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-12-17 15:43 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-12-17 15:43 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-12-17 15:43 - 2014-11-22 03:49 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2014-12-17 15:43 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-12-17 15:43 - 2014-11-22 03:35 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-12-17 15:43 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-12-17 15:43 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-12-17 15:43 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-12-17 15:43 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-12-17 15:43 - 2014-11-22 03:06 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2014-12-17 15:43 - 2014-11-22 03:06 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2014-12-17 15:43 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-12-17 15:43 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-12-17 15:43 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-12-17 15:43 - 2014-11-22 02:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2014-12-17 15:43 - 2014-11-22 02:55 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-12-17 15:43 - 2014-11-22 02:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2014-12-17 15:43 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-12-17 15:43 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-12-17 15:43 - 2014-11-22 02:49 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-12-17 15:43 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-12-17 15:43 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-12-17 15:43 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-12-17 15:43 - 2014-11-22 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2014-12-17 15:43 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-12-17 15:43 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-12-17 15:43 - 2014-11-22 02:29 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2014-12-17 15:43 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-12-17 15:43 - 2014-11-22 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2014-12-17 15:43 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-12-17 15:43 - 2014-11-22 02:23 - 00326656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-12-17 15:43 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-12-17 15:43 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-12-17 15:43 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-12-17 15:43 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-12-17 15:43 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-12-17 15:43 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-12-17 15:43 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-12-17 15:42 - 2014-12-04 00:37 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-12-17 15:42 - 2014-12-04 00:09 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 01083392 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 00740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 00396288 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2014-12-17 15:42 - 2014-12-03 00:09 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2014-12-17 15:41 - 2014-11-07 05:16 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2014-12-17 15:41 - 2014-11-07 04:26 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2014-12-17 15:41 - 2014-11-01 00:57 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2014-12-17 15:41 - 2014-11-01 00:47 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2014-12-17 15:41 - 2014-10-31 00:39 - 01970432 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2014-12-17 15:41 - 2014-10-31 00:38 - 01612992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2014-12-17 15:10 - 2014-11-10 03:29 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupStatusProvider.dll
2014-12-17 15:10 - 2014-11-10 02:51 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceSetupStatusProvider.dll
2014-12-17 15:10 - 2014-10-13 03:43 - 00238912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2014-12-17 15:10 - 2014-10-13 03:43 - 00153920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2014-12-17 15:10 - 2014-10-13 03:43 - 00086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2014-12-17 15:10 - 2014-10-13 03:43 - 00039744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2014-12-09 21:47 - 2014-12-09 21:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-20 22:05 - 2014-04-21 08:11 - 00014990 _____ () C:\Users\Honza\Downloads\FRST.txt
2014-12-20 22:04 - 2014-03-16 15:35 - 00000000 ____D () C:\FRST
2014-12-20 22:03 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-12-20 22:02 - 2014-08-31 11:39 - 01472943 _____ () C:\WINDOWS\WindowsUpdate.log
2014-12-20 21:49 - 2013-12-30 07:14 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\Skype
2014-12-20 21:47 - 2013-11-14 13:40 - 01938474 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-12-20 21:47 - 2013-11-14 13:24 - 00803244 _____ () C:\WINDOWS\system32\perfh005.dat
2014-12-20 21:47 - 2013-11-14 13:24 - 00184236 _____ () C:\WINDOWS\system32\perfc005.dat
2014-12-20 21:43 - 2012-09-26 09:53 - 00000950 _____ () C:\WINDOWS\SysWOW64\bscs.ini
2014-12-20 21:41 - 2013-11-10 16:56 - 00003619 _____ () C:\WINDOWS\SysWOW64\LOCALSERVICE.INI
2014-12-20 21:41 - 2013-11-07 19:20 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-12-20 21:40 - 2013-11-10 16:56 - 00000043 _____ () C:\WINDOWS\SysWOW64\LOCALDEVICE.INI
2014-12-20 21:40 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-12-20 21:40 - 2012-11-22 04:49 - 00000000 ____D () C:\ProgramData\PDFC
2014-12-20 21:37 - 2014-03-16 14:55 - 00000000 ____D () C:\zoek_backup
2014-12-20 21:23 - 2014-01-14 14:59 - 00003954 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{DA3C9BDD-9D8C-42BC-851D-E81AC4AAD560}
2014-12-20 20:53 - 2014-03-16 14:47 - 00000000 ____D () C:\AdwCleaner
2014-12-20 20:53 - 2013-08-22 14:25 - 00000194 _____ () C:\WINDOWS\win.ini
2014-12-20 20:11 - 2014-07-06 19:18 - 00000000 ____D () C:\Users\Honza\Downloads\FRST-OlderVersion
2014-12-20 20:11 - 2014-04-21 08:10 - 02122240 _____ (Farbar) C:\Users\Honza\Downloads\FRST64.exe
2014-12-20 20:01 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-12-20 18:50 - 2013-10-24 02:35 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3949523431-268354437-2035300158-1002
2014-12-20 18:41 - 2012-11-22 04:47 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2014-12-20 18:20 - 2014-08-31 13:35 - 00000000 ____D () C:\ProgramData\Vodafone
2014-12-20 18:04 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-12-20 18:02 - 2013-12-30 07:14 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-20 18:02 - 2013-11-10 20:01 - 00003156 _____ () C:\WINDOWS\System32\Tasks\HPCeeScheduleForHonza
2014-12-20 18:02 - 2013-11-10 20:01 - 00000342 _____ () C:\WINDOWS\Tasks\HPCeeScheduleForHonza.job
2014-12-20 18:00 - 2012-11-22 04:49 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2014-12-17 16:15 - 2013-11-03 11:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-17 16:13 - 2014-07-12 06:03 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-12-17 16:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-RS
2014-12-17 16:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-CS
2014-12-17 16:13 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-12-17 15:48 - 2013-11-04 17:52 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-12-17 15:46 - 2013-11-04 17:52 - 112710672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-12-17 11:24 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-12-15 06:46 - 2013-11-09 11:53 - 00000052 _____ () C:\WINDOWS\SysWOW64\DOErrors.log
2014-12-15 06:45 - 2013-11-10 14:25 - 00000000 _____ () C:\WINDOWS\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-12-09 21:43 - 2013-11-07 19:20 - 00003802 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-11-20 21:51 - 2014-05-19 17:26 - 00714208 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-11-20 21:51 - 2014-05-19 17:26 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-20 06:27 - 2013-08-22 15:44 - 00346768 _____ () C:\WINDOWS\system32\FNTCACHE.DAT

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-12-20 21:54

==================== End Of Log ============================

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: nevyžádané pop-up okna

#10 Příspěvek od vyosek »

:arrow: Odinstalujte GlaryInitialize 5 - je neucinny

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-24] (CyberLink Corp.)
    HKLM-x32\...\Run: [RemoteControl10] => c:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
    HKLM-x32\...\Run: [YouCam Mirage] => c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2012-08-31] (CyberLink)
    HKLM-x32\...\Run: [] => [X]
    HKU\S-1-5-21-3949523431-268354437-2035300158-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
    HKU\S-1-5-21-3949523431-268354437-2035300158-1002\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-12-08] (Glarysoft Ltd)
    
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    
    FF Extension: EnhanceEmpire 1.0.1 - C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default\Extensions\{3655ec02-5936-4d49-865a-01a969dc2792}.xpi [2014-11-27]
    FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon
    FF Extension: Bytemobile Optimization Client - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon [2014-08-31]
    
    2014-12-20 21:39 - 2014-12-20 21:24 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
    2014-12-20 21:25 - 2014-12-20 21:40 - 00010733 _____ () C:\zoek-results.log
    2014-12-20 20:47 - 2014-12-20 20:47 - 02166272 _____ () C:\Users\Honza\Downloads\AdwCleaner.exe
    2014-12-20 20:42 - 2014-12-20 20:42 - 00000198 _____ () C:\Users\Honza\Documents\sekunda.txt
    2014-12-20 20:40 - 2014-12-20 20:40 - 01295360 _____ () C:\Users\Honza\Downloads\zoek.exe
    2014-12-20 20:13 - 2014-12-20 20:14 - 00030609 _____ () C:\Users\Honza\Downloads\Addition.txt
    2014-12-20 19:18 - 2014-12-20 19:18 - 00000039 _____ () C:\WINDOWS\setupact.log
    2014-12-20 19:18 - 2014-12-20 19:18 - 00000000 _____ () C:\WINDOWS\setuperr.log
    2014-12-20 19:12 - 2014-12-20 21:40 - 00001434 _____ () C:\WINDOWS\PFRO.log
    2014-12-20 18:52 - 2014-12-20 18:52 - 00000000 ____D () C:\ProgramData\GlarySoft
    2014-12-20 18:36 - 2014-12-20 21:41 - 00000338 _____ () C:\WINDOWS\Tasks\GlaryInitialize 5.job
    2014-12-20 18:36 - 2014-12-20 18:36 - 00020160 _____ (Glarysoft Ltd) C:\WINDOWS\system32\Drivers\GUBootStartup.sys
    2014-12-20 18:36 - 2014-12-20 18:36 - 00002964 _____ () C:\WINDOWS\System32\Tasks\GU5SkipUAC
    2014-12-20 18:36 - 2014-12-20 18:36 - 00002606 _____ () C:\WINDOWS\System32\Tasks\GlaryInitialize 5
    2014-12-20 18:36 - 2014-12-20 18:36 - 00001106 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
    2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\GlarySoft
    2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
    2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 5
    2014-12-20 20:11 - 2014-07-06 19:18 - 00000000 ____D () C:\Users\Honza\Downloads\FRST-OlderVersion
    2014-12-20 20:53 - 2014-03-16 14:47 - 00000000 ____D () C:\AdwCleaner
    2014-12-20 21:37 - 2014-03-16 14:55 - 00000000 ____D () C:\zoek_backup
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TIVL
Návštěvník
Návštěvník
Příspěvky: 97
Registrován: 20 Led 2007 20:20
Kontaktovat uživatele:

Re: nevyžádané pop-up okna

#11 Příspěvek od TIVL »

fixlog

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-12-2014
Ran by Honza at 2014-12-20 22:26:36 Run:1
Running from C:\Users\Honza\Downloads
Loaded Profile: Honza (Available profiles: Honza)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM-x32\...\Run: [CLVirtualDrive] => c:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-24] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => c:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2012-08-31] (CyberLink)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-12-08] (Glarysoft Ltd)

SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

FF Extension: EnhanceEmpire 1.0.1 - C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default\Extensions\{3655ec02-5936-4d49-865a-01a969dc2792}.xpi [2014-11-27]
FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon
FF Extension: Bytemobile Optimization Client - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon [2014-08-31]

2014-12-20 21:39 - 2014-12-20 21:24 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2014-12-20 21:25 - 2014-12-20 21:40 - 00010733 _____ () C:\zoek-results.log
2014-12-20 20:47 - 2014-12-20 20:47 - 02166272 _____ () C:\Users\Honza\Downloads\AdwCleaner.exe
2014-12-20 20:42 - 2014-12-20 20:42 - 00000198 _____ () C:\Users\Honza\Documents\sekunda.txt
2014-12-20 20:40 - 2014-12-20 20:40 - 01295360 _____ () C:\Users\Honza\Downloads\zoek.exe
2014-12-20 20:13 - 2014-12-20 20:14 - 00030609 _____ () C:\Users\Honza\Downloads\Addition.txt
2014-12-20 19:18 - 2014-12-20 19:18 - 00000039 _____ () C:\WINDOWS\setupact.log
2014-12-20 19:18 - 2014-12-20 19:18 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-12-20 19:12 - 2014-12-20 21:40 - 00001434 _____ () C:\WINDOWS\PFRO.log
2014-12-20 18:52 - 2014-12-20 18:52 - 00000000 ____D () C:\ProgramData\GlarySoft
2014-12-20 18:36 - 2014-12-20 21:41 - 00000338 _____ () C:\WINDOWS\Tasks\GlaryInitialize 5.job
2014-12-20 18:36 - 2014-12-20 18:36 - 00020160 _____ (Glarysoft Ltd) C:\WINDOWS\system32\Drivers\GUBootStartup.sys
2014-12-20 18:36 - 2014-12-20 18:36 - 00002964 _____ () C:\WINDOWS\System32\Tasks\GU5SkipUAC
2014-12-20 18:36 - 2014-12-20 18:36 - 00002606 _____ () C:\WINDOWS\System32\Tasks\GlaryInitialize 5
2014-12-20 18:36 - 2014-12-20 18:36 - 00001106 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Users\Honza\AppData\Roaming\GlarySoft
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
2014-12-20 18:36 - 2014-12-20 18:36 - 00000000 ____D () C:\Program Files (x86)\Glary Utilities 5
2014-12-20 20:11 - 2014-07-06 19:18 - 00000000 ____D () C:\Users\Honza\Downloads\FRST-OlderVersion
2014-12-20 20:53 - 2014-03-16 14:47 - 00000000 ____D () C:\AdwCleaner
2014-12-20 21:37 - 2014-03-16 14:55 - 00000000 ____D () C:\zoek_backup

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\CLVirtualDrive => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\RemoteControl10 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\YouCam Mirage => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => value deleted successfully.
HKU\S-1-5-21-3949523431-268354437-2035300158-1002\Software\Microsoft\Windows\CurrentVersion\Run\\GUDelayStartup => Value not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
C:\Users\Honza\AppData\Roaming\Mozilla\Firefox\Profiles\jbqukk6j.default\Extensions\{3655ec02-5936-4d49-865a-01a969dc2792}.xpi => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ff-bmboc@bytemobile.com => value deleted successfully.
C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\addon => Moved successfully.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\Users\Honza\Downloads\AdwCleaner.exe => Moved successfully.
C:\Users\Honza\Documents\sekunda.txt => Moved successfully.
C:\Users\Honza\Downloads\zoek.exe => Moved successfully.
C:\Users\Honza\Downloads\Addition.txt => Moved successfully.
C:\WINDOWS\setupact.log => Moved successfully.
C:\WINDOWS\setuperr.log => Moved successfully.
C:\WINDOWS\PFRO.log => Moved successfully.
C:\ProgramData\GlarySoft => Moved successfully.
"C:\WINDOWS\Tasks\GlaryInitialize 5.job" => File/Directory not found.
"C:\WINDOWS\system32\Drivers\GUBootStartup.sys" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\GU5SkipUAC" => File/Directory not found.
"C:\WINDOWS\System32\Tasks\GlaryInitialize 5" => File/Directory not found.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk" => File/Directory not found.
C:\Users\Honza\AppData\Roaming\GlarySoft => Moved successfully.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5" => File/Directory not found.
"C:\Program Files (x86)\Glary Utilities 5" => File/Directory not found.
C:\Users\Honza\Downloads\FRST-OlderVersion => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 42.2 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: nevyžádané pop-up okna

#12 Příspěvek od vyosek »

Jak se chova PC???
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TIVL
Návštěvník
Návštěvník
Příspěvky: 97
Registrován: 20 Led 2007 20:20
Kontaktovat uživatele:

Re: nevyžádané pop-up okna

#13 Příspěvek od TIVL »

vypadá čistě, nějaké doporučení jako náhrada glary utilities?

Avatar uživatele
vyosek
VIP
VIP
Příspěvky: 56365
Registrován: 07 Lis 2006 15:24
Místo/Bydliště: Šalingrad - Brno

Re: nevyžádané pop-up okna

#14 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remote disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner https://www.piriform.com/ccleaner/download/standard
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Na udrzbu PC CCleaner, na obcasny jednorazovy sken doporucuji MBAM

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

TIVL
Návštěvník
Návštěvník
Příspěvky: 97
Registrován: 20 Led 2007 20:20
Kontaktovat uživatele:

Re: nevyžádané pop-up okna

#15 Příspěvek od TIVL »

díky za podporu

Zamčeno