poprosim kontrolu fb haveď
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
poprosim kontrolu fb haveď
Logfile of random's system information tool 1.10 (written by random/random)
Run by Adka at 2014-12-25 15:13:04
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 18 GB (18%) free of 100 GB
Total RAM: 3929 MB (33% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:13:10, on 25. 12. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
D:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Steam\steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
D:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Users\Adka\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files\trend micro\Adka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [DriverChecker.exe] C:\Program Files (x86)\Driver Checker\DriverChecker.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://D:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll,C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Sleep memory optimizer (FFSOpzSvc) - Acer Incorporated - C:\Program Files\Sleep Memory Optimizer\FFSService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel® Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - D:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Wlan Agent - Atheros - C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe
--
End of file - 10886 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe"
C:\Windows\system32\WLANExt.exe 32017984
\??\C:\Windows\system32\conhost.exe "-342406640-206402651215382417711192018350925993151-622317180-483793813328974138
C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"taskhost.exe"
taskeng.exe {D3592351-A44B-42F7-B33B-AEA595C60318}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Explorer.EXE
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Sleep Memory Optimizer\FFSService.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 7741a8d9-d84d-4680-bfcf-dc1ab6219b7b 1
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "1322402661196605158813207131851723781432496924758201459604213838287101573026713
\??\C:\Windows\system32\conhost.exe "602242871-1428528502-783208200-571386675-3099394762007110924-2004740509-237597168
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"D:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
ngservice.exe pipeserver
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Steam\steam.exe" "steam://rungameid/221100"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Program Files (x86)\Steam\config\htmlcache" -cookiepath "C:\Program Files (x86)\Steam\config\cookies" -steampid 4968 --blacklist-accelerated-compositing --process-per-tab --disable-accelerated-video-decode --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4044.1fa24860.511628965 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 4044 "\\.\pipe\gecko-crash-server-pipe.4044" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe" --proxy-stub-channel=Flash6140.5D965348.19004 --host-broker-channel=Flash6140.5D965348.22228 --host-pid=6140 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe" --channel=1636.0030F3C4.294640507 --proxy-stub-channel=Flash6140.5D965348.19004 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll" --host-npapi-version=27 --type=renderer
"D:\Program Files (x86)\iTunes\iTunes.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe" --pipe \\.\pipe\30416965-1153609284116674644 --parentPipe
\??\C:\Windows\system32\conhost.exe "336741249-7748038091111376576-7685657238442663961118042387-2007585894-1326411592
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe"
\??\C:\Windows\system32\conhost.exe "725939290-1581602155214340466330260191287898954-16763378321206954946-469832168
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" -Embedding
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe"
\??\C:\Windows\system32\conhost.exe "-123522261493069841-23309751685383925-1867415137-2051640266284065410-1143292501
"C:\Users\Adka\AppData\Roaming\uTorrent\uTorrent.exe" "C:\Users\Adka\Downloads\Minecraft_-_Pocket_Edition_(v.0.94)_[iOS_Game]_[English].ipa.torrent"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
"C:\Users\Adka\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
prefs.js - "browser.startup.homepage" - "Google.sk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=Doplnok iTunes Detector
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=D:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-11-16 705448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - D:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2012-10-01 877720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-11-16 586968]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2012-10-01 704664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2012-10-01 1720976]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [2014-11-16 7144960]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-01-29 171992]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-01-29 399832]
"Persistence"=C:\Windows\system32\igfxpers.exe [2014-01-29 442328]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-12-13 2824504]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-01-10 12445288]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-10-23 6501656]
"AdobeBridge"= []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2014-10-23 6501656]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
D:\Program Files (x86)\Origin\Origin.exe [2014-11-17 3618648]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-12-12 5227112]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-11-30 56128]
"DriverChecker.exe"=C:\Program Files (x86)\Driver Checker\DriverChecker.exe [2012-11-08 11707336]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-02-26 291608]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"iTunesHelper"=D:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-10-15 157480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" ,C:\Windows\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2014-01-29 442880]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-12-25 15:13:05 ----D---- C:\Program Files\trend micro
2014-12-25 15:13:04 ----D---- C:\rsit
2014-12-23 22:16:38 ----D---- C:\Users\Adka\AppData\Roaming\Apple Computer
2014-12-23 22:16:26 ----DC---- C:\Windows\system32\DRVSTORE
2014-12-23 22:16:26 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2014-12-23 22:15:57 ----D---- C:\Program Files\iPod
2014-12-23 22:15:55 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-12-23 22:15:55 ----D---- C:\ProgramData\Apple Computer
2014-12-23 22:15:55 ----D---- C:\Program Files\iTunes
2014-12-23 22:13:33 ----D---- C:\Program Files (x86)\Apple Software Update
2014-12-23 22:13:11 ----D---- C:\Program Files\Common Files\Apple
2014-12-23 22:12:50 ----D---- C:\Program Files\Bonjour
2014-12-23 22:12:50 ----D---- C:\Program Files (x86)\Bonjour
2014-12-23 22:12:33 ----D---- C:\ProgramData\Apple
2014-12-23 20:54:33 ----D---- C:\Windows\SYSWOW64\NV
2014-12-23 20:54:33 ----D---- C:\Windows\system32\NV
2014-12-23 20:54:31 ----D---- C:\ProgramData\NVIDIA
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvvsvc.exe
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvsvcr.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvsvc64.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvshext.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvmctray.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvcpl.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nv3dappshextr.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nv3dappshext.dll
2014-12-23 20:52:20 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2014-12-23 20:52:20 ----A---- C:\Windows\system32\OpenCL.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvwgf2umx.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvumdshimx.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvopencl.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvoglv64.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvoglshim64.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvinitx.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\drivers\nvpciflt.sys
2014-12-23 20:45:51 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\NvIFR64.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\NvFBC64.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvdispgenco6434709.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvdispco6434709.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvd3dumx.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvcuvid.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvcuda.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvcompiler.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvapi64.dll
2014-12-18 08:50:11 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-12-18 08:50:11 ----A---- C:\Windows\system32\ieUnatt.exe
2014-12-16 21:28:17 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2014-12-16 21:22:28 ----D---- C:\Program Files\Adobe
2014-12-16 21:20:28 ----D---- C:\ProgramData\ALM
2014-12-16 21:11:33 ----D---- C:\Program Files (x86)\Adobe
2014-12-16 21:07:12 ----D---- C:\Program Files\Common Files\Adobe
2014-12-16 20:58:39 ----D---- C:\ProgramData\Adobe
2014-12-16 18:49:53 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2014-12-16 18:49:53 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2014-12-13 16:42:15 ----RHD---- C:\MSOCache
2014-12-11 08:12:23 ----D---- C:\Windows\system32\appraiser
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\mfps.dll
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\mferror.dll
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\mf.dll
2014-12-11 02:14:00 ----A---- C:\Windows\system32\rrinstaller.exe
2014-12-11 02:14:00 ----A---- C:\Windows\system32\mfps.dll
2014-12-11 02:14:00 ----A---- C:\Windows\system32\mfpmp.exe
2014-12-11 02:14:00 ----A---- C:\Windows\system32\mferror.dll
2014-12-11 02:13:59 ----A---- C:\Windows\system32\mf.dll
2014-12-11 02:01:50 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-12-11 02:01:50 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-12-11 02:01:39 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-12-11 02:01:39 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-12-11 02:01:39 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-12-11 02:01:39 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-12-11 02:01:38 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-12-11 02:01:38 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-12-11 02:01:38 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-12-11 02:01:38 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-12-11 02:01:38 ----A---- C:\Windows\system32\iernonce.dll
2014-12-11 02:01:38 ----A---- C:\Windows\system32\ie4uinit.exe
2014-12-11 02:01:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-12-11 02:01:37 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-12-11 02:01:37 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-12-11 02:01:37 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-11 02:01:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-12-11 02:01:36 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-12-11 02:01:35 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-12-11 02:01:35 ----A---- C:\Windows\system32\urlmon.dll
2014-12-11 02:01:35 ----A---- C:\Windows\system32\iedkcs32.dll
2014-12-11 02:01:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-12-11 02:01:34 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-12-11 02:01:34 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-12-11 02:01:33 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-12-11 02:01:33 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-12-11 02:01:33 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-11 02:01:33 ----A---- C:\Windows\system32\msfeeds.dll
2014-12-11 02:01:33 ----A---- C:\Windows\system32\dxtrans.dll
2014-12-11 02:01:32 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-12-11 02:01:32 ----A---- C:\Windows\system32\iesetup.dll
2014-12-11 02:01:32 ----A---- C:\Windows\system32\ieapfltr.dll
2014-12-11 02:01:31 ----A---- C:\Windows\system32\iertutil.dll
2014-12-11 02:01:30 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-12-11 02:01:29 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-12-11 02:01:29 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-12-11 02:01:29 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-12-11 02:01:29 ----A---- C:\Windows\system32\jsproxy.dll
2014-12-11 02:01:28 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-12-11 02:01:28 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-12-11 02:01:28 ----A---- C:\Windows\system32\dxtmsft.dll
2014-12-11 02:01:27 ----A---- C:\Windows\system32\ieui.dll
2014-12-11 02:01:27 ----A---- C:\Windows\system32\ieframe.dll
2014-12-11 02:01:26 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-12-11 02:01:26 ----A---- C:\Windows\system32\mshtmled.dll
2014-12-11 02:01:26 ----A---- C:\Windows\system32\jscript9diag.dll
2014-12-11 02:01:25 ----A---- C:\Windows\system32\wininet.dll
2014-12-11 02:01:25 ----A---- C:\Windows\system32\vbscript.dll
2014-12-11 02:01:25 ----A---- C:\Windows\system32\jscript9.dll
2014-12-11 02:01:24 ----A---- C:\Windows\system32\msrating.dll
2014-12-11 02:01:24 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-12-11 02:01:23 ----A---- C:\Windows\system32\mshtml.dll
2014-12-11 02:01:00 ----A---- C:\Windows\system32\aitstatic.exe
2014-12-11 02:00:59 ----A---- C:\Windows\system32\invagent.dll
2014-12-11 02:00:59 ----A---- C:\Windows\system32\appraiser.dll
2014-12-11 02:00:59 ----A---- C:\Windows\system32\aepic.dll
2014-12-11 02:00:59 ----A---- C:\Windows\system32\aeinv.dll
2014-12-11 02:00:58 ----A---- C:\Windows\system32\generaltel.dll
2014-12-11 02:00:58 ----A---- C:\Windows\system32\devinv.dll
2014-12-11 02:00:57 ----A---- C:\Windows\system32\aepdu.dll
2014-12-11 02:00:56 ----A---- C:\Windows\system32\charmap.exe
2014-12-11 02:00:56 ----A---- C:\Windows\system32\drivers\tdx.sys
2014-12-11 02:00:55 ----A---- C:\Windows\SYSWOW64\charmap.exe
2014-12-11 02:00:54 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2014-12-11 02:00:54 ----A---- C:\Windows\system32\WsmWmiPl.dll
2014-12-11 02:00:54 ----A---- C:\Windows\system32\WsmSvc.dll
2014-12-11 02:00:53 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2014-12-11 02:00:53 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2014-12-11 02:00:53 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2014-12-11 02:00:53 ----A---- C:\Windows\system32\WsmAuto.dll
2014-12-11 02:00:53 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-11 02:00:53 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2014-12-11 02:00:52 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2014-12-11 02:00:50 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-12-11 02:00:50 ----A---- C:\Windows\system32\tzres.dll
2014-12-10 17:58:18 ----D---- C:\AdwCleaner
2014-12-07 13:13:48 ----D---- C:\Program Files (x86)\Steam
2014-12-07 12:36:41 ----D---- C:\ProgramData\3872871776
2014-12-06 16:01:44 ----D---- C:\ProgramData\WarThunder
2014-12-03 08:17:48 ----D---- C:\Program Files (x86)\YoutubeAdBlocke
2014-12-03 08:17:16 ----D---- C:\ProgramData\ncfnhhjacephkbmcmanplgkelpmncbba
2014-12-03 08:13:07 ----D---- C:\ProgramData\moiflmcepnmeogbnogkidklbilimgmmh
2014-12-01 23:18:54 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-29 15:03:30 ----D---- C:\NVIDIA
======List of files/folders modified in the last 1 month======
2014-12-25 15:13:10 ----D---- C:\Windows\Prefetch
2014-12-25 15:13:08 ----D---- C:\Windows\Temp
2014-12-25 15:13:05 ----RD---- C:\Program Files
2014-12-25 15:12:58 ----D---- C:\Users\Adka\AppData\Roaming\uTorrent
2014-12-25 12:40:33 ----D---- C:\Windows\system32\config
2014-12-25 12:29:12 ----D---- C:\Windows\System32
2014-12-24 03:32:19 ----D---- C:\Windows\system32\catroot
2014-12-23 22:16:43 ----SHD---- C:\Windows\Installer
2014-12-23 22:16:30 ----D---- C:\Windows\SysWOW64
2014-12-23 22:16:26 ----D---- C:\Windows\system32\drivers
2014-12-23 22:15:55 ----HD---- C:\ProgramData
2014-12-23 22:14:19 ----SHD---- C:\System Volume Information
2014-12-23 22:13:38 ----D---- C:\Windows\system32\Tasks
2014-12-23 22:13:33 ----RD---- C:\Program Files (x86)
2014-12-23 22:13:26 ----D---- C:\Windows\system32\DriverStore
2014-12-23 22:13:25 ----D---- C:\Windows\inf
2014-12-23 22:13:11 ----D---- C:\Program Files\Common Files
2014-12-23 22:12:33 ----D---- C:\Program Files (x86)\Common Files
2014-12-23 20:52:49 ----D---- C:\Windows\Help
2014-12-23 20:52:49 ----D---- C:\Program Files\NVIDIA Corporation
2014-12-23 20:52:08 ----D---- C:\ProgramData\NVIDIA Corporation
2014-12-23 20:51:57 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-12-23 20:49:10 ----D---- C:\Windows\system32\catroot2
2014-12-23 20:38:06 ----D---- C:\Windows
2014-12-23 18:50:14 ----D---- C:\Windows\Minidump
2014-12-23 18:00:35 ----D---- C:\ProgramData\EA Logs
2014-12-23 07:07:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-12-22 23:39:29 ----SD---- C:\Users\Adka\AppData\Roaming\Microsoft
2014-12-18 22:34:02 ----D---- C:\Windows\winsxs
2014-12-17 08:13:19 ----D---- C:\Windows\system32\LogFiles
2014-12-16 21:31:16 ----D---- C:\Users\Adka\AppData\Roaming\Adobe
2014-12-16 21:14:16 ----RSD---- C:\Windows\Fonts
2014-12-16 20:17:58 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-12-15 12:34:02 ----D---- C:\Windows\system32\wdi
2014-12-13 20:30:31 ----D---- C:\Windows\rescache
2014-12-13 14:35:52 ----D---- C:\Users\Adka\AppData\Roaming\vlc
2014-12-13 03:50:58 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-12-13 03:50:58 ----D---- C:\Windows\system32\cs-CZ
2014-12-13 01:12:24 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2014-12-13 01:12:24 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-12-13 01:12:12 ----A---- C:\Windows\system32\nvspcap64.dll
2014-12-13 01:12:12 ----A---- C:\Windows\system32\nvspbridge64.dll
2014-12-11 18:47:54 ----RSD---- C:\Windows\assembly
2014-12-11 17:39:26 ----D---- C:\Windows\Logs
2014-12-11 08:12:25 ----SD---- C:\Windows\system32\CompatTel
2014-12-11 08:12:25 ----D---- C:\Windows\AppCompat
2014-12-11 08:12:23 ----SD---- C:\ProgramData\Microsoft
2014-12-11 08:12:16 ----D---- C:\Program Files\Internet Explorer
2014-12-11 08:12:14 ----D---- C:\Windows\SYSWOW64\en-US
2014-12-11 08:12:11 ----D---- C:\Windows\PolicyDefinitions
2014-12-11 08:12:10 ----D---- C:\Windows\system32\en-US
2014-12-11 08:12:08 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-11 02:18:28 ----D---- C:\Windows\system32\MRT
2014-12-11 02:15:26 ----D---- C:\Windows\debug
2014-12-11 02:15:21 ----A---- C:\Windows\system32\MRT.exe
2014-12-10 18:02:15 ----D---- C:\Windows\Tasks
2014-12-10 16:59:36 ----D---- C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-16 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-16 267632]
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2012-11-19 652344]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2012-11-19 28216]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2012-02-26 16152]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2014-12-13 31376]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-11-16 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-22 1050432]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-16 436624]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-11-16 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-16 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-16 83280]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-11-16 116728]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-11-16 271752]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-03-09 3580928]
R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2014-11-16 22592]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-01-29 5363200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-10 4731112]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2012-02-26 356120]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2012-02-26 788760]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2012-06-02 440360]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-17 62784]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-11-22 38032]
S3 DrvAgent64;DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS [2014-11-17 21712]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2011-05-04 338536]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-10-07 60744]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-16 50344]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 FFSOpzSvc;Sleep memory optimizer; C:\Program Files\Sleep Memory Optimizer\FFSService.exe [2011-09-17 141192]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 IAStorDataMgrSvc;Úložná technologie Intel® Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-11-19 14904]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-07 2375168]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-12-13 935240]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-11-17 76888]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE [2014-11-16 48128]
R2 ZAtheros Wlan Agent;ZAtheros Wlan Agent; C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe [2012-03-13 76960]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-11-16 4012248]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-10-15 643880]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-11-18 833728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-16 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-23 267440]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2014-12-11 448384]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-01-29 279000]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-16 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-11-22 114688]
S3 Origin Client Service;Origin Client Service; D:\Program Files (x86)\Origin\OriginClientService.exe [2014-11-17 1900400]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-11-16 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Run by Adka at 2014-12-25 15:13:04
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 18 GB (18%) free of 100 GB
Total RAM: 3929 MB (33% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:13:10, on 25. 12. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
D:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Steam\steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
D:\Program Files (x86)\iTunes\iTunes.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Users\Adka\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files\trend micro\Adka.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [DriverChecker.exe] C:\Program Files (x86)\Driver Checker\DriverChecker.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~2\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://D:\PROGRA~2\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll,C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Sleep memory optimizer (FFSOpzSvc) - Acer Incorporated - C:\Program Files\Sleep Memory Optimizer\FFSService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel® Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - D:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Broadcom Corporation - C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Wlan Agent - Atheros - C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe
--
End of file - 10886 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE" "C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe"
C:\Windows\system32\WLANExt.exe 32017984
\??\C:\Windows\system32\conhost.exe "-342406640-206402651215382417711192018350925993151-622317180-483793813328974138
C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"taskhost.exe"
taskeng.exe {D3592351-A44B-42F7-B33B-AEA595C60318}
"C:\Windows\system32\Dwm.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Explorer.EXE
"C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Sleep Memory Optimizer\FFSService.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 7741a8d9-d84d-4680-bfcf-dc1ab6219b7b 1
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "1322402661196605158813207131851723781432496924758201459604213838287101573026713
\??\C:\Windows\system32\conhost.exe "602242871-1428528502-783208200-571386675-3099394762007110924-2004740509-237597168
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"D:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
ngservice.exe pipeserver
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Steam\steam.exe" "steam://rungameid/221100"
"C:\Program Files (x86)\Steam\bin\steamwebhelper.exe" -cefhost -cachedir "C:\Program Files (x86)\Steam\config\htmlcache" -cookiepath "C:\Program Files (x86)\Steam\config\cookies" -steampid 4968 --blacklist-accelerated-compositing --process-per-tab --disable-accelerated-video-decode --enable-direct-write
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=4044.1fa24860.511628965 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 4044 "\\.\pipe\gecko-crash-server-pipe.4044" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe" --proxy-stub-channel=Flash6140.5D965348.19004 --host-broker-channel=Flash6140.5D965348.22228 --host-pid=6140 --host-npapi-version=27 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe" --channel=1636.0030F3C4.294640507 --proxy-stub-channel=Flash6140.5D965348.19004 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll" --host-npapi-version=27 --type=renderer
"D:\Program Files (x86)\iTunes\iTunes.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe" --pipe \\.\pipe\30416965-1153609284116674644 --parentPipe
\??\C:\Windows\system32\conhost.exe "336741249-7748038091111376576-7685657238442663961118042387-2007585894-1326411592
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe"
\??\C:\Windows\system32\conhost.exe "725939290-1581602155214340466330260191287898954-16763378321206954946-469832168
"C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" -Embedding
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe"
\??\C:\Windows\system32\conhost.exe "-123522261493069841-23309751685383925-1867415137-2051640266284065410-1143292501
"C:\Users\Adka\AppData\Roaming\uTorrent\uTorrent.exe" "C:\Users\Adka\Downloads\Minecraft_-_Pocket_Edition_(v.0.94)_[iOS_Game]_[English].ipa.torrent"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
"C:\Users\Adka\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
prefs.js - "browser.startup.homepage" - "Google.sk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=Doplnok iTunes Detector
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=D:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-11-16 705448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - D:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2012-10-01 877720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-11-16 586968]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2012-10-01 704664]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2012-10-01 1720976]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [2014-11-16 7144960]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-01-29 171992]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-01-29 399832]
"Persistence"=C:\Windows\system32\igfxpers.exe [2014-01-29 442328]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-12-13 2824504]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-01-10 12445288]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2014-10-23 6501656]
"AdobeBridge"= []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files\CCleaner\CCleaner64.exe [2014-10-23 6501656]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
D:\Program Files (x86)\Origin\Origin.exe [2014-11-17 3618648]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-12-12 5227112]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-11-30 56128]
"DriverChecker.exe"=C:\Program Files (x86)\Driver Checker\DriverChecker.exe [2012-11-08 11707336]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-02-26 291608]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"iTunesHelper"=D:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-10-15 157480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" ,C:\Windows\system32\nvinitx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2014-01-29 442880]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-12-25 15:13:05 ----D---- C:\Program Files\trend micro
2014-12-25 15:13:04 ----D---- C:\rsit
2014-12-23 22:16:38 ----D---- C:\Users\Adka\AppData\Roaming\Apple Computer
2014-12-23 22:16:26 ----DC---- C:\Windows\system32\DRVSTORE
2014-12-23 22:16:26 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2014-12-23 22:15:57 ----D---- C:\Program Files\iPod
2014-12-23 22:15:55 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-12-23 22:15:55 ----D---- C:\ProgramData\Apple Computer
2014-12-23 22:15:55 ----D---- C:\Program Files\iTunes
2014-12-23 22:13:33 ----D---- C:\Program Files (x86)\Apple Software Update
2014-12-23 22:13:11 ----D---- C:\Program Files\Common Files\Apple
2014-12-23 22:12:50 ----D---- C:\Program Files\Bonjour
2014-12-23 22:12:50 ----D---- C:\Program Files (x86)\Bonjour
2014-12-23 22:12:33 ----D---- C:\ProgramData\Apple
2014-12-23 20:54:33 ----D---- C:\Windows\SYSWOW64\NV
2014-12-23 20:54:33 ----D---- C:\Windows\system32\NV
2014-12-23 20:54:31 ----D---- C:\ProgramData\NVIDIA
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvvsvc.exe
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvsvcr.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvsvc64.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvshext.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvmctray.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nvcpl.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nv3dappshextr.dll
2014-12-23 20:52:50 ----A---- C:\Windows\system32\nv3dappshext.dll
2014-12-23 20:52:20 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2014-12-23 20:52:20 ----A---- C:\Windows\system32\OpenCL.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2014-12-23 20:45:51 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvwgf2umx.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvumdshimx.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvopencl.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvoglv64.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvoglshim64.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\nvinitx.dll
2014-12-23 20:45:51 ----A---- C:\Windows\system32\drivers\nvpciflt.sys
2014-12-23 20:45:51 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2014-12-23 20:45:50 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\NvIFR64.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\NvFBC64.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvdispgenco6434709.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvdispco6434709.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvd3dumx.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvcuvid.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvcuda.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvcompiler.dll
2014-12-23 20:45:50 ----A---- C:\Windows\system32\nvapi64.dll
2014-12-18 08:50:11 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-12-18 08:50:11 ----A---- C:\Windows\system32\ieUnatt.exe
2014-12-16 21:28:17 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2014-12-16 21:22:28 ----D---- C:\Program Files\Adobe
2014-12-16 21:20:28 ----D---- C:\ProgramData\ALM
2014-12-16 21:11:33 ----D---- C:\Program Files (x86)\Adobe
2014-12-16 21:07:12 ----D---- C:\Program Files\Common Files\Adobe
2014-12-16 20:58:39 ----D---- C:\ProgramData\Adobe
2014-12-16 18:49:53 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2014-12-16 18:49:53 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2014-12-13 16:42:15 ----RHD---- C:\MSOCache
2014-12-11 08:12:23 ----D---- C:\Windows\system32\appraiser
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\mfps.dll
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\mferror.dll
2014-12-11 02:14:00 ----A---- C:\Windows\SYSWOW64\mf.dll
2014-12-11 02:14:00 ----A---- C:\Windows\system32\rrinstaller.exe
2014-12-11 02:14:00 ----A---- C:\Windows\system32\mfps.dll
2014-12-11 02:14:00 ----A---- C:\Windows\system32\mfpmp.exe
2014-12-11 02:14:00 ----A---- C:\Windows\system32\mferror.dll
2014-12-11 02:13:59 ----A---- C:\Windows\system32\mf.dll
2014-12-11 02:01:50 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-12-11 02:01:50 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-12-11 02:01:39 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-12-11 02:01:39 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-12-11 02:01:39 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-12-11 02:01:39 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-12-11 02:01:38 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-12-11 02:01:38 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-12-11 02:01:38 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-12-11 02:01:38 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-12-11 02:01:38 ----A---- C:\Windows\system32\iernonce.dll
2014-12-11 02:01:38 ----A---- C:\Windows\system32\ie4uinit.exe
2014-12-11 02:01:37 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-12-11 02:01:37 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-12-11 02:01:37 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-12-11 02:01:37 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-11 02:01:36 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-12-11 02:01:36 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-12-11 02:01:35 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-12-11 02:01:35 ----A---- C:\Windows\system32\urlmon.dll
2014-12-11 02:01:35 ----A---- C:\Windows\system32\iedkcs32.dll
2014-12-11 02:01:34 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-12-11 02:01:34 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-12-11 02:01:34 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-12-11 02:01:33 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-12-11 02:01:33 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-12-11 02:01:33 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-11 02:01:33 ----A---- C:\Windows\system32\msfeeds.dll
2014-12-11 02:01:33 ----A---- C:\Windows\system32\dxtrans.dll
2014-12-11 02:01:32 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-12-11 02:01:32 ----A---- C:\Windows\system32\iesetup.dll
2014-12-11 02:01:32 ----A---- C:\Windows\system32\ieapfltr.dll
2014-12-11 02:01:31 ----A---- C:\Windows\system32\iertutil.dll
2014-12-11 02:01:30 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-12-11 02:01:29 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-12-11 02:01:29 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-12-11 02:01:29 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-12-11 02:01:29 ----A---- C:\Windows\system32\jsproxy.dll
2014-12-11 02:01:28 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-12-11 02:01:28 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-12-11 02:01:28 ----A---- C:\Windows\system32\dxtmsft.dll
2014-12-11 02:01:27 ----A---- C:\Windows\system32\ieui.dll
2014-12-11 02:01:27 ----A---- C:\Windows\system32\ieframe.dll
2014-12-11 02:01:26 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-12-11 02:01:26 ----A---- C:\Windows\system32\mshtmled.dll
2014-12-11 02:01:26 ----A---- C:\Windows\system32\jscript9diag.dll
2014-12-11 02:01:25 ----A---- C:\Windows\system32\wininet.dll
2014-12-11 02:01:25 ----A---- C:\Windows\system32\vbscript.dll
2014-12-11 02:01:25 ----A---- C:\Windows\system32\jscript9.dll
2014-12-11 02:01:24 ----A---- C:\Windows\system32\msrating.dll
2014-12-11 02:01:24 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-12-11 02:01:23 ----A---- C:\Windows\system32\mshtml.dll
2014-12-11 02:01:00 ----A---- C:\Windows\system32\aitstatic.exe
2014-12-11 02:00:59 ----A---- C:\Windows\system32\invagent.dll
2014-12-11 02:00:59 ----A---- C:\Windows\system32\appraiser.dll
2014-12-11 02:00:59 ----A---- C:\Windows\system32\aepic.dll
2014-12-11 02:00:59 ----A---- C:\Windows\system32\aeinv.dll
2014-12-11 02:00:58 ----A---- C:\Windows\system32\generaltel.dll
2014-12-11 02:00:58 ----A---- C:\Windows\system32\devinv.dll
2014-12-11 02:00:57 ----A---- C:\Windows\system32\aepdu.dll
2014-12-11 02:00:56 ----A---- C:\Windows\system32\charmap.exe
2014-12-11 02:00:56 ----A---- C:\Windows\system32\drivers\tdx.sys
2014-12-11 02:00:55 ----A---- C:\Windows\SYSWOW64\charmap.exe
2014-12-11 02:00:54 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2014-12-11 02:00:54 ----A---- C:\Windows\system32\WsmWmiPl.dll
2014-12-11 02:00:54 ----A---- C:\Windows\system32\WsmSvc.dll
2014-12-11 02:00:53 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2014-12-11 02:00:53 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2014-12-11 02:00:53 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2014-12-11 02:00:53 ----A---- C:\Windows\system32\WsmAuto.dll
2014-12-11 02:00:53 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-11 02:00:53 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2014-12-11 02:00:52 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2014-12-11 02:00:50 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-12-11 02:00:50 ----A---- C:\Windows\system32\tzres.dll
2014-12-10 17:58:18 ----D---- C:\AdwCleaner
2014-12-07 13:13:48 ----D---- C:\Program Files (x86)\Steam
2014-12-07 12:36:41 ----D---- C:\ProgramData\3872871776
2014-12-06 16:01:44 ----D---- C:\ProgramData\WarThunder
2014-12-03 08:17:48 ----D---- C:\Program Files (x86)\YoutubeAdBlocke
2014-12-03 08:17:16 ----D---- C:\ProgramData\ncfnhhjacephkbmcmanplgkelpmncbba
2014-12-03 08:13:07 ----D---- C:\ProgramData\moiflmcepnmeogbnogkidklbilimgmmh
2014-12-01 23:18:54 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-11-29 15:03:30 ----D---- C:\NVIDIA
======List of files/folders modified in the last 1 month======
2014-12-25 15:13:10 ----D---- C:\Windows\Prefetch
2014-12-25 15:13:08 ----D---- C:\Windows\Temp
2014-12-25 15:13:05 ----RD---- C:\Program Files
2014-12-25 15:12:58 ----D---- C:\Users\Adka\AppData\Roaming\uTorrent
2014-12-25 12:40:33 ----D---- C:\Windows\system32\config
2014-12-25 12:29:12 ----D---- C:\Windows\System32
2014-12-24 03:32:19 ----D---- C:\Windows\system32\catroot
2014-12-23 22:16:43 ----SHD---- C:\Windows\Installer
2014-12-23 22:16:30 ----D---- C:\Windows\SysWOW64
2014-12-23 22:16:26 ----D---- C:\Windows\system32\drivers
2014-12-23 22:15:55 ----HD---- C:\ProgramData
2014-12-23 22:14:19 ----SHD---- C:\System Volume Information
2014-12-23 22:13:38 ----D---- C:\Windows\system32\Tasks
2014-12-23 22:13:33 ----RD---- C:\Program Files (x86)
2014-12-23 22:13:26 ----D---- C:\Windows\system32\DriverStore
2014-12-23 22:13:25 ----D---- C:\Windows\inf
2014-12-23 22:13:11 ----D---- C:\Program Files\Common Files
2014-12-23 22:12:33 ----D---- C:\Program Files (x86)\Common Files
2014-12-23 20:52:49 ----D---- C:\Windows\Help
2014-12-23 20:52:49 ----D---- C:\Program Files\NVIDIA Corporation
2014-12-23 20:52:08 ----D---- C:\ProgramData\NVIDIA Corporation
2014-12-23 20:51:57 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-12-23 20:49:10 ----D---- C:\Windows\system32\catroot2
2014-12-23 20:38:06 ----D---- C:\Windows
2014-12-23 18:50:14 ----D---- C:\Windows\Minidump
2014-12-23 18:00:35 ----D---- C:\ProgramData\EA Logs
2014-12-23 07:07:03 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-12-22 23:39:29 ----SD---- C:\Users\Adka\AppData\Roaming\Microsoft
2014-12-18 22:34:02 ----D---- C:\Windows\winsxs
2014-12-17 08:13:19 ----D---- C:\Windows\system32\LogFiles
2014-12-16 21:31:16 ----D---- C:\Users\Adka\AppData\Roaming\Adobe
2014-12-16 21:14:16 ----RSD---- C:\Windows\Fonts
2014-12-16 20:17:58 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-12-15 12:34:02 ----D---- C:\Windows\system32\wdi
2014-12-13 20:30:31 ----D---- C:\Windows\rescache
2014-12-13 14:35:52 ----D---- C:\Users\Adka\AppData\Roaming\vlc
2014-12-13 03:50:58 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-12-13 03:50:58 ----D---- C:\Windows\system32\cs-CZ
2014-12-13 01:12:24 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2014-12-13 01:12:24 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-12-13 01:12:12 ----A---- C:\Windows\system32\nvspcap64.dll
2014-12-13 01:12:12 ----A---- C:\Windows\system32\nvspbridge64.dll
2014-12-11 18:47:54 ----RSD---- C:\Windows\assembly
2014-12-11 17:39:26 ----D---- C:\Windows\Logs
2014-12-11 08:12:25 ----SD---- C:\Windows\system32\CompatTel
2014-12-11 08:12:25 ----D---- C:\Windows\AppCompat
2014-12-11 08:12:23 ----SD---- C:\ProgramData\Microsoft
2014-12-11 08:12:16 ----D---- C:\Program Files\Internet Explorer
2014-12-11 08:12:14 ----D---- C:\Windows\SYSWOW64\en-US
2014-12-11 08:12:11 ----D---- C:\Windows\PolicyDefinitions
2014-12-11 08:12:10 ----D---- C:\Windows\system32\en-US
2014-12-11 08:12:08 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-11 02:18:28 ----D---- C:\Windows\system32\MRT
2014-12-11 02:15:26 ----D---- C:\Windows\debug
2014-12-11 02:15:21 ----A---- C:\Windows\system32\MRT.exe
2014-12-10 18:02:15 ----D---- C:\Windows\Tasks
2014-12-10 16:59:36 ----D---- C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-16 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-16 267632]
R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2012-11-19 652344]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2012-11-19 28216]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2012-02-26 16152]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2014-12-13 31376]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-11-16 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-22 1050432]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-16 436624]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-11-16 283064]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-16 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-16 83280]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-11-16 116728]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2014-11-16 271752]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2012-03-09 3580928]
R3 BCM42RLY;BCM42RLY; C:\Windows\system32\drivers\BCM42RLY.sys [2014-11-16 22592]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-01-29 5363200]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-10 4731112]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2012-02-26 356120]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2012-02-26 788760]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys [2012-06-02 440360]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-17 62784]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-11-22 38032]
S3 DrvAgent64;DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS [2014-11-17 21712]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2011-05-04 338536]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2014-08-15 54784]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-10-07 60744]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-16 50344]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 FFSOpzSvc;Sleep memory optimizer; C:\Program Files\Sleep Memory Optimizer\FFSService.exe [2011-09-17 141192]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 IAStorDataMgrSvc;Úložná technologie Intel® Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-11-19 14904]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-03-07 2375168]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-12-13 935240]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-11-17 76888]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE [2014-11-16 48128]
R2 ZAtheros Wlan Agent;ZAtheros Wlan Agent; C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe [2012-03-13 76960]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2014-11-16 4012248]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-10-15 643880]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-11-18 833728]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-16 116648]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-23 267440]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2014-12-11 448384]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-01-29 279000]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-11-16 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-11-22 114688]
S3 Origin Client Service;Origin Client Service; D:\Program Files (x86)\Origin\OriginClientService.exe [2014-11-17 1900400]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 SwitchBoard;Adobe SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-11-16 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Re: poprosim kontrolu fb haveď
Zdravim 
V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).
Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Ulozte na plochu zoek.exe http://hijackthis.nl/smeenk/zoek.htm
- ukoncete vsechny programy
- kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
- kliknete na Scan, pote na Clean
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
- spustte jako spravce
- do velkeho okna zkopirujte script uvedeny nize
- kliknete na Run script
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\zoek-results.log) - vlozte mi jej do pristi odpovedi
Kód: Vybrat vše
autoclean; emptyclsid; emptyalltemp;
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: poprosim kontrolu fb haveď
mam tu ešte stary log
# AdwCleaner v4.105 - Report created 10/12/2014 at 18:01:40
# Updated 08/12/2014 by Xplode
# Database : 2014-12-08.2 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Adka - ADKA-PC
# Running from : C:\Users\Adka\Downloads\adwcleaner_4.105.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : Util PodoWeb
[#] Service Deleted : Update PodoWeb
Service Deleted : MaintainerSvc6.89.573444
Service Deleted : {c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\drivergenius
Folder Deleted : C:\ProgramData\9703280295557063155
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\driver genius
Folder Deleted : C:\Program Files (x86)\eSupport.com
[!] Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\PodoWeb
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Users\Adka\AppData\Local\eSupport.com
Folder Deleted : C:\Users\Adka\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Adka\AppData\Roaming\SkypEmoticons
Folder Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\faststartff@gmail.com
Folder Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\B5FX@usUaqVH.net
Folder Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\r@7NnU.net
Folder Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\s@GaCp.edu
Folder Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejddjnilmdncjilbfjgameihlklfpohp
File Deleted : C:\Windows\System32\drivers\{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64.sys
File Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\searchplugins\WebSearch.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\mystartsearch.xml
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal
***** [ Scheduled Tasks ] *****
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : 03028fde-b6ef-4928-878a-0e9ddec76e17-3
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKLM\SOFTWARE\Classes\.
Key Deleted : HKLM\SOFTWARE\Classes\..9
Key Deleted : HKLM\SOFTWARE\Classes\BuyNsave.BuyNsave
Key Deleted : HKLM\SOFTWARE\Classes\BuyNsave.BuyNsave.9
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{fc746929-f2aa-4b41-a3e9-f655f97d7a6c}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{fc746929-f2aa-4b41-a3e9-f655f97d7a6c}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{fc746929-f2aa-4b41-a3e9-f655f97d7a6c}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKCU\Software\eSupport.com
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\Driver-Soft
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\mystartsearchSoftware
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{842C4394-47F7-60DE-480B-C09116B63559}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mystartsearch.com
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v34.0 (x86 sk)
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "mystartsearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename,S", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.searchmania.info/?pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70&l=1&q=");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.order.1", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.order.1,S", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine,S", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.AP2z5BEG50oRZbqe.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.X5zT5WZa3vvp5SKV.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.fXYKRNqIdAJgg1Ds.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("keyword.URL", "hxxp://websearch.searchmania.info/?pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70&l=1&q=");
-\\ Google Chrome v39.0.2171.71
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://websearch.searchmania.info/?l=1&q={searchTerms}&pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : ejddjnilmdncjilbfjgameihlklfpohp
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Homepage] : hxxp://websearch.searchmania.info/?pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://websearch.searchmania.info/?pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70
*************************
AdwCleaner[R0].txt - [14723 octets] - [10/12/2014 17:58:22]
AdwCleaner[S0].txt - [12905 octets] - [10/12/2014 18:01:40]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12966 octets] ##########
aktualne
# AdwCleaner v4.106 - Report created 25/12/2014 at 15:54:16
# Updated 21/12/2014 by Xplode
# Database : 2014-12-21.4 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Adka - ADKA-PC
# Running from : C:\Users\Adka\Downloads\adwcleaner_4.106.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_searches.vi-view.com_0.localstorage-journal
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v34.0 (x86 sk)
-\\ Google Chrome v39.0.2171.71
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
*************************
AdwCleaner[R0].txt - [14723 octets] - [10/12/2014 17:58:22]
AdwCleaner[R1].txt - [1552 octets] - [25/12/2014 15:47:21]
AdwCleaner[R2].txt - [1612 octets] - [25/12/2014 15:50:24]
AdwCleaner[S0].txt - [13103 octets] - [10/12/2014 18:01:40]
AdwCleaner[S1].txt - [1541 octets] - [25/12/2014 15:54:16]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1601 octets] ##########
Zoek.exe v5.0.0.0 Updated 24-12-2014
Tool run by Adka on çt 25. 12. 2014 at 16:01:10,30.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Adka\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
25. 12. 2014 16:03:04 Zoek.exe System Restore Point Created Succesfully.
==== Empty Folders Check ======================
C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~3\ALM deleted successfully
C:\Users\Adka\AppData\Local\GHISLER deleted successfully
C:\Users\Adka\AppData\Local\pangu deleted successfully
C:\Users\Adka\AppData\Local\VirtualStore deleted successfully
C:\Users\Adka\AppData\Local\WarThunder deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
ProfilePath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
user.js not found
---- Lines PodoWeb removed from prefs.js ----
user_pref("extensions.PodoWeb.asul", "1416182667259");
user_pref("extensions.PodoWeb.aul", "1416219662554");
user_pref("extensions.PodoWeb.irl", true);
user_pref("extensions.PodoWeb.is", "smdvsk");
user_pref("extensions.PodoWeb.ug", "E1EDF9DA-1ADE-41B0-9D00-4E71A5AF3CBE");
---- Lines extensions.AP2z5BEG50oRZbqe removed from prefs.js ----
user_pref("extensions.AP2z5BEG50oRZbqe.epoch", "1418281751");
user_pref("extensions.AP2z5BEG50oRZbqe.url", "http://onionbarstar.com/sync2/?q=hfZ9of ... chIC7n0rjn
---- Lines extensions.X5zT5WZa3vvp5SKV removed from prefs.js ----
user_pref("extensions.X5zT5WZa3vvp5SKV.epoch", "1418281750");
user_pref("extensions.X5zT5WZa3vvp5SKV.url", "http://jobur.net/sync2/?q=hfZ9oetKCGhEA ... rjnFrTaHrd
---- Lines extensions.fXYKRNqIdAJgg1Ds removed from prefs.js ----
user_pref("extensions.fXYKRNqIdAJgg1Ds.epoch", "1417959307");
user_pref("extensions.fXYKRNqIdAJgg1Ds.url", "http://jobfirstnet.info/sync2/?q=hfZ9oe ... ShIC7n0rjn
---- FireFox user.js and prefs.js backups ----
prefs_201425.12._1629_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~3\moiflmcepnmeogbnogkidklbilimgmmh deleted
C:\PROGRA~3\ncfnhhjacephkbmcmanplgkelpmncbba deleted
C:\PROGRA~3\01e58235-010d-43b1-8340-277d43a75321 deleted
C:\PROGRA~3\3872871776 deleted
C:\Users\Adka\.android deleted
C:\PROGRA~2\YoutubeAdBlocke deleted
C:\PROGRA~3\Package Cache deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\machine deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
user_pref("browser.startup.homepage", "Google.sk");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [16. 11. 2014 14:34]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
424899266BA430CCE5DDB6C1B4BE1B99 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll - Shockwave Flash
==== Chromium Look ======================
Google Chrome Version: 39.0.2171.71 (Possible outdated, latest Stable version: 39.0.2171.95)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[16. 11. 2014 14:34]
==== Chromium Fix ======================
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.searchmania.info_0.localstorage deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.searchmania.info_0.localstorage-journal deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.publikeco00.publikeco.com_0.localstorage deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.publikeco00.publikeco.com_0.localstorage-journal deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_searches.vi-view.com_0.localstorage deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Adka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Adka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Adka\AppData\Local\Mozilla\Firefox\Profiles\qsecgys1.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=43 folders=23 16345993 bytes)
==== Empty Temp Folders ======================
C:\Users\Adka\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Adka\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on çt 25. 12. 2014 at 16:37:26,27 ======================
# AdwCleaner v4.105 - Report created 10/12/2014 at 18:01:40
# Updated 08/12/2014 by Xplode
# Database : 2014-12-08.2 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Adka - ADKA-PC
# Running from : C:\Users\Adka\Downloads\adwcleaner_4.105.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : Util PodoWeb
[#] Service Deleted : Update PodoWeb
Service Deleted : MaintainerSvc6.89.573444
Service Deleted : {c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\drivergenius
Folder Deleted : C:\ProgramData\9703280295557063155
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\driver genius
Folder Deleted : C:\Program Files (x86)\eSupport.com
[!] Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\PodoWeb
Folder Deleted : C:\Program Files (x86)\SupTab
Folder Deleted : C:\Users\Adka\AppData\Local\eSupport.com
Folder Deleted : C:\Users\Adka\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Adka\AppData\Roaming\SkypEmoticons
Folder Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\faststartff@gmail.com
Folder Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\B5FX@usUaqVH.net
Folder Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\r@7NnU.net
Folder Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\s@GaCp.edu
Folder Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejddjnilmdncjilbfjgameihlklfpohp
File Deleted : C:\Windows\System32\drivers\{c0b542ce-0b43-4536-9ff3-886eaf9fb44c}Gw64.sys
File Deleted : C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\searchplugins\WebSearch.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\mystartsearch.xml
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal
***** [ Scheduled Tasks ] *****
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : 03028fde-b6ef-4928-878a-0e9ddec76e17-3
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKLM\SOFTWARE\Classes\.
Key Deleted : HKLM\SOFTWARE\Classes\..9
Key Deleted : HKLM\SOFTWARE\Classes\BuyNsave.BuyNsave
Key Deleted : HKLM\SOFTWARE\Classes\BuyNsave.BuyNsave.9
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{fc746929-f2aa-4b41-a3e9-f655f97d7a6c}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{fc746929-f2aa-4b41-a3e9-f655f97d7a6c}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{fc746929-f2aa-4b41-a3e9-f655f97d7a6c}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{de206122-b77c-4b04-a28d-f70d6e3c7b1c}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Key Deleted : HKCU\Software\eSupport.com
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\SOFTWARE\Driver-Soft
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\mystartsearchSoftware
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{842C4394-47F7-60DE-480B-C09116B63559}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mystartsearch.com
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v34.0 (x86 sk)
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "mystartsearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename,S", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.defaulturl", "hxxp://websearch.searchmania.info/?pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70&l=1&q=");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.order.1", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.order.1,S", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine,S", "WebSearch");
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.AP2z5BEG50oRZbqe.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.X5zT5WZa3vvp5SKV.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.fXYKRNqIdAJgg1Ds.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.quick_start.enable_search1", false);
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
[qsecgys1.default\prefs.js] - Line Deleted : user_pref("keyword.URL", "hxxp://websearch.searchmania.info/?pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70&l=1&q=");
-\\ Google Chrome v39.0.2171.71
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://websearch.searchmania.info/?l=1&q={searchTerms}&pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : ejddjnilmdncjilbfjgameihlklfpohp
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Homepage] : hxxp://websearch.searchmania.info/?pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Startup_URLs] : hxxp://websearch.searchmania.info/?pid=21073&r=2014/12/03&hid=13199284914318343954&lg=EN&cc=SK&unqvl=70
*************************
AdwCleaner[R0].txt - [14723 octets] - [10/12/2014 17:58:22]
AdwCleaner[S0].txt - [12905 octets] - [10/12/2014 18:01:40]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12966 octets] ##########
aktualne
# AdwCleaner v4.106 - Report created 25/12/2014 at 15:54:16
# Updated 21/12/2014 by Xplode
# Database : 2014-12-21.4 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Adka - ADKA-PC
# Running from : C:\Users\Adka\Downloads\adwcleaner_4.106.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
File Deleted : C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_searches.vi-view.com_0.localstorage-journal
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v34.0 (x86 sk)
-\\ Google Chrome v39.0.2171.71
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
[C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
*************************
AdwCleaner[R0].txt - [14723 octets] - [10/12/2014 17:58:22]
AdwCleaner[R1].txt - [1552 octets] - [25/12/2014 15:47:21]
AdwCleaner[R2].txt - [1612 octets] - [25/12/2014 15:50:24]
AdwCleaner[S0].txt - [13103 octets] - [10/12/2014 18:01:40]
AdwCleaner[S1].txt - [1541 octets] - [25/12/2014 15:54:16]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1601 octets] ##########
Zoek.exe v5.0.0.0 Updated 24-12-2014
Tool run by Adka on çt 25. 12. 2014 at 16:01:10,30.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Adka\Downloads\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
25. 12. 2014 16:03:04 Zoek.exe System Restore Point Created Succesfully.
==== Empty Folders Check ======================
C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~3\ALM deleted successfully
C:\Users\Adka\AppData\Local\GHISLER deleted successfully
C:\Users\Adka\AppData\Local\pangu deleted successfully
C:\Users\Adka\AppData\Local\VirtualStore deleted successfully
C:\Users\Adka\AppData\Local\WarThunder deleted successfully
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
ProfilePath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
user.js not found
---- Lines PodoWeb removed from prefs.js ----
user_pref("extensions.PodoWeb.asul", "1416182667259");
user_pref("extensions.PodoWeb.aul", "1416219662554");
user_pref("extensions.PodoWeb.irl", true);
user_pref("extensions.PodoWeb.is", "smdvsk");
user_pref("extensions.PodoWeb.ug", "E1EDF9DA-1ADE-41B0-9D00-4E71A5AF3CBE");
---- Lines extensions.AP2z5BEG50oRZbqe removed from prefs.js ----
user_pref("extensions.AP2z5BEG50oRZbqe.epoch", "1418281751");
user_pref("extensions.AP2z5BEG50oRZbqe.url", "http://onionbarstar.com/sync2/?q=hfZ9of ... chIC7n0rjn
---- Lines extensions.X5zT5WZa3vvp5SKV removed from prefs.js ----
user_pref("extensions.X5zT5WZa3vvp5SKV.epoch", "1418281750");
user_pref("extensions.X5zT5WZa3vvp5SKV.url", "http://jobur.net/sync2/?q=hfZ9oetKCGhEA ... rjnFrTaHrd
---- Lines extensions.fXYKRNqIdAJgg1Ds removed from prefs.js ----
user_pref("extensions.fXYKRNqIdAJgg1Ds.epoch", "1417959307");
user_pref("extensions.fXYKRNqIdAJgg1Ds.url", "http://jobfirstnet.info/sync2/?q=hfZ9oe ... ShIC7n0rjn
---- FireFox user.js and prefs.js backups ----
prefs_201425.12._1629_.backup
==== Deleting Files \ Folders ======================
C:\PROGRA~3\moiflmcepnmeogbnogkidklbilimgmmh deleted
C:\PROGRA~3\ncfnhhjacephkbmcmanplgkelpmncbba deleted
C:\PROGRA~3\01e58235-010d-43b1-8340-277d43a75321 deleted
C:\PROGRA~3\3872871776 deleted
C:\Users\Adka\.android deleted
C:\PROGRA~2\YoutubeAdBlocke deleted
C:\PROGRA~3\Package Cache deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\machine deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
user_pref("browser.startup.homepage", "Google.sk");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [16. 11. 2014 14:34]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
424899266BA430CCE5DDB6C1B4BE1B99 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll - Shockwave Flash
==== Chromium Look ======================
Google Chrome Version: 39.0.2171.71 (Possible outdated, latest Stable version: 39.0.2171.95)
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[16. 11. 2014 14:34]
==== Chromium Fix ======================
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.searchmania.info_0.localstorage deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.searchmania.info_0.localstorage-journal deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.publikeco00.publikeco.com_0.localstorage deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.publikeco00.publikeco.com_0.localstorage-journal deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_searches.vi-view.com_0.localstorage deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage deleted successfully
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Adka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Adka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Adka\AppData\Local\Mozilla\Firefox\Profiles\qsecgys1.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
No Java Cache Found
==== C:\zoek_backup content ======================
C:\zoek_backup (files=43 folders=23 16345993 bytes)
==== Empty Temp Folders ======================
C:\Users\Adka\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\Adka\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on çt 25. 12. 2014 at 16:37:26,27 ======================
Re: poprosim kontrolu fb haveď
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: poprosim kontrolu fb haveď
ano chapem ten prvy log je stary ale zanim je hned ten novy čo som aj dneska stiahol a urobil scan
Re: poprosim kontrolu fb haveď
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: poprosim kontrolu fb haveď
vyzera v pohode .. pri použivani chrome furt zachytaval atnivirak nejaku haveď teraz už je ticho ..
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-12-2014
Ran by Adka (administrator) on ADKA-PC on 25-12-2014 17:53:39
Running from C:\Users\Adka\Desktop
Loaded Profile: Adka (Available profiles: Adka)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\BCMWLTRY.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Acer Incorporated) C:\Program Files\Sleep Memory Optimizer\FFSService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Atheros) C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(forum.viry.cz) C:\Users\Adka\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [7144960 2014-11-16] (Broadcom Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12445288 2012-01-10] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2014-12-12] (AVAST Software)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-11-19] (Intel Corporation)
HKLM-x32\...\Run: [DriverChecker.exe] => C:\Program Files (x86)\Driver Checker\DriverChecker.exe [11707336 2012-11-08] ()
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => D:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [**e©Kű¨**ˇ<*>] => C:\Program Files (x86)\Tongbu\tbMobileService.exe /start <===== ATTENTION (Value Name with invalid characters)
AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178632 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: ,C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3385117169-3715099472-58281317-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: ͬ˛˝Ň»Ľü°˛×°Ö§łÖ -> {F72C8153-7140-4FEE-8F69-CA4579D71195} -> C:\Program Files (x86)\Tongbu\Addin\tbIEAddin.dll (同步网络平台)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - D:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
FF Homepage: Google.sk
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll ()
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> D:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tongbu.com/tongbu,version=0.1 -> C:\Program Files (x86)\Tongbu\Addin\npTongbuAddin.dll (同步网络平台)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: Adblock Plus - C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-16]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-16]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR DefaultSearchKeyword: Default -> mystartsearch
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Peněženka Google) - C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-16]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-16]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-16] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-16] (Avast Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2014-12-11] ()
R2 FFSOpzSvc; C:\Program Files\Sleep Memory Optimizer\FFSService.exe [141192 2011-09-17] (Acer Incorporated)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2375168 2011-03-07] (Realsil Microelectronics Inc.) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
S3 Origin Client Service; D:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-17] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-11-17] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe [5836800 2014-11-16] (Broadcom Corporation) [File not signed]
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe [76960 2012-03-13] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-16] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-16] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-16] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-16] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-16] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-16] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-16] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-11-16] (Disc Soft Ltd)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-11-19] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-16] (Avast Software)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-25 17:53 - 2014-12-25 17:54 - 00015328 _____ () C:\Users\Adka\Desktop\FRST.txt
2014-12-25 17:53 - 2014-12-25 17:53 - 00000000 ____D () C:\FRST
2014-12-25 17:52 - 2014-12-25 17:52 - 00112640 _____ (forum.viry.cz) C:\Users\Adka\Desktop\FRSTLauncher.exe
2014-12-25 17:50 - 2014-12-25 17:50 - 02122240 _____ (Farbar) C:\Users\Adka\Desktop\FRST64.exe
2014-12-25 16:39 - 2014-12-25 16:39 - 00000197 _____ () C:\Windows\system32\2014-12-25-15-39-09.098-AvastVBoxSVC.exe-3388.log
2014-12-25 16:37 - 2014-12-25 16:37 - 00000000 ____D () C:\Users\Adka\AppData\Local\VirtualStore
2014-12-25 16:35 - 2014-12-25 16:00 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-12-25 16:02 - 2014-12-25 16:37 - 00009655 _____ () C:\zoek-results.log
2014-12-25 16:00 - 2014-12-25 16:32 - 00000000 ____D () C:\zoek_backup
2014-12-25 16:00 - 2014-12-25 16:00 - 01295360 _____ () C:\Users\Adka\Downloads\zoek.exe
2014-12-25 15:59 - 2014-12-25 15:59 - 00000197 _____ () C:\Windows\system32\2014-12-25-14-59-26.004-AvastVBoxSVC.exe-3600.log
2014-12-25 15:41 - 2014-12-25 15:41 - 02173952 _____ () C:\Users\Adka\Downloads\adwcleaner_4.106.exe
2014-12-25 15:27 - 2014-12-25 15:46 - 00000000 ____D () C:\Program Files (x86)\Tongbu
2014-12-25 15:27 - 2014-12-25 15:42 - 00000000 ____D () C:\Users\Adka\Documents\Tongbu
2014-12-25 15:27 - 2014-12-25 15:37 - 00001895 _____ () C:\Users\Public\Desktop\Tongbu Assistant.lnk
2014-12-25 15:27 - 2014-12-25 15:27 - 00001234 _____ () C:\Users\Public\Desktop\Game Center.lnk
2014-12-25 15:27 - 2014-12-25 15:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tongbu Network
2014-12-25 15:26 - 2014-12-25 15:26 - 22863792 _____ () C:\Users\Adka\Downloads\Tongbu_Setup_2.2.3_zsgw.exe
2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\rsit
2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\Program Files\trend micro
2014-12-25 15:12 - 2014-12-25 15:13 - 01222144 _____ () C:\Users\Adka\Downloads\RSITx64.exe
2014-12-25 14:52 - 2014-12-25 14:52 - 00017471 _____ () C:\Users\Adka\Downloads\Minecraft_-_Pocket_Edition_(v.0.94)_[iOS_Game]_[English].ipa.torrent
2014-12-25 14:20 - 2014-12-25 14:23 - 13479310 _____ () C:\Users\Adka\Downloads\Minecraft---Pocket-Edition-APK-0.9.5-CRACKED_downloadapks.org.apk
2014-12-25 12:29 - 2014-12-25 12:29 - 00000197 _____ () C:\Windows\system32\2014-12-25-11-29-12.084-AvastVBoxSVC.exe-1608.log
2014-12-25 03:03 - 2014-12-25 03:03 - 00000197 _____ () C:\Windows\system32\2014-12-25-02-03-25.031-AvastVBoxSVC.exe-3204.log
2014-12-24 21:59 - 2014-12-24 21:59 - 00007609 _____ () C:\Users\Adka\AppData\Local\Resmon.ResmonCfg
2014-12-24 13:03 - 2014-12-25 15:00 - 00000000 ____D () C:\Users\Adka\Desktop\iPod Photo Cache
2014-12-24 13:03 - 2014-12-24 13:04 - 00000000 ____D () C:\Users\Adka\Desktop\Nová složka
2014-12-24 10:17 - 2014-12-24 10:17 - 00000197 _____ () C:\Windows\system32\2014-12-24-09-17-27.027-AvastVBoxSVC.exe-3168.log
2014-12-24 01:53 - 2014-12-24 01:53 - 00000197 _____ () C:\Windows\system32\2014-12-24-00-53-32.006-AvastVBoxSVC.exe-3928.log
2014-12-23 22:45 - 2014-12-23 22:47 - 173016004 _____ () C:\Users\Adka\Downloads\87e5ec2626b9931aeecdc67f81c971c3e468e727.ipa
2014-12-23 22:21 - 2014-12-23 22:21 - 09716132 _____ () C:\Users\Adka\Downloads\605cc375669ecff7c3db587ec05371407148c6f5.ipa
2014-12-23 22:16 - 2014-12-23 22:25 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Apple Computer
2014-12-23 22:16 - 2014-12-23 22:16 - 00000000 ____D () C:\Users\Adka\AppData\Local\Apple Computer
2014-12-23 22:16 - 2014-12-23 22:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-12-23 22:16 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2014-12-23 22:15 - 2014-12-23 22:16 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-12-23 22:15 - 2014-12-23 22:16 - 00000000 ____D () C:\Program Files\iTunes
2014-12-23 22:15 - 2014-12-23 22:15 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-12-23 22:15 - 2014-12-23 22:15 - 00000000 ____D () C:\Program Files\iPod
2014-12-23 22:13 - 2014-12-23 22:15 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-12-23 22:13 - 2014-12-23 22:13 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-12-23 22:13 - 2014-12-23 22:13 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-12-23 22:13 - 2014-12-23 22:13 - 00000000 ____D () C:\Users\Adka\AppData\Local\Apple
2014-12-23 22:13 - 2014-12-23 22:13 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-12-23 22:12 - 2014-12-23 22:13 - 00000000 ____D () C:\ProgramData\Apple
2014-12-23 22:12 - 2014-12-23 22:12 - 00000000 ____D () C:\Program Files\Bonjour
2014-12-23 22:12 - 2014-12-23 22:12 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-12-23 22:10 - 2014-12-23 22:10 - 122418480 _____ (Apple Inc.) C:\Users\Adka\Downloads\iTunes64Setup.exe
2014-12-23 20:57 - 2014-12-23 20:57 - 00000197 _____ () C:\Windows\system32\2014-12-23-19-57-07.023-AvastVBoxSVC.exe-3328.log
2014-12-23 20:54 - 2014-12-23 20:54 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-12-23 20:54 - 2014-12-23 20:54 - 00000000 ____D () C:\Windows\system32\NV
2014-12-23 20:54 - 2014-12-23 20:54 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-12-23 20:52 - 2014-12-13 11:08 - 00074056 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-12-23 20:52 - 2014-12-13 11:08 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 06859408 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 03513488 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 02558608 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 01097360 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 00935240 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-12-23 20:52 - 2014-12-13 09:03 - 00386368 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 00075080 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-12-23 20:52 - 2014-12-13 00:11 - 04151176 _____ () C:\Windows\system32\nvcoproc.bin
2014-12-23 20:51 - 2014-12-23 20:51 - 00000197 _____ () C:\Windows\system32\2014-12-23-19-51-06.016-AvastVBoxSVC.exe-2760.log
2014-12-23 20:45 - 2014-12-13 11:08 - 32099472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 25460552 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 24764232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 20465808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 18594432 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 17264312 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 16040184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 14128496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 13288360 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 13202520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 10770120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 10710160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 10345280 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-12-23 20:45 - 2014-12-13 11:08 - 03610440 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 03293136 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 03248968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 02897824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 01895056 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434709.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 01556624 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434709.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00994384 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00968336 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00942400 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00928072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00906560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00876976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00496272 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00399688 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00391488 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00353224 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00346944 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00306328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00178632 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00165760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00031376 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2014-12-23 20:45 - 2014-12-13 11:08 - 00027983 _____ () C:\Windows\system32\nvinfo.pb
2014-12-23 18:52 - 2014-12-23 18:52 - 00000197 _____ () C:\Windows\system32\2014-12-23-17-52-53.007-AvastVBoxSVC.exe-3220.log
2014-12-23 18:50 - 2014-12-23 18:50 - 00734728 _____ () C:\Windows\Minidump\122314-28610-01.dmp
2014-12-23 18:00 - 2014-12-23 22:53 - 00000000 ___RD () C:\Users\Adka\Desktop\bordel
2014-12-23 09:06 - 2014-12-23 09:06 - 00000197 _____ () C:\Windows\system32\2014-12-23-08-06-20.037-AvastVBoxSVC.exe-3500.log
2014-12-23 07:07 - 2014-12-23 07:07 - 00000197 _____ () C:\Windows\system32\2014-12-23-06-07-23.057-AvastVBoxSVC.exe-3288.log
2014-12-22 08:07 - 2014-12-22 08:07 - 00000197 _____ () C:\Windows\system32\2014-12-22-07-07-48.007-AvastVBoxSVC.exe-3236.log
2014-12-21 16:10 - 2014-12-21 16:10 - 00000197 _____ () C:\Windows\system32\2014-12-21-15-10-07.068-AvastVBoxSVC.exe-3828.log
2014-12-20 10:40 - 2014-12-20 10:40 - 00000197 _____ () C:\Windows\system32\2014-12-20-09-40-41.064-AvastVBoxSVC.exe-3196.log
2014-12-19 10:53 - 2014-12-19 10:53 - 00000197 _____ () C:\Windows\system32\2014-12-19-09-53-19.003-AvastVBoxSVC.exe-3672.log
2014-12-18 08:50 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 08:50 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-18 08:44 - 2014-12-18 08:45 - 00000197 _____ () C:\Windows\system32\2014-12-18-07-44-42.068-AvastVBoxSVC.exe-4620.log
2014-12-17 13:27 - 2014-12-17 13:27 - 00000197 _____ () C:\Windows\system32\2014-12-17-12-27-17.088-AvastVBoxSVC.exe-3324.log
2014-12-17 08:21 - 2014-12-17 08:21 - 00000197 _____ () C:\Windows\system32\2014-12-17-07-21-08.031-AvastVBoxSVC.exe-3200.log
2014-12-16 21:28 - 2014-12-16 21:28 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-12-16 21:22 - 2014-12-16 21:22 - 00000000 ____D () C:\Program Files\Adobe
2014-12-16 21:15 - 2014-12-16 21:15 - 00001097 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
2014-12-16 21:11 - 2014-12-16 21:15 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-12-16 21:11 - 2014-12-16 21:11 - 00000997 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2014-12-16 21:11 - 2014-12-16 21:11 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-12-16 21:11 - 2014-12-16 21:11 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-12-16 21:08 - 2014-12-16 21:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
2014-12-16 21:07 - 2014-12-16 21:26 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-12-16 20:58 - 2014-12-16 21:28 - 00000000 ____D () C:\ProgramData\Adobe
2014-12-16 20:58 - 2014-12-16 20:58 - 00000197 _____ () C:\Windows\system32\2014-12-16-19-58-18.013-AvastVBoxSVC.exe-3200.log
2014-12-16 20:57 - 2014-12-23 07:09 - 00000000 ____D () C:\Users\Adka\AppData\Local\Adobe
2014-12-16 18:49 - 2014-11-22 11:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-12-16 18:49 - 2014-11-22 11:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-12-16 12:06 - 2014-12-16 12:06 - 04645006 _____ () C:\Users\Adka\Downloads\zoznam_dlznikov_20_11_2014.zip
2014-12-16 08:01 - 2014-12-16 08:01 - 00000197 _____ () C:\Windows\system32\2014-12-16-07-01-39.077-AvastVBoxSVC.exe-3200.log
2014-12-15 08:36 - 2014-12-15 08:37 - 00000247 _____ () C:\Windows\system32\2014-12-15-07-36-59.034-aswFe.exe-1944.log
2014-12-15 08:30 - 2014-12-15 08:36 - 00000247 _____ () C:\Windows\system32\2014-12-15-07-30-50.016-aswFe.exe-2640.log
2014-12-15 08:30 - 2014-12-15 08:30 - 00000197 _____ () C:\Windows\system32\2014-12-15-07-30-43.047-AvastVBoxSVC.exe-5448.log
2014-12-14 22:53 - 2014-12-14 22:53 - 00000197 _____ () C:\Windows\system32\2014-12-14-21-53-00.054-AvastVBoxSVC.exe-3192.log
2014-12-14 05:03 - 2014-12-14 05:03 - 00000197 _____ () C:\Windows\system32\2014-12-14-04-03-00.048-AvastVBoxSVC.exe-3132.log
2014-12-13 19:12 - 2014-12-13 19:12 - 00000000 ____D () C:\Users\Adka\Documents\Vlastní šablony Office
2014-12-13 16:42 - 2014-12-13 16:42 - 00000000 __RHD () C:\MSOCache
2014-12-13 16:37 - 2014-12-25 17:02 - 00004948 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Adka-PC-Adka Adka-PC
2014-12-13 15:26 - 2014-12-13 15:26 - 00000230 _____ () C:\Users\Adka\Desktop\Mobil Adri Kallistofatře Kallová.URL
2014-12-13 11:41 - 2014-12-13 11:42 - 00000197 _____ () C:\Windows\system32\2014-12-13-10-41-32.084-AvastVBoxSVC.exe-3076.log
2014-12-13 03:52 - 2014-12-13 03:53 - 00000197 _____ () C:\Windows\system32\2014-12-13-02-52-47.089-AvastVBoxSVC.exe-2240.log
2014-12-12 07:57 - 2014-12-12 07:57 - 00000197 _____ () C:\Windows\system32\2014-12-12-06-57-37.095-AvastVBoxSVC.exe-4004.log
2014-12-11 17:39 - 2014-12-11 18:48 - 00018189 _____ () C:\Windows\DirectX.log
2014-12-11 16:42 - 2014-12-11 16:42 - 00000197 _____ () C:\Windows\system32\2014-12-11-15-42-27.041-AvastVBoxSVC.exe-3224.log
2014-12-11 08:16 - 2014-12-11 08:16 - 00000197 _____ () C:\Windows\system32\2014-12-11-07-16-25.079-AvastVBoxSVC.exe-2884.log
2014-12-11 08:12 - 2014-12-11 08:12 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-11 02:14 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-11 02:14 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-11 02:14 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-11 02:14 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-11 02:14 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-11 02:14 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-11 02:14 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-11 02:14 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-11 02:14 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-11 02:13 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-11 02:01 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-11 02:01 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-11 02:01 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-11 02:01 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-11 02:01 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-11 02:01 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-11 02:01 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-11 02:01 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-11 02:01 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-11 02:01 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-11 02:01 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-11 02:01 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-11 02:01 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-11 02:01 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-11 02:01 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-11 02:01 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-11 02:01 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-11 02:01 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-11 02:01 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-11 02:01 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-11 02:01 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-11 02:01 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-11 02:01 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-11 02:01 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-11 02:01 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-11 02:01 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-11 02:01 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-11 02:01 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-11 02:01 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-11 02:01 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-11 02:01 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-11 02:01 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-11 02:01 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-11 02:01 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-11 02:01 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-11 02:01 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-11 02:01 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-11 02:01 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-11 02:01 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-11 02:01 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-11 02:01 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-11 02:01 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-11 02:01 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-11 02:01 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-11 02:01 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-11 02:01 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-11 02:01 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-11 02:01 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-11 02:01 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-11 02:01 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-11 02:01 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-11 02:01 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-11 02:01 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-11 02:01 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-11 02:01 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-11 02:01 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-11 02:01 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-11 02:00 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-11 02:00 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-11 02:00 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-11 02:00 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-11 02:00 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-11 02:00 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-11 02:00 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-11 02:00 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-11 02:00 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-11 02:00 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-11 02:00 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-11 02:00 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-11 02:00 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-11 02:00 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-11 02:00 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-11 02:00 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-11 01:56 - 2014-12-11 01:56 - 00000197 _____ () C:\Windows\system32\2014-12-11-00-56-20.037-AvastVBoxSVC.exe-3700.log
2014-12-10 18:06 - 2014-12-10 18:06 - 00000197 _____ () C:\Windows\system32\2014-12-10-17-06-33.050-AvastVBoxSVC.exe-3972.log
2014-12-10 18:01 - 2014-12-10 18:02 - 00013103 _____ () C:\Users\Adka\Desktop\AdwCleaner[S0].txt
2014-12-10 17:58 - 2014-12-25 15:54 - 00000000 ____D () C:\AdwCleaner
2014-12-10 17:58 - 2014-12-10 17:58 - 02166272 _____ () C:\Users\Adka\Downloads\adwcleaner_4.105.exe
2014-12-10 16:59 - 2014-12-10 17:00 - 00000197 _____ () C:\Windows\system32\2014-12-10-15-59-41.012-AvastVBoxSVC.exe-3488.log
2014-12-10 08:19 - 2014-12-10 08:19 - 00000197 _____ () C:\Windows\system32\2014-12-10-07-19-11.093-AvastVBoxSVC.exe-4340.log
2014-12-10 08:08 - 2014-12-10 08:08 - 00000197 _____ () C:\Windows\system32\2014-12-10-07-08-13.098-AvastVBoxSVC.exe-4048.log
2014-12-09 23:17 - 2014-12-09 23:17 - 00000197 _____ () C:\Windows\system32\2014-12-09-22-17-42.068-AvastVBoxSVC.exe-3216.log
2014-12-09 17:31 - 2014-12-09 17:31 - 00000197 _____ () C:\Windows\system32\2014-12-09-16-31-12.059-AvastVBoxSVC.exe-3624.log
2014-12-09 08:04 - 2014-12-09 08:04 - 00000197 _____ () C:\Windows\system32\2014-12-09-07-04-52.006-AvastVBoxSVC.exe-4156.log
2014-12-09 00:21 - 2014-12-21 16:28 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-12-08 23:43 - 2014-12-08 23:43 - 00000197 _____ () C:\Windows\system32\2014-12-08-22-43-04.012-AvastVBoxSVC.exe-4660.log
2014-12-08 08:08 - 2014-12-08 08:08 - 00000197 _____ () C:\Windows\system32\2014-12-08-07-08-40.092-AvastVBoxSVC.exe-3536.log
2014-12-07 13:13 - 2014-12-25 16:44 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-12-07 13:13 - 2014-12-07 13:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-12-07 13:12 - 2014-12-07 13:12 - 01142392 _____ () C:\Users\Adka\Downloads\SteamSetup(1).exe
2014-12-07 11:26 - 2014-12-07 11:27 - 00000247 _____ () C:\Windows\system32\2014-12-07-10-26-56.032-aswFe.exe-2272.log
2014-12-07 11:21 - 2014-12-07 11:26 - 00000247 _____ () C:\Windows\system32\2014-12-07-10-21-02.046-aswFe.exe-632.log
2014-12-07 11:20 - 2014-12-07 11:20 - 00000197 _____ () C:\Windows\system32\2014-12-07-10-20-55.053-AvastVBoxSVC.exe-5972.log
2014-12-07 04:00 - 2014-12-07 04:00 - 00000197 _____ () C:\Windows\system32\2014-12-07-03-00-28.085-AvastVBoxSVC.exe-4216.log
2014-12-06 22:43 - 2014-12-06 22:43 - 00000197 _____ () C:\Windows\system32\2014-12-06-21-43-23.029-AvastVBoxSVC.exe-4248.log
2014-12-06 16:01 - 2014-12-06 16:01 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunderDev
2014-12-06 16:01 - 2014-12-06 16:01 - 00000000 ____D () C:\ProgramData\WarThunder
2014-12-06 16:00 - 2014-12-06 16:01 - 04086008 _____ (Gaijin Entertainment ) C:\Users\Adka\Downloads\wt_dev_launcher.exe
2014-12-06 14:22 - 2014-12-06 14:23 - 00000197 _____ () C:\Windows\system32\2014-12-06-13-22-49.059-AvastVBoxSVC.exe-4620.log
2014-12-05 17:19 - 2014-12-05 17:19 - 00000197 _____ () C:\Windows\system32\2014-12-05-16-19-23.029-AvastVBoxSVC.exe-4204.log
2014-12-05 15:04 - 2014-12-05 15:05 - 00000197 _____ () C:\Windows\system32\2014-12-05-14-04-49.036-AvastVBoxSVC.exe-3892.log
2014-12-05 07:23 - 2014-12-05 07:23 - 00000197 _____ () C:\Windows\system32\2014-12-05-06-23-42.046-AvastVBoxSVC.exe-3744.log
2014-12-04 15:42 - 2014-12-04 15:42 - 00000197 _____ () C:\Windows\system32\2014-12-04-14-42-03.092-AvastVBoxSVC.exe-4388.log
2014-12-04 07:10 - 2014-12-04 07:10 - 00000197 _____ () C:\Windows\system32\2014-12-04-06-10-39.039-AvastVBoxSVC.exe-3504.log
2014-12-03 18:06 - 2014-12-03 18:07 - 00000197 _____ () C:\Windows\system32\2014-12-03-17-06-49.035-AvastVBoxSVC.exe-4092.log
2014-12-03 08:30 - 2014-12-03 08:31 - 00000197 _____ () C:\Windows\system32\2014-12-03-07-30-45.088-AvastVBoxSVC.exe-4616.log
2014-12-03 08:23 - 2014-12-23 11:57 - 00000000 ____D () C:\Users\Adka\Desktop\LILA
2014-12-03 08:12 - 2014-12-03 08:12 - 01024368 _____ () C:\Users\Adka\Downloads\zeds dead dirtyphonics where are you now ft bright lights 320 kbps tags cover t9631125.exe
2014-12-03 07:37 - 2014-12-03 07:37 - 00000197 _____ () C:\Windows\system32\2014-12-03-06-37-31.088-AvastVBoxSVC.exe-2576.log
2014-12-02 19:13 - 2014-12-02 19:13 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Forest 1.0
2014-12-02 17:45 - 2014-12-02 17:46 - 00000197 _____ () C:\Windows\system32\2014-12-02-16-45-45.029-AvastVBoxSVC.exe-524.log
2014-12-02 08:12 - 2014-12-02 08:13 - 00000197 _____ () C:\Windows\system32\2014-12-02-07-12-25.096-AvastVBoxSVC.exe-3424.log
2014-12-01 23:18 - 2014-12-01 23:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-01 17:31 - 2014-12-01 17:31 - 00000197 _____ () C:\Windows\system32\2014-12-01-16-31-56.016-AvastVBoxSVC.exe-4624.log
2014-12-01 08:24 - 2014-12-01 08:24 - 00000197 _____ () C:\Windows\system32\2014-12-01-07-24-03.071-AvastVBoxSVC.exe-2680.log
2014-11-30 11:21 - 2014-11-30 11:21 - 00000197 _____ () C:\Windows\system32\2014-11-30-10-21-15.061-AvastVBoxSVC.exe-4188.log
2014-11-30 03:04 - 2014-11-30 03:04 - 00000197 _____ () C:\Windows\system32\2014-11-30-02-04-13.008-AvastVBoxSVC.exe-4224.log
2014-11-29 15:21 - 2014-11-29 15:21 - 00000197 _____ () C:\Windows\system32\2014-11-29-14-21-00.040-AvastVBoxSVC.exe-3596.log
2014-11-29 15:13 - 2014-11-29 15:13 - 00000197 _____ () C:\Windows\system32\2014-11-29-14-13-19.059-AvastVBoxSVC.exe-3080.log
2014-11-29 15:03 - 2014-11-29 15:03 - 00000000 ____D () C:\NVIDIA
2014-11-29 14:58 - 2014-11-29 15:01 - 308364224 _____ (NVIDIA Corporation) C:\Users\Adka\Downloads\344.75-notebook-win8-win7-64bit-international-whql.exe
2014-11-29 13:54 - 2014-11-29 13:54 - 00000197 _____ () C:\Windows\system32\2014-11-29-12-54-03.068-AvastVBoxSVC.exe-3848.log
2014-11-28 09:12 - 2014-11-28 09:12 - 00000197 _____ () C:\Windows\system32\2014-11-28-08-12-20.015-AvastVBoxSVC.exe-3324.log
2014-11-27 20:30 - 2014-11-28 14:56 - 00000000 ____D () C:\Users\Adka\Desktop\Adulik
2014-11-27 09:37 - 2014-11-27 09:37 - 00000197 _____ () C:\Windows\system32\2014-11-27-08-37-54.059-AvastVBoxSVC.exe-3572.log
2014-11-26 18:21 - 2014-11-26 18:23 - 10420018 _____ () C:\Users\Adka\Downloads\Patch to v46.1.zip
2014-11-26 17:53 - 2014-11-26 17:53 - 00003146 _____ () C:\Windows\System32\Tasks\{99B64EC8-C64D-43FA-8D12-A74FCE02A380}
2014-11-26 09:38 - 2014-11-26 09:38 - 00000197 _____ () C:\Windows\system32\2014-11-26-08-38-43.098-AvastVBoxSVC.exe-3476.log
2014-11-26 09:36 - 2014-12-25 16:36 - 00015256 _____ () C:\Windows\setupact.log
2014-11-26 09:36 - 2014-12-25 16:36 - 00003114 _____ () C:\Windows\PFRO.log
2014-11-26 09:36 - 2014-11-26 09:36 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-25 13:25 - 2014-11-25 13:25 - 00000197 _____ () C:\Windows\system32\2014-11-25-12-25-05.025-AvastVBoxSVC.exe-3408.log
2014-11-25 13:19 - 2014-11-25 13:19 - 00000000 ____D () C:\Program Files (x86)\CinemaP-1.3c
2014-11-25 13:16 - 2014-11-25 13:16 - 00593608 _____ () C:\Users\Adka\Downloads\Hay Day Windows Installer__8715_il1978.exe
2014-11-25 09:53 - 2014-11-25 09:53 - 00000000 __SHD () C:\Users\Adka\AppData\Local\EmieUserList
2014-11-25 09:53 - 2014-11-25 09:53 - 00000000 __SHD () C:\Users\Adka\AppData\Local\EmieSiteList
2014-11-25 09:53 - 2014-11-25 09:53 - 00000000 __SHD () C:\Users\Adka\AppData\Local\EmieBrowserModeList
2014-11-25 09:10 - 2014-11-25 09:10 - 00000197 _____ () C:\Windows\system32\2014-11-25-08-10-30.088-AvastVBoxSVC.exe-3872.log
2014-11-25 00:23 - 2014-11-25 00:23 - 00000197 _____ () C:\Windows\system32\2014-11-24-23-23-04.001-AvastVBoxSVC.exe-3608.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-25 17:37 - 2014-11-16 14:42 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-25 16:44 - 2009-07-14 05:45 - 00028928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-25 16:44 - 2009-07-14 05:45 - 00028928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-25 16:43 - 2014-11-16 23:41 - 00000000 ____D () C:\Users\Adka\AppData\Local\DayZ
2014-12-25 16:40 - 2014-11-16 14:31 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-25 16:40 - 2014-11-16 12:38 - 01342170 _____ () C:\Windows\WindowsUpdate.log
2014-12-25 16:37 - 2014-11-16 18:38 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-12-25 16:36 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-25 16:30 - 2014-11-16 12:47 - 00000000 ____D () C:\Users\Adka
2014-12-25 16:30 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2014-12-25 15:47 - 2014-11-16 14:59 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\uTorrent
2014-12-24 10:17 - 2014-11-16 14:31 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-12-23 20:52 - 2014-11-16 14:14 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-12-23 20:52 - 2014-11-16 14:14 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-12-23 20:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help
2014-12-23 20:51 - 2014-11-16 14:14 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-12-23 18:50 - 2014-11-16 15:05 - 00000000 ____D () C:\Windows\Minidump
2014-12-23 07:07 - 2014-11-16 14:42 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-23 07:07 - 2014-11-16 14:42 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-23 07:07 - 2014-11-16 14:42 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-17 08:18 - 2009-07-14 05:45 - 04938752 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-16 21:31 - 2014-11-16 14:43 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Adobe
2014-12-16 21:30 - 2014-11-16 13:16 - 00070376 _____ () C:\Users\Adka\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-16 20:17 - 2011-04-12 09:34 - 00661266 _____ () C:\Windows\system32\perfh005.dat
2014-12-16 20:17 - 2011-04-12 09:34 - 00141414 _____ () C:\Windows\system32\perfc005.dat
2014-12-16 20:17 - 2009-07-14 06:13 - 01585684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-14 05:01 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-12-13 20:30 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-13 14:35 - 2014-11-16 14:47 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\vlc
2014-12-13 01:12 - 2014-11-16 19:01 - 02824504 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-12-13 01:12 - 2014-11-16 19:01 - 02210040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-12-13 01:12 - 2014-11-16 19:01 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-12-13 01:12 - 2014-11-16 19:01 - 01291464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-12-11 08:12 - 2014-11-16 18:27 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-11 08:12 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-11 08:12 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-11 02:18 - 2014-11-16 14:28 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-11 02:15 - 2014-11-16 14:28 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-29 15:17 - 2014-11-16 19:25 - 00001347 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk
2014-11-26 21:17 - 2014-11-22 16:46 - 00000000 ____D () C:\Users\Adka\Documents\DayZ
2014-11-26 18:01 - 2014-11-16 13:46 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-26 18:01 - 2014-11-16 13:46 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-26 18:01 - 2014-11-16 12:48 - 00001393 _____ () C:\Users\Adka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-25 16:32 - 2014-11-16 12:34 - 00000000 ____D () C:\Windows\Panther
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Users\Adka\Downloads\Hay Day Windows Installer__8715_il1978.exe:typelib
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Adka\Desktop" je 36 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring
"C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM
"D:\Program Files (x86)\Origin\Origin.exe" -AutoStart [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-12-2014
Ran by Adka (administrator) on ADKA-PC on 25-12-2014 17:53:39
Running from C:\Users\Adka\Desktop
Loaded Profile: Adka (Available profiles: Adka)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\BCMWLTRY.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Acer Incorporated) C:\Program Files\Sleep Memory Optimizer\FFSService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Atheros) C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Broadcom Corporation) C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(forum.viry.cz) C:\Users\Adka\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [7144960 2014-11-16] (Broadcom Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12445288 2012-01-10] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2014-12-12] (AVAST Software)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-11-19] (Intel Corporation)
HKLM-x32\...\Run: [DriverChecker.exe] => C:\Program Files (x86)\Driver Checker\DriverChecker.exe [11707336 2012-11-08] ()
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-26] (Intel Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => D:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [**e©Kű¨**ˇ<*>] => C:\Program Files (x86)\Tongbu\tbMobileService.exe /start <===== ATTENTION (Value Name with invalid characters)
AppInit_DLLs: ,C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178632 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: ,C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3385117169-3715099472-58281317-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: ͬ˛˝Ň»Ľü°˛×°Ö§łÖ -> {F72C8153-7140-4FEE-8F69-CA4579D71195} -> C:\Program Files (x86)\Tongbu\Addin\tbIEAddin.dll (同步网络平台)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - D:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default
FF Homepage: Google.sk
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll ()
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> D:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tongbu.com/tongbu,version=0.1 -> C:\Program Files (x86)\Tongbu\Addin\npTongbuAddin.dll (同步网络平台)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: Adblock Plus - C:\Users\Adka\AppData\Roaming\Mozilla\Firefox\Profiles\qsecgys1.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-16]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-16]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR DefaultSearchKeyword: Default -> mystartsearch
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Peněženka Google) - C:\Users\Adka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-16]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-16]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-16] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-16] (Avast Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2014-12-11] ()
R2 FFSOpzSvc; C:\Program Files\Sleep Memory Optimizer\FFSService.exe [141192 2011-09-17] (Acer Incorporated)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2375168 2011-03-07] (Realsil Microelectronics Inc.) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
S3 Origin Client Service; D:\Program Files (x86)\Origin\OriginClientService.exe [1900400 2014-11-17] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-11-17] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe [5836800 2014-11-16] (Broadcom Corporation) [File not signed]
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Acer\WDAgent\Ath_WlanAgent.exe [76960 2012-03-13] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-16] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-16] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-16] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-16] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-16] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-16] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-16] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-11-16] (Disc Soft Ltd)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28216 2012-11-19] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-16] (Avast Software)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-25 17:53 - 2014-12-25 17:54 - 00015328 _____ () C:\Users\Adka\Desktop\FRST.txt
2014-12-25 17:53 - 2014-12-25 17:53 - 00000000 ____D () C:\FRST
2014-12-25 17:52 - 2014-12-25 17:52 - 00112640 _____ (forum.viry.cz) C:\Users\Adka\Desktop\FRSTLauncher.exe
2014-12-25 17:50 - 2014-12-25 17:50 - 02122240 _____ (Farbar) C:\Users\Adka\Desktop\FRST64.exe
2014-12-25 16:39 - 2014-12-25 16:39 - 00000197 _____ () C:\Windows\system32\2014-12-25-15-39-09.098-AvastVBoxSVC.exe-3388.log
2014-12-25 16:37 - 2014-12-25 16:37 - 00000000 ____D () C:\Users\Adka\AppData\Local\VirtualStore
2014-12-25 16:35 - 2014-12-25 16:00 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-12-25 16:02 - 2014-12-25 16:37 - 00009655 _____ () C:\zoek-results.log
2014-12-25 16:00 - 2014-12-25 16:32 - 00000000 ____D () C:\zoek_backup
2014-12-25 16:00 - 2014-12-25 16:00 - 01295360 _____ () C:\Users\Adka\Downloads\zoek.exe
2014-12-25 15:59 - 2014-12-25 15:59 - 00000197 _____ () C:\Windows\system32\2014-12-25-14-59-26.004-AvastVBoxSVC.exe-3600.log
2014-12-25 15:41 - 2014-12-25 15:41 - 02173952 _____ () C:\Users\Adka\Downloads\adwcleaner_4.106.exe
2014-12-25 15:27 - 2014-12-25 15:46 - 00000000 ____D () C:\Program Files (x86)\Tongbu
2014-12-25 15:27 - 2014-12-25 15:42 - 00000000 ____D () C:\Users\Adka\Documents\Tongbu
2014-12-25 15:27 - 2014-12-25 15:37 - 00001895 _____ () C:\Users\Public\Desktop\Tongbu Assistant.lnk
2014-12-25 15:27 - 2014-12-25 15:27 - 00001234 _____ () C:\Users\Public\Desktop\Game Center.lnk
2014-12-25 15:27 - 2014-12-25 15:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tongbu Network
2014-12-25 15:26 - 2014-12-25 15:26 - 22863792 _____ () C:\Users\Adka\Downloads\Tongbu_Setup_2.2.3_zsgw.exe
2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\rsit
2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\Program Files\trend micro
2014-12-25 15:12 - 2014-12-25 15:13 - 01222144 _____ () C:\Users\Adka\Downloads\RSITx64.exe
2014-12-25 14:52 - 2014-12-25 14:52 - 00017471 _____ () C:\Users\Adka\Downloads\Minecraft_-_Pocket_Edition_(v.0.94)_[iOS_Game]_[English].ipa.torrent
2014-12-25 14:20 - 2014-12-25 14:23 - 13479310 _____ () C:\Users\Adka\Downloads\Minecraft---Pocket-Edition-APK-0.9.5-CRACKED_downloadapks.org.apk
2014-12-25 12:29 - 2014-12-25 12:29 - 00000197 _____ () C:\Windows\system32\2014-12-25-11-29-12.084-AvastVBoxSVC.exe-1608.log
2014-12-25 03:03 - 2014-12-25 03:03 - 00000197 _____ () C:\Windows\system32\2014-12-25-02-03-25.031-AvastVBoxSVC.exe-3204.log
2014-12-24 21:59 - 2014-12-24 21:59 - 00007609 _____ () C:\Users\Adka\AppData\Local\Resmon.ResmonCfg
2014-12-24 13:03 - 2014-12-25 15:00 - 00000000 ____D () C:\Users\Adka\Desktop\iPod Photo Cache
2014-12-24 13:03 - 2014-12-24 13:04 - 00000000 ____D () C:\Users\Adka\Desktop\Nová složka
2014-12-24 10:17 - 2014-12-24 10:17 - 00000197 _____ () C:\Windows\system32\2014-12-24-09-17-27.027-AvastVBoxSVC.exe-3168.log
2014-12-24 01:53 - 2014-12-24 01:53 - 00000197 _____ () C:\Windows\system32\2014-12-24-00-53-32.006-AvastVBoxSVC.exe-3928.log
2014-12-23 22:45 - 2014-12-23 22:47 - 173016004 _____ () C:\Users\Adka\Downloads\87e5ec2626b9931aeecdc67f81c971c3e468e727.ipa
2014-12-23 22:21 - 2014-12-23 22:21 - 09716132 _____ () C:\Users\Adka\Downloads\605cc375669ecff7c3db587ec05371407148c6f5.ipa
2014-12-23 22:16 - 2014-12-23 22:25 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Apple Computer
2014-12-23 22:16 - 2014-12-23 22:16 - 00000000 ____D () C:\Users\Adka\AppData\Local\Apple Computer
2014-12-23 22:16 - 2014-12-23 22:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-12-23 22:16 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2014-12-23 22:15 - 2014-12-23 22:16 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2014-12-23 22:15 - 2014-12-23 22:16 - 00000000 ____D () C:\Program Files\iTunes
2014-12-23 22:15 - 2014-12-23 22:15 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-12-23 22:15 - 2014-12-23 22:15 - 00000000 ____D () C:\Program Files\iPod
2014-12-23 22:13 - 2014-12-23 22:15 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-12-23 22:13 - 2014-12-23 22:13 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-12-23 22:13 - 2014-12-23 22:13 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-12-23 22:13 - 2014-12-23 22:13 - 00000000 ____D () C:\Users\Adka\AppData\Local\Apple
2014-12-23 22:13 - 2014-12-23 22:13 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-12-23 22:12 - 2014-12-23 22:13 - 00000000 ____D () C:\ProgramData\Apple
2014-12-23 22:12 - 2014-12-23 22:12 - 00000000 ____D () C:\Program Files\Bonjour
2014-12-23 22:12 - 2014-12-23 22:12 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-12-23 22:10 - 2014-12-23 22:10 - 122418480 _____ (Apple Inc.) C:\Users\Adka\Downloads\iTunes64Setup.exe
2014-12-23 20:57 - 2014-12-23 20:57 - 00000197 _____ () C:\Windows\system32\2014-12-23-19-57-07.023-AvastVBoxSVC.exe-3328.log
2014-12-23 20:54 - 2014-12-23 20:54 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-12-23 20:54 - 2014-12-23 20:54 - 00000000 ____D () C:\Windows\system32\NV
2014-12-23 20:54 - 2014-12-23 20:54 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-12-23 20:52 - 2014-12-13 11:08 - 00074056 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-12-23 20:52 - 2014-12-13 11:08 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 06859408 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 03513488 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 02558608 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 01097360 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 00935240 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-12-23 20:52 - 2014-12-13 09:03 - 00386368 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 00075080 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2014-12-23 20:52 - 2014-12-13 09:03 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-12-23 20:52 - 2014-12-13 00:11 - 04151176 _____ () C:\Windows\system32\nvcoproc.bin
2014-12-23 20:51 - 2014-12-23 20:51 - 00000197 _____ () C:\Windows\system32\2014-12-23-19-51-06.016-AvastVBoxSVC.exe-2760.log
2014-12-23 20:45 - 2014-12-13 11:08 - 32099472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 25460552 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 24764232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 20465808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 18594432 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 17264312 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 16040184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 14128496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 13288360 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 13202520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 10770120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 10710160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 10345280 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-12-23 20:45 - 2014-12-13 11:08 - 03610440 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 03293136 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 03248968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 02897824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 01895056 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434709.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 01556624 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434709.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00994384 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00968336 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00942400 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00928072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00906560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00876976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00496272 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00399688 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00391488 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00353224 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00346944 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00306328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00178632 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00165760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-12-23 20:45 - 2014-12-13 11:08 - 00031376 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2014-12-23 20:45 - 2014-12-13 11:08 - 00027983 _____ () C:\Windows\system32\nvinfo.pb
2014-12-23 18:52 - 2014-12-23 18:52 - 00000197 _____ () C:\Windows\system32\2014-12-23-17-52-53.007-AvastVBoxSVC.exe-3220.log
2014-12-23 18:50 - 2014-12-23 18:50 - 00734728 _____ () C:\Windows\Minidump\122314-28610-01.dmp
2014-12-23 18:00 - 2014-12-23 22:53 - 00000000 ___RD () C:\Users\Adka\Desktop\bordel
2014-12-23 09:06 - 2014-12-23 09:06 - 00000197 _____ () C:\Windows\system32\2014-12-23-08-06-20.037-AvastVBoxSVC.exe-3500.log
2014-12-23 07:07 - 2014-12-23 07:07 - 00000197 _____ () C:\Windows\system32\2014-12-23-06-07-23.057-AvastVBoxSVC.exe-3288.log
2014-12-22 08:07 - 2014-12-22 08:07 - 00000197 _____ () C:\Windows\system32\2014-12-22-07-07-48.007-AvastVBoxSVC.exe-3236.log
2014-12-21 16:10 - 2014-12-21 16:10 - 00000197 _____ () C:\Windows\system32\2014-12-21-15-10-07.068-AvastVBoxSVC.exe-3828.log
2014-12-20 10:40 - 2014-12-20 10:40 - 00000197 _____ () C:\Windows\system32\2014-12-20-09-40-41.064-AvastVBoxSVC.exe-3196.log
2014-12-19 10:53 - 2014-12-19 10:53 - 00000197 _____ () C:\Windows\system32\2014-12-19-09-53-19.003-AvastVBoxSVC.exe-3672.log
2014-12-18 08:50 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 08:50 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-18 08:44 - 2014-12-18 08:45 - 00000197 _____ () C:\Windows\system32\2014-12-18-07-44-42.068-AvastVBoxSVC.exe-4620.log
2014-12-17 13:27 - 2014-12-17 13:27 - 00000197 _____ () C:\Windows\system32\2014-12-17-12-27-17.088-AvastVBoxSVC.exe-3324.log
2014-12-17 08:21 - 2014-12-17 08:21 - 00000197 _____ () C:\Windows\system32\2014-12-17-07-21-08.031-AvastVBoxSVC.exe-3200.log
2014-12-16 21:28 - 2014-12-16 21:28 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-12-16 21:22 - 2014-12-16 21:22 - 00000000 ____D () C:\Program Files\Adobe
2014-12-16 21:15 - 2014-12-16 21:15 - 00001097 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Widget Browser.lnk
2014-12-16 21:11 - 2014-12-16 21:15 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-12-16 21:11 - 2014-12-16 21:11 - 00000997 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
2014-12-16 21:11 - 2014-12-16 21:11 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2014-12-16 21:11 - 2014-12-16 21:11 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Macromedia
2014-12-16 21:08 - 2014-12-16 21:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
2014-12-16 21:07 - 2014-12-16 21:26 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-12-16 20:58 - 2014-12-16 21:28 - 00000000 ____D () C:\ProgramData\Adobe
2014-12-16 20:58 - 2014-12-16 20:58 - 00000197 _____ () C:\Windows\system32\2014-12-16-19-58-18.013-AvastVBoxSVC.exe-3200.log
2014-12-16 20:57 - 2014-12-23 07:09 - 00000000 ____D () C:\Users\Adka\AppData\Local\Adobe
2014-12-16 18:49 - 2014-11-22 11:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-12-16 18:49 - 2014-11-22 11:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-12-16 12:06 - 2014-12-16 12:06 - 04645006 _____ () C:\Users\Adka\Downloads\zoznam_dlznikov_20_11_2014.zip
2014-12-16 08:01 - 2014-12-16 08:01 - 00000197 _____ () C:\Windows\system32\2014-12-16-07-01-39.077-AvastVBoxSVC.exe-3200.log
2014-12-15 08:36 - 2014-12-15 08:37 - 00000247 _____ () C:\Windows\system32\2014-12-15-07-36-59.034-aswFe.exe-1944.log
2014-12-15 08:30 - 2014-12-15 08:36 - 00000247 _____ () C:\Windows\system32\2014-12-15-07-30-50.016-aswFe.exe-2640.log
2014-12-15 08:30 - 2014-12-15 08:30 - 00000197 _____ () C:\Windows\system32\2014-12-15-07-30-43.047-AvastVBoxSVC.exe-5448.log
2014-12-14 22:53 - 2014-12-14 22:53 - 00000197 _____ () C:\Windows\system32\2014-12-14-21-53-00.054-AvastVBoxSVC.exe-3192.log
2014-12-14 05:03 - 2014-12-14 05:03 - 00000197 _____ () C:\Windows\system32\2014-12-14-04-03-00.048-AvastVBoxSVC.exe-3132.log
2014-12-13 19:12 - 2014-12-13 19:12 - 00000000 ____D () C:\Users\Adka\Documents\Vlastní šablony Office
2014-12-13 16:42 - 2014-12-13 16:42 - 00000000 __RHD () C:\MSOCache
2014-12-13 16:37 - 2014-12-25 17:02 - 00004948 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Adka-PC-Adka Adka-PC
2014-12-13 15:26 - 2014-12-13 15:26 - 00000230 _____ () C:\Users\Adka\Desktop\Mobil Adri Kallistofatře Kallová.URL
2014-12-13 11:41 - 2014-12-13 11:42 - 00000197 _____ () C:\Windows\system32\2014-12-13-10-41-32.084-AvastVBoxSVC.exe-3076.log
2014-12-13 03:52 - 2014-12-13 03:53 - 00000197 _____ () C:\Windows\system32\2014-12-13-02-52-47.089-AvastVBoxSVC.exe-2240.log
2014-12-12 07:57 - 2014-12-12 07:57 - 00000197 _____ () C:\Windows\system32\2014-12-12-06-57-37.095-AvastVBoxSVC.exe-4004.log
2014-12-11 17:39 - 2014-12-11 18:48 - 00018189 _____ () C:\Windows\DirectX.log
2014-12-11 16:42 - 2014-12-11 16:42 - 00000197 _____ () C:\Windows\system32\2014-12-11-15-42-27.041-AvastVBoxSVC.exe-3224.log
2014-12-11 08:16 - 2014-12-11 08:16 - 00000197 _____ () C:\Windows\system32\2014-12-11-07-16-25.079-AvastVBoxSVC.exe-2884.log
2014-12-11 08:12 - 2014-12-11 08:12 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-11 02:14 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-11 02:14 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-11 02:14 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-11 02:14 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-11 02:14 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-11 02:14 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-11 02:14 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-11 02:14 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-11 02:14 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-11 02:13 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-11 02:01 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-11 02:01 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-11 02:01 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-11 02:01 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-11 02:01 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-11 02:01 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-11 02:01 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-11 02:01 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-11 02:01 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-11 02:01 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-11 02:01 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-11 02:01 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-11 02:01 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-11 02:01 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-11 02:01 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-11 02:01 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-11 02:01 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-11 02:01 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-11 02:01 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-11 02:01 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-11 02:01 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-11 02:01 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-11 02:01 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-11 02:01 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-11 02:01 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-11 02:01 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-11 02:01 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-11 02:01 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-11 02:01 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-11 02:01 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-11 02:01 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-11 02:01 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-11 02:01 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-11 02:01 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-11 02:01 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-11 02:01 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-11 02:01 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-11 02:01 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-11 02:01 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-11 02:01 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-11 02:01 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-11 02:01 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-11 02:01 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-11 02:01 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-11 02:01 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-11 02:01 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-11 02:01 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-11 02:01 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-11 02:01 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-11 02:01 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-11 02:01 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-11 02:01 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-11 02:01 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-11 02:01 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-11 02:01 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-11 02:01 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-11 02:01 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-11 02:00 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-11 02:00 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-11 02:00 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-11 02:00 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-11 02:00 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-11 02:00 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-11 02:00 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-11 02:00 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-11 02:00 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-11 02:00 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-11 02:00 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-11 02:00 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-11 02:00 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-11 02:00 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-11 02:00 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-11 02:00 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-11 02:00 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-11 01:56 - 2014-12-11 01:56 - 00000197 _____ () C:\Windows\system32\2014-12-11-00-56-20.037-AvastVBoxSVC.exe-3700.log
2014-12-10 18:06 - 2014-12-10 18:06 - 00000197 _____ () C:\Windows\system32\2014-12-10-17-06-33.050-AvastVBoxSVC.exe-3972.log
2014-12-10 18:01 - 2014-12-10 18:02 - 00013103 _____ () C:\Users\Adka\Desktop\AdwCleaner[S0].txt
2014-12-10 17:58 - 2014-12-25 15:54 - 00000000 ____D () C:\AdwCleaner
2014-12-10 17:58 - 2014-12-10 17:58 - 02166272 _____ () C:\Users\Adka\Downloads\adwcleaner_4.105.exe
2014-12-10 16:59 - 2014-12-10 17:00 - 00000197 _____ () C:\Windows\system32\2014-12-10-15-59-41.012-AvastVBoxSVC.exe-3488.log
2014-12-10 08:19 - 2014-12-10 08:19 - 00000197 _____ () C:\Windows\system32\2014-12-10-07-19-11.093-AvastVBoxSVC.exe-4340.log
2014-12-10 08:08 - 2014-12-10 08:08 - 00000197 _____ () C:\Windows\system32\2014-12-10-07-08-13.098-AvastVBoxSVC.exe-4048.log
2014-12-09 23:17 - 2014-12-09 23:17 - 00000197 _____ () C:\Windows\system32\2014-12-09-22-17-42.068-AvastVBoxSVC.exe-3216.log
2014-12-09 17:31 - 2014-12-09 17:31 - 00000197 _____ () C:\Windows\system32\2014-12-09-16-31-12.059-AvastVBoxSVC.exe-3624.log
2014-12-09 08:04 - 2014-12-09 08:04 - 00000197 _____ () C:\Windows\system32\2014-12-09-07-04-52.006-AvastVBoxSVC.exe-4156.log
2014-12-09 00:21 - 2014-12-21 16:28 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-12-08 23:43 - 2014-12-08 23:43 - 00000197 _____ () C:\Windows\system32\2014-12-08-22-43-04.012-AvastVBoxSVC.exe-4660.log
2014-12-08 08:08 - 2014-12-08 08:08 - 00000197 _____ () C:\Windows\system32\2014-12-08-07-08-40.092-AvastVBoxSVC.exe-3536.log
2014-12-07 13:13 - 2014-12-25 16:44 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-12-07 13:13 - 2014-12-07 13:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2014-12-07 13:12 - 2014-12-07 13:12 - 01142392 _____ () C:\Users\Adka\Downloads\SteamSetup(1).exe
2014-12-07 11:26 - 2014-12-07 11:27 - 00000247 _____ () C:\Windows\system32\2014-12-07-10-26-56.032-aswFe.exe-2272.log
2014-12-07 11:21 - 2014-12-07 11:26 - 00000247 _____ () C:\Windows\system32\2014-12-07-10-21-02.046-aswFe.exe-632.log
2014-12-07 11:20 - 2014-12-07 11:20 - 00000197 _____ () C:\Windows\system32\2014-12-07-10-20-55.053-AvastVBoxSVC.exe-5972.log
2014-12-07 04:00 - 2014-12-07 04:00 - 00000197 _____ () C:\Windows\system32\2014-12-07-03-00-28.085-AvastVBoxSVC.exe-4216.log
2014-12-06 22:43 - 2014-12-06 22:43 - 00000197 _____ () C:\Windows\system32\2014-12-06-21-43-23.029-AvastVBoxSVC.exe-4248.log
2014-12-06 16:01 - 2014-12-06 16:01 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunderDev
2014-12-06 16:01 - 2014-12-06 16:01 - 00000000 ____D () C:\ProgramData\WarThunder
2014-12-06 16:00 - 2014-12-06 16:01 - 04086008 _____ (Gaijin Entertainment ) C:\Users\Adka\Downloads\wt_dev_launcher.exe
2014-12-06 14:22 - 2014-12-06 14:23 - 00000197 _____ () C:\Windows\system32\2014-12-06-13-22-49.059-AvastVBoxSVC.exe-4620.log
2014-12-05 17:19 - 2014-12-05 17:19 - 00000197 _____ () C:\Windows\system32\2014-12-05-16-19-23.029-AvastVBoxSVC.exe-4204.log
2014-12-05 15:04 - 2014-12-05 15:05 - 00000197 _____ () C:\Windows\system32\2014-12-05-14-04-49.036-AvastVBoxSVC.exe-3892.log
2014-12-05 07:23 - 2014-12-05 07:23 - 00000197 _____ () C:\Windows\system32\2014-12-05-06-23-42.046-AvastVBoxSVC.exe-3744.log
2014-12-04 15:42 - 2014-12-04 15:42 - 00000197 _____ () C:\Windows\system32\2014-12-04-14-42-03.092-AvastVBoxSVC.exe-4388.log
2014-12-04 07:10 - 2014-12-04 07:10 - 00000197 _____ () C:\Windows\system32\2014-12-04-06-10-39.039-AvastVBoxSVC.exe-3504.log
2014-12-03 18:06 - 2014-12-03 18:07 - 00000197 _____ () C:\Windows\system32\2014-12-03-17-06-49.035-AvastVBoxSVC.exe-4092.log
2014-12-03 08:30 - 2014-12-03 08:31 - 00000197 _____ () C:\Windows\system32\2014-12-03-07-30-45.088-AvastVBoxSVC.exe-4616.log
2014-12-03 08:23 - 2014-12-23 11:57 - 00000000 ____D () C:\Users\Adka\Desktop\LILA
2014-12-03 08:12 - 2014-12-03 08:12 - 01024368 _____ () C:\Users\Adka\Downloads\zeds dead dirtyphonics where are you now ft bright lights 320 kbps tags cover t9631125.exe
2014-12-03 07:37 - 2014-12-03 07:37 - 00000197 _____ () C:\Windows\system32\2014-12-03-06-37-31.088-AvastVBoxSVC.exe-2576.log
2014-12-02 19:13 - 2014-12-02 19:13 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Forest 1.0
2014-12-02 17:45 - 2014-12-02 17:46 - 00000197 _____ () C:\Windows\system32\2014-12-02-16-45-45.029-AvastVBoxSVC.exe-524.log
2014-12-02 08:12 - 2014-12-02 08:13 - 00000197 _____ () C:\Windows\system32\2014-12-02-07-12-25.096-AvastVBoxSVC.exe-3424.log
2014-12-01 23:18 - 2014-12-01 23:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-01 17:31 - 2014-12-01 17:31 - 00000197 _____ () C:\Windows\system32\2014-12-01-16-31-56.016-AvastVBoxSVC.exe-4624.log
2014-12-01 08:24 - 2014-12-01 08:24 - 00000197 _____ () C:\Windows\system32\2014-12-01-07-24-03.071-AvastVBoxSVC.exe-2680.log
2014-11-30 11:21 - 2014-11-30 11:21 - 00000197 _____ () C:\Windows\system32\2014-11-30-10-21-15.061-AvastVBoxSVC.exe-4188.log
2014-11-30 03:04 - 2014-11-30 03:04 - 00000197 _____ () C:\Windows\system32\2014-11-30-02-04-13.008-AvastVBoxSVC.exe-4224.log
2014-11-29 15:21 - 2014-11-29 15:21 - 00000197 _____ () C:\Windows\system32\2014-11-29-14-21-00.040-AvastVBoxSVC.exe-3596.log
2014-11-29 15:13 - 2014-11-29 15:13 - 00000197 _____ () C:\Windows\system32\2014-11-29-14-13-19.059-AvastVBoxSVC.exe-3080.log
2014-11-29 15:03 - 2014-11-29 15:03 - 00000000 ____D () C:\NVIDIA
2014-11-29 14:58 - 2014-11-29 15:01 - 308364224 _____ (NVIDIA Corporation) C:\Users\Adka\Downloads\344.75-notebook-win8-win7-64bit-international-whql.exe
2014-11-29 13:54 - 2014-11-29 13:54 - 00000197 _____ () C:\Windows\system32\2014-11-29-12-54-03.068-AvastVBoxSVC.exe-3848.log
2014-11-28 09:12 - 2014-11-28 09:12 - 00000197 _____ () C:\Windows\system32\2014-11-28-08-12-20.015-AvastVBoxSVC.exe-3324.log
2014-11-27 20:30 - 2014-11-28 14:56 - 00000000 ____D () C:\Users\Adka\Desktop\Adulik
2014-11-27 09:37 - 2014-11-27 09:37 - 00000197 _____ () C:\Windows\system32\2014-11-27-08-37-54.059-AvastVBoxSVC.exe-3572.log
2014-11-26 18:21 - 2014-11-26 18:23 - 10420018 _____ () C:\Users\Adka\Downloads\Patch to v46.1.zip
2014-11-26 17:53 - 2014-11-26 17:53 - 00003146 _____ () C:\Windows\System32\Tasks\{99B64EC8-C64D-43FA-8D12-A74FCE02A380}
2014-11-26 09:38 - 2014-11-26 09:38 - 00000197 _____ () C:\Windows\system32\2014-11-26-08-38-43.098-AvastVBoxSVC.exe-3476.log
2014-11-26 09:36 - 2014-12-25 16:36 - 00015256 _____ () C:\Windows\setupact.log
2014-11-26 09:36 - 2014-12-25 16:36 - 00003114 _____ () C:\Windows\PFRO.log
2014-11-26 09:36 - 2014-11-26 09:36 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-25 13:25 - 2014-11-25 13:25 - 00000197 _____ () C:\Windows\system32\2014-11-25-12-25-05.025-AvastVBoxSVC.exe-3408.log
2014-11-25 13:19 - 2014-11-25 13:19 - 00000000 ____D () C:\Program Files (x86)\CinemaP-1.3c
2014-11-25 13:16 - 2014-11-25 13:16 - 00593608 _____ () C:\Users\Adka\Downloads\Hay Day Windows Installer__8715_il1978.exe
2014-11-25 09:53 - 2014-11-25 09:53 - 00000000 __SHD () C:\Users\Adka\AppData\Local\EmieUserList
2014-11-25 09:53 - 2014-11-25 09:53 - 00000000 __SHD () C:\Users\Adka\AppData\Local\EmieSiteList
2014-11-25 09:53 - 2014-11-25 09:53 - 00000000 __SHD () C:\Users\Adka\AppData\Local\EmieBrowserModeList
2014-11-25 09:10 - 2014-11-25 09:10 - 00000197 _____ () C:\Windows\system32\2014-11-25-08-10-30.088-AvastVBoxSVC.exe-3872.log
2014-11-25 00:23 - 2014-11-25 00:23 - 00000197 _____ () C:\Windows\system32\2014-11-24-23-23-04.001-AvastVBoxSVC.exe-3608.log
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-25 17:37 - 2014-11-16 14:42 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-25 16:44 - 2009-07-14 05:45 - 00028928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-25 16:44 - 2009-07-14 05:45 - 00028928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-25 16:43 - 2014-11-16 23:41 - 00000000 ____D () C:\Users\Adka\AppData\Local\DayZ
2014-12-25 16:40 - 2014-11-16 14:31 - 00002183 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-25 16:40 - 2014-11-16 12:38 - 01342170 _____ () C:\Windows\WindowsUpdate.log
2014-12-25 16:37 - 2014-11-16 18:38 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-12-25 16:36 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-25 16:30 - 2014-11-16 12:47 - 00000000 ____D () C:\Users\Adka
2014-12-25 16:30 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2014-12-25 15:47 - 2014-11-16 14:59 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\uTorrent
2014-12-24 10:17 - 2014-11-16 14:31 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-12-23 20:52 - 2014-11-16 14:14 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-12-23 20:52 - 2014-11-16 14:14 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-12-23 20:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Help
2014-12-23 20:51 - 2014-11-16 14:14 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-12-23 18:50 - 2014-11-16 15:05 - 00000000 ____D () C:\Windows\Minidump
2014-12-23 07:07 - 2014-11-16 14:42 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-23 07:07 - 2014-11-16 14:42 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-23 07:07 - 2014-11-16 14:42 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-17 08:18 - 2009-07-14 05:45 - 04938752 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-16 21:31 - 2014-11-16 14:43 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\Adobe
2014-12-16 21:30 - 2014-11-16 13:16 - 00070376 _____ () C:\Users\Adka\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-16 20:17 - 2011-04-12 09:34 - 00661266 _____ () C:\Windows\system32\perfh005.dat
2014-12-16 20:17 - 2011-04-12 09:34 - 00141414 _____ () C:\Windows\system32\perfc005.dat
2014-12-16 20:17 - 2009-07-14 06:13 - 01585684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-14 05:01 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-12-13 20:30 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-13 14:35 - 2014-11-16 14:47 - 00000000 ____D () C:\Users\Adka\AppData\Roaming\vlc
2014-12-13 01:12 - 2014-11-16 19:01 - 02824504 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-12-13 01:12 - 2014-11-16 19:01 - 02210040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-12-13 01:12 - 2014-11-16 19:01 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-12-13 01:12 - 2014-11-16 19:01 - 01291464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-12-11 08:12 - 2014-11-16 18:27 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-11 08:12 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-11 08:12 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-11 02:18 - 2014-11-16 14:28 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-11 02:15 - 2014-11-16 14:28 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-29 15:17 - 2014-11-16 19:25 - 00001347 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk
2014-11-26 21:17 - 2014-11-22 16:46 - 00000000 ____D () C:\Users\Adka\Documents\DayZ
2014-11-26 18:01 - 2014-11-16 13:46 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-26 18:01 - 2014-11-16 13:46 - 00001147 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-26 18:01 - 2014-11-16 12:48 - 00001393 _____ () C:\Users\Adka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-25 16:32 - 2014-11-16 12:34 - 00000000 ____D () C:\Windows\Panther
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Users\Adka\Downloads\Hay Day Windows Installer__8715_il1978.exe:typelib
==================== Security Center ==================
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Adka\Desktop" je 36 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring
"C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM
"D:\Program Files (x86)\Origin\Origin.exe" -AutoStart [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
- Přílohy
-
- Addition.zip
- (7.8 KiB) Staženo 71 x
Re: poprosim kontrolu fb haveď
- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu na Vas vyskoci fixlog (pripadne bude ulozen na Plose), jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd) HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [**e©Kű¨**ˇ<*>] => C:\Program Files (x86)\Tongbu\tbMobileService.exe /start <===== ATTENTION (Value Name with invalid characters) FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File CHR dev: Chrome dev build detected! <======= ATTENTION CHR DefaultSearchKeyword: Default -> mystartsearch 2014-12-25 17:53 - 2014-12-25 17:54 - 00015328 _____ () C:\Users\Adka\Desktop\FRST.txt 2014-12-25 17:52 - 2014-12-25 17:52 - 00112640 _____ (forum.viry.cz) C:\Users\Adka\Desktop\FRSTLauncher.exe 2014-12-25 16:35 - 2014-12-25 16:00 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-12-25 16:02 - 2014-12-25 16:37 - 00009655 _____ () C:\zoek-results.log 2014-12-25 16:00 - 2014-12-25 16:32 - 00000000 ____D () C:\zoek_backup 2014-12-25 16:00 - 2014-12-25 16:00 - 01295360 _____ () C:\Users\Adka\Downloads\zoek.exe 2014-12-25 15:41 - 2014-12-25 15:41 - 02173952 _____ () C:\Users\Adka\Downloads\adwcleaner_4.106.exe 2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\rsit 2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\Program Files\trend micro 2014-12-25 15:12 - 2014-12-25 15:13 - 01222144 _____ () C:\Users\Adka\Downloads\RSITx64.exe 2014-12-10 18:01 - 2014-12-10 18:02 - 00013103 _____ () C:\Users\Adka\Desktop\AdwCleaner[S0].txt 2014-12-10 17:58 - 2014-12-25 15:54 - 00000000 ____D () C:\AdwCleaner 2014-12-10 17:58 - 2014-12-10 17:58 - 02166272 _____ () C:\Users\Adka\Downloads\adwcleaner_4.105.exe 2014-12-07 13:12 - 2014-12-07 13:12 - 01142392 _____ () C:\Users\Adka\Downloads\SteamSetup(1).exe REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring" /f REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe AlternateDataStreams: C:\Users\Adka\Downloads\Hay Day Windows Installer__8715_il1978.exe:typelib Hosts: EmptyTemp: End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: poprosim kontrolu fb haveď
togbu poznam len som skušal rušim ho
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-12-2014
Ran by Adka at 2014-12-26 11:38:15 Run:1
Running from C:\Users\Adka\Desktop
Loaded Profile: Adka (Available profiles: Adka)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [**e©Kű¨**ˇ<*>] => C:\Program Files (x86)\Tongbu\tbMobileService.exe /start <===== ATTENTION (Value Name with invalid characters)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR DefaultSearchKeyword: Default -> mystartsearch
2014-12-25 17:53 - 2014-12-25 17:54 - 00015328 _____ () C:\Users\Adka\Desktop\FRST.txt
2014-12-25 17:52 - 2014-12-25 17:52 - 00112640 _____ (forum.viry.cz) C:\Users\Adka\Desktop\FRSTLauncher.exe
2014-12-25 16:35 - 2014-12-25 16:00 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-12-25 16:02 - 2014-12-25 16:37 - 00009655 _____ () C:\zoek-results.log
2014-12-25 16:00 - 2014-12-25 16:32 - 00000000 ____D () C:\zoek_backup
2014-12-25 16:00 - 2014-12-25 16:00 - 01295360 _____ () C:\Users\Adka\Downloads\zoek.exe
2014-12-25 15:41 - 2014-12-25 15:41 - 02173952 _____ () C:\Users\Adka\Downloads\adwcleaner_4.106.exe
2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\rsit
2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\Program Files\trend micro
2014-12-25 15:12 - 2014-12-25 15:13 - 01222144 _____ () C:\Users\Adka\Downloads\RSITx64.exe
2014-12-10 18:01 - 2014-12-10 18:02 - 00013103 _____ () C:\Users\Adka\Desktop\AdwCleaner[S0].txt
2014-12-10 17:58 - 2014-12-25 15:54 - 00000000 ____D () C:\AdwCleaner
2014-12-10 17:58 - 2014-12-10 17:58 - 02166272 _____ () C:\Users\Adka\Downloads\adwcleaner_4.105.exe
2014-12-07 13:12 - 2014-12-07 13:12 - 01142392 _____ () C:\Users\Adka\Downloads\SteamSetup(1).exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\Users\Adka\Downloads\Hay Day Windows Installer__8715_il1978.exe:typelib
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS6ServiceManager => value deleted successfully.
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value deleted successfully.
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\Software\Microsoft\Windows\CurrentVersion\Run\\**e©Kű¨**ˇ<*> => Value Deleted Successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
CHR dev: Chrome dev build detected! <======= ATTENTION => Error: No automatic fix found for this entry.
Chrome DefaultSearchKeyword deleted successfully.
C:\Users\Adka\Desktop\FRST.txt => Moved successfully.
C:\Users\Adka\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Adka\Downloads\zoek.exe => Moved successfully.
C:\Users\Adka\Downloads\adwcleaner_4.106.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Users\Adka\Downloads\RSITx64.exe => Moved successfully.
C:\Users\Adka\Desktop\AdwCleaner[S0].txt => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Adka\Downloads\adwcleaner_4.105.exe => Moved successfully.
C:\Users\Adka\Downloads\SteamSetup(1).exe => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Users\Adka\Downloads\Hay Day Windows Installer__8715_il1978.exe => ":typelib" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 471.2 MB temporary data.
The system needed a reboot.
==== End of Fixlog 11:38:41 ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-12-2014
Ran by Adka at 2014-12-26 11:38:15 Run:1
Running from C:\Users\Adka\Desktop
Loaded Profile: Adka (Available profiles: Adka)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\...\Run: [**e©Kű¨**ˇ<*>] => C:\Program Files (x86)\Tongbu\tbMobileService.exe /start <===== ATTENTION (Value Name with invalid characters)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR DefaultSearchKeyword: Default -> mystartsearch
2014-12-25 17:53 - 2014-12-25 17:54 - 00015328 _____ () C:\Users\Adka\Desktop\FRST.txt
2014-12-25 17:52 - 2014-12-25 17:52 - 00112640 _____ (forum.viry.cz) C:\Users\Adka\Desktop\FRSTLauncher.exe
2014-12-25 16:35 - 2014-12-25 16:00 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-12-25 16:02 - 2014-12-25 16:37 - 00009655 _____ () C:\zoek-results.log
2014-12-25 16:00 - 2014-12-25 16:32 - 00000000 ____D () C:\zoek_backup
2014-12-25 16:00 - 2014-12-25 16:00 - 01295360 _____ () C:\Users\Adka\Downloads\zoek.exe
2014-12-25 15:41 - 2014-12-25 15:41 - 02173952 _____ () C:\Users\Adka\Downloads\adwcleaner_4.106.exe
2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\rsit
2014-12-25 15:13 - 2014-12-25 15:13 - 00000000 ____D () C:\Program Files\trend micro
2014-12-25 15:12 - 2014-12-25 15:13 - 01222144 _____ () C:\Users\Adka\Downloads\RSITx64.exe
2014-12-10 18:01 - 2014-12-10 18:02 - 00013103 _____ () C:\Users\Adka\Desktop\AdwCleaner[S0].txt
2014-12-10 17:58 - 2014-12-25 15:54 - 00000000 ____D () C:\AdwCleaner
2014-12-10 17:58 - 2014-12-10 17:58 - 02166272 _____ () C:\Users\Adka\Downloads\adwcleaner_4.105.exe
2014-12-07 13:12 - 2014-12-07 13:12 - 01142392 _____ () C:\Users\Adka\Downloads\SteamSetup(1).exe
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring" /f
REG: reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\Users\Adka\Downloads\Hay Day Windows Installer__8715_il1978.exe:typelib
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS6ServiceManager => value deleted successfully.
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value deleted successfully.
HKU\S-1-5-21-3385117169-3715099472-58281317-1000\Software\Microsoft\Windows\CurrentVersion\Run\\**e©Kű¨**ˇ<*> => Value Deleted Successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
CHR dev: Chrome dev build detected! <======= ATTENTION => Error: No automatic fix found for this entry.
Chrome DefaultSearchKeyword deleted successfully.
C:\Users\Adka\Desktop\FRST.txt => Moved successfully.
C:\Users\Adka\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Adka\Downloads\zoek.exe => Moved successfully.
C:\Users\Adka\Downloads\adwcleaner_4.106.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Users\Adka\Downloads\RSITx64.exe => Moved successfully.
C:\Users\Adka\Desktop\AdwCleaner[S0].txt => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\Adka\Downloads\adwcleaner_4.105.exe => Moved successfully.
C:\Users\Adka\Downloads\SteamSetup(1).exe => Moved successfully.
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
========= reg delete "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite" /f =========
Operace byla dokonźena ŁspŘçnŘ.
========= End of Reg: =========
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Users\Adka\Downloads\Hay Day Windows Installer__8715_il1978.exe => ":typelib" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 471.2 MB temporary data.
The system needed a reboot.
==== End of Fixlog 11:38:41 ====
Re: poprosim kontrolu fb haveď
Doporucuji zmenit heslo k fb. Takze jeste uklidime.
- Stahnete a spustte DelFix - https://toolslib.net/downloads/viewdownload/2-delfix/
- Oznacte jen moznost "Remove disinfection tools"
- kliknete na Run
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: poprosim kontrolu fb haveď
ok tak dakujem 
Re: poprosim kontrolu fb haveď
Nemate zac, rad jsem pomohl
Mejte se a treba zase nekdy
Mejte se a treba zase nekdy
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.


Přispějete na provoz fóra?