Mbam problém.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
Alex05
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 19 Led 2013 00:21

Mbam problém.

#1 Příspěvek od Alex05 »

Dobrý večer.

Používám Mbam a jsem sním spokojen. Jen dneska se objevil problém kdy začne skenovat a najednou se zastaví teda spíše zasekne u prvního kroku kdy se připravuje na scan.
Nejde potom vypnout ani přes správce uloh.
Mohli by jste mi prosím pomoct? :) a když jsme u toho můžeme mi i pomoct vyčistit počítač? :)
Děkuji za odpověd :)

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Mbam problém.

#2 Příspěvek od altrok »

Zdravim :bye:

:arrow: Koukneme na to... dejte log z RSIT - http://forum.viry.cz/viewtopic.php?f=13&t=130786
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Alex05
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 19 Led 2013 00:21

Re: Mbam problém.

#3 Příspěvek od Alex05 »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Alík at 2014-12-25 11:24:35
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 2 GB (2%) free of 95 GB
Total RAM: 4094 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:24:45, on 25.12.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Alík.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1ewenusDefaultPack/U223_FRPage
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Alík\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1419493948
O4 - Global Startup: TP-LINK Wireless Configuration Utility.lnk = C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files (x86)\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files (x86)\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - (no file)
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
O23 - Service: Desura Install Service - Desura Pty Ltd - C:\Program Files (x86)\Common Files\Desura\desura_service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: WinTab Service (WinTabService) - Unknown owner - C:\Windows\System32\Drivers\WTSRV.EXE (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11772 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe"
"C:\Windows\System32\Drivers\WTSRV.EXE"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2368
"taskhost.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe" -nogui
HydraDM64.exe -h:65934 "Maximalizovat na celou plochu" "Maximalizovat k rohům okna" "Obnovit pracovní plochu"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM" PriorityLow
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Users\Alík\Desktop\blbosti\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Alex05
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 19 Led 2013 00:21

Re: Mbam problém.

#4 Příspěvek od Alex05 »

Jen to nejde celé skopírovat.
Vždy když dám kopírovat tak se skopíruje jen část a další ne a i když zkouším tu část co se neskopírovala tam dodat tak jako by to nešlo.

Alex05
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 19 Led 2013 00:21

Re: Mbam problém.

#5 Příspěvek od Alex05 »

tady pro jistotu příkládám.
Přílohy
log.rar
(9.98 KiB) Staženo 49 x

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Mbam problém.

#6 Příspěvek od altrok »

:arrow: Uvolnete misto na disku (odinstalujte nepouzivane programy, ...)

:arrow: MBAM odinstalujte pomoci http://downloads.malwarebytes.org/file/mbam_clean

:arrow: Spustte jako spravce C:\Program Files\trend micro\Alík.exe
  • kliknete na Do a system scan only
  • zatrhnete (udelejte fajfku) nasledujici polozky
    • O15 - Trusted Zone: *.clonewarsadventures.com
      O15 - Trusted Zone: *.freerealms.com
      O15 - Trusted Zone: *.soe.com
      O15 - Trusted Zone: *.sony.com
  • kliknete na Fix checked
:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Clean
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Alex05
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 19 Led 2013 00:21

Re: Mbam problém.

#7 Příspěvek od Alex05 »

# AdwCleaner v4.106 - Report created 25/12/2014 at 16:12:10
# Updated 21/12/2014 by Xplode
# Database : 2014-12-21.4 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Alík - MARTIN-PC
# Running from : C:\Users\Alík\Desktop\blbosti\Downloads\adwcleaner_4.106.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\PC Drivers HeadQuarters
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Users\Alík\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Alík\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\htyvuhpd.default-1358181912570\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Folder Deleted : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\ktuvflc9.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
File Deleted : C:\Users\Alík\AppData\Roaming\Mozilla\Firefox\Profiles\falarzhh.default-1399235657348\invalidprefs.js
File Deleted : C:\Users\Alík\AppData\Roaming\Mozilla\Firefox\Profiles\falarzhh.default-1399235657348\searchplugins\bingp.xml
File Deleted : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.ak.facebook.com_0.localstorage
File Deleted : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.ak.facebook.com_0.localstorage-journal

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Value Deleted : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2488}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\SafetyNut
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00E944CB89111313EAF35A0553F547F9
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CFE535C35F99574E8340BFA75BF92C2
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\261F213D1F55267499B1F87D0CC3BCF7
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2468513CA2D6943A1A233CD3F88CE7
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F55AF3F4049ED3FA6EA6F88E414E24
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E4BF4B11615E03C97732FD581AB607
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CE3DDAB2D152683FBCEB4866BCD2B0F
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF6CE16AFEA5C9A39B766468A8B35C21
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB1E44269B58F433A8C8E671E37CFDCF
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3192AA38321C641458DBDAF83979D193
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\467F76FB6B590634BB752B5EAAC618B4
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\F928123A039649549966D4C29D35B1C9

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Mozilla Firefox v34.0.5 (x86 cs)

[falarzhh.default-1399235657348\prefs.js] - Line Deleted : user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__blacklist_domain.value", "%7B%22SLIDERS%22%3A%5B%226pm.com%22%2C%22amazon.c[...]
[falarzhh.default-1399235657348\prefs.js] - Line Deleted : user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]

-\\ Google Chrome v24.0.1312.52

[C:\Users\Alík\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=&systemid=&v=-&apn_uid=&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
[C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : fbmimoidopbghbcmdmpkjaffffmcbmbg
[C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : geggofhlfbcmanadhknllmlajiafopoh
[C:\Users\Alík\AppData\Local\Chromium\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyB0AyBzytDyDtCtCtD0FtA0AyD0FyC0EtN0D0Tzu0CtBzytAtN1L2XzutBtFtBtFtDtFtAyEyE&cr=2140902348
[C:\Users\Alík\AppData\Local\Chromium\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=209&systemid=488&v=a12834-385&apn_uid=4020427313224010&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}

-\\ Chromium v

[C:\Users\Alík\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=&systemid=&v=-&apn_uid=&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}
[C:\Users\Alík\AppData\Local\Chromium\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://searchfunmoods.com/results.php?f=4&q={searchTerms}&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzuyB0AyBzytDyDtCtCtD0FtA0AyD0FyC0EtN0D0Tzu0CtBzytAtN1L2XzutBtFtBtFtDtFtAyEyE&cr=2140902348
[C:\Users\Alík\AppData\Local\Chromium\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=209&systemid=488&v=a12834-385&apn_uid=4020427313224010&apn_dtid=TCH001&o=APN11459&apn_ptnrs=AG1&q={searchTerms}

*************************

AdwCleaner[R0].txt - [12697 octets] - [14/01/2014 23:09:28]
AdwCleaner[R1].txt - [9112 octets] - [21/06/2014 12:34:07]
AdwCleaner[R2].txt - [20039 octets] - [25/12/2014 16:09:10]
AdwCleaner[S0].txt - [12556 octets] - [14/01/2014 23:11:20]
AdwCleaner[S1].txt - [8526 octets] - [21/06/2014 12:35:36]
AdwCleaner[S2].txt - [20332 octets] - [25/12/2014 16:12:10]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [20393 octets] ##########

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Mbam problém.

#8 Příspěvek od altrok »

:arrow: Ulozte na plochu zoek.exe http://hijackthis.nl/smeenk/zoek.htm
  • spustte jako spravce
  • do velkeho okna zkopirujte script uvedeny nize
  • kliknete na Run script
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\zoek-results.log) - vlozte mi jej do pristi odpovedi

    Kód: Vybrat vše

    autoclean;
    emptyclsid;
    emptyalltemp;
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Alex05
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 19 Led 2013 00:21

Re: Mbam problém.

#9 Příspěvek od Alex05 »

Je normální že mi systém a nečiné procesy systému zabírají přes 80 cpu?
Hned potom co se restartoval počítač po adw cleaneru

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Mbam problém.

#10 Příspěvek od altrok »

:arrow: Necinne procesy = rezervni prostredky... prostredky, ktere nejsou vyuzivany. 80 % je dobre.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Alex05
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 19 Led 2013 00:21

Re: Mbam problém.

#11 Příspěvek od Alex05 »

I ten systém?..mám namysli..NT Kernel a System taky mají přes 40.
A celkově na celí počítač je to 80-90 ted o.o nějak se mi to zdá moc.

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Mbam problém.

#12 Příspěvek od altrok »

:arrow: Pustte tam jeste zoek, pak se na to podivame.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Alex05
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 19 Led 2013 00:21

Re: Mbam problém.

#13 Příspěvek od Alex05 »

Zoek.exe v5.0.0.0 Updated 24-12-2014
Tool run by Alˇk on źt 25.12.2014 at 16:44:19,99.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Alík\Desktop\blbosti\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

25.12.2014 16:47:56 Zoek.exe System Restore Point Created Succesfully.

==== Empty Folders Check ======================

C:\PROGRA~2\CodeStuff deleted successfully
C:\PROGRA~2\CommViewWiFi deleted successfully
C:\PROGRA~2\CoreCodec deleted successfully
C:\PROGRA~2\Eidos deleted successfully
C:\PROGRA~2\Get Styles deleted successfully
C:\PROGRA~2\Konami deleted successfully
C:\PROGRA~2\Logia deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\PopCap Games deleted successfully
C:\PROGRA~2\ProtectDisc Driver Installer deleted successfully
C:\PROGRA~2\RTL Winter Sports 2009 deleted successfully
C:\PROGRA~2\thriXXX deleted successfully
C:\PROGRA~2\TopCD deleted successfully
C:\PROGRA~2\VstPlugins deleted successfully
C:\PROGRA~2\World of Warcraft deleted successfully
C:\PROGRA~3\AVAST Software deleted successfully
C:\PROGRA~3\BioWare deleted successfully
C:\PROGRA~3\Hi-Rez Studios deleted successfully
C:\PROGRA~3\Local Settings deleted successfully
C:\PROGRA~3\TamoSoft deleted successfully
C:\PROGRA~3\TrueCrypt deleted successfully
C:\Users\Alˇk\AppData\Roaming\Apple Computer deleted successfully
C:\Users\Alˇk\AppData\Roaming\Awesomium deleted successfully
C:\Users\Alˇk\AppData\Roaming\gtk-2.0 deleted successfully
C:\Users\Alˇk\AppData\Roaming\Publish Providers deleted successfully
C:\Users\Alˇk\AppData\Roaming\Toribash deleted successfully
C:\Users\Alˇk\AppData\Roaming\Windows Live Writer deleted successfully
C:\Users\Guest\AppData\Roaming\DAEMON Tools Lite deleted successfully
C:\Users\Guest\AppData\Roaming\TP-LINK deleted successfully
C:\Users\Martin\AppData\Roaming\Atari deleted successfully
C:\Users\Martin\AppData\Roaming\install deleted successfully
C:\Users\Martin\AppData\Roaming\Spyware Terminator deleted successfully
C:\Users\Martin\AppData\Roaming\Summer Athletics 2008 deleted successfully
C:\Users\Martin\AppData\Roaming\Windows Live Writer deleted successfully
C:\Users\Alˇk\AppData\Local\.# deleted successfully
C:\Users\Alˇk\AppData\Local\2012 deleted successfully
C:\Users\Alˇk\AppData\Local\LG Electronics deleted successfully
C:\Users\Alˇk\AppData\Local\MigWiz deleted successfully
C:\Users\Alˇk\AppData\Local\Samsung deleted successfully
C:\Users\Alˇk\AppData\Local\WOP deleted successfully
C:\Users\Alˇk\AppData\Local\{0D2358D4-220C-4258-BEE7-8FB7C5FB76D2} deleted successfully
C:\Users\Alˇk\AppData\Local\{0ECB1CB7-FA7A-43A5-BA95-C8A8F475AE26} deleted successfully
C:\Users\Alˇk\AppData\Local\{144CB015-46DD-431B-B46A-120D7C8CEB93} deleted successfully
C:\Users\Alˇk\AppData\Local\{1DF21E1B-1297-443C-B407-CD6C2F7CBEBD} deleted successfully
C:\Users\Alˇk\AppData\Local\{2E2D8374-9C90-4C01-84B0-288C9A63DEFC} deleted successfully
C:\Users\Alˇk\AppData\Local\{5F9E0D95-6001-448F-961A-1A275EB7FFE5} deleted successfully
C:\Users\Alˇk\AppData\Local\{6CEBD133-495D-4A3F-A2CA-D7361518EA77} deleted successfully
C:\Users\Alˇk\AppData\Local\{7122C79B-B4D1-47EB-AB20-BD36CBF981DA} deleted successfully
C:\Users\Alˇk\AppData\Local\{8C23A76C-8197-42E7-BFDE-E4313726839C} deleted successfully
C:\Users\Alˇk\AppData\Local\{92D7BF5D-0FAA-4913-84CB-B44777B72514} deleted successfully
C:\Users\Alˇk\AppData\Local\{94FF9F0F-3193-4230-930D-5EDE3CF93B2A} deleted successfully
C:\Users\Alˇk\AppData\Local\{A92C1927-9A9A-4DD7-807E-D06FB0460D97} deleted successfully
C:\Users\Alˇk\AppData\Local\{AAA70CA4-249C-40DA-8510-8C33334B946E} deleted successfully
C:\Users\Alˇk\AppData\Local\{E8EB0C9A-9B1D-4667-AE4F-1A2586570512} deleted successfully
C:\Users\Alˇk\AppData\Local\{E8F1164E-ABD1-4D7E-954D-7814FE40FE32} deleted successfully
C:\Users\Alˇk\AppData\Local\{F159210F-C494-4572-85E3-5B2FF8196D01} deleted successfully
C:\Users\Martin\AppData\Local\GHISLER deleted successfully
C:\Users\Martin\AppData\Local\{B200AF1F-4251-4738-93EC-102528A77E9E} deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{291F61F4-E715-4871-A0C3-DE08F6AEAB6} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{345c1300-0d4c-468c-b0e7-c69ecdbfbeaf} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7191E5A7-374F-4691-8623-46405736FCF5} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BBA933FC-90AB-4D32-978F-D9F348FCF45C} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f4eaeb02-fa22-43b0-bca6-4bc2d4b50303} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F73B8518-AE66-45BD-BC76-84BBE558C526} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{345c1300-0d4c-468c-b0e7-c69ecdbfbeaf} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f4eaeb02-fa22-43b0-bca6-4bc2d4b50303} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{E9911EC6-1BCC-40B0-9993-E0EEA7F6953F} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{00000000-0000-0000-0000-000000000000} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{336D0C35-8A85-403a-B9D2-65C292C39087} deleted successfully
HKEY_USERS\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

ProfilePath: C:\Users\ALK~1\AppData\Roaming\Mozilla\Firefox\Profiles\falarzhh.default-1399235657348

user.js not found
---- Lines aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822 removed from prefs.js ----
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.InstallationThankYouPage", false);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.InstallationTime", 1410607657);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.a346f15b-f72e-4205-b29d-52ad46792214@bf4b3822-f1
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b2
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b2
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.active", true);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.addressbar", "NA");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.addressbarenhanced", "");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.asyncdb.was_copied", "true");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.asyncdb_dbWasSet", true);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.asyncdb_dbWasSet_FF25_FIX", true);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.asyncinternaldb.was_copied", "true");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.asyncinternaldb_dbWasSet", true);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.asyncinternaldb_dbWasSet_FF25_FIX", true);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.backgroundver", 1);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.certdomaininstaller", "");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.changeprevious", false);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.cookie.InstallationTime.expiration", "Fri Feb 01
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.cookie.InstallationTime.value", "%221410607657%2
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.cookie.InstallerParams.expiration", "Fri Feb 01
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.cookie.InstallerParams.value", "%7B%22source_id%
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.description", "Shop-Up");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.domain", "");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.enablesearch", false);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.homepage", "");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.iframe", false);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.InstallerIdentifiers.expiration", "Fr
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.InstallerIdentifiers.value", "%7B%22i
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.InstallerParams.expiration", "Fri Feb
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.InstallerParams.value", "%7B%22source
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.InstallerParamsCache.expiration", "Fr
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.InstallerParamsCache.value", "%7B%22s
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.InstallerUserIdentifiersCache.expirat
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.InstallerUserIdentifiersCache.value",
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_appVer.expiration", "Fri Fe
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_appVer.value", "137");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_lastVersion.expiration", "F
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_lastVersion.value", "1");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_meta.expiration", "Fri Feb
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_meta.value", "%7B%7D");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_nextCheck.expiration", "Sun
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_nextCheck.value", "true");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_queue.expiration", "Fri Feb
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.Resources_queue.value", "%7B%7D");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__blacklist_domain.expirati
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__global_rules.expiration",
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__global_rules.value", "%5B
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__global_rules_verion.expir
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__global_rules_verion.value
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__last_daily_visit.expirati
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__last_daily_visit.value",
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__last_impression_time.expi
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__last_impression_time.valu
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__marketing_rules.expiratio
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__marketing_rules.value", "
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__marketing_rules_verion.ex
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__marketing_rules_verion.va
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__pages_visited_count.expir
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__pages_visited_count.value
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__pagevies_count_14.8.2014.
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__pagevies_count_14.8.2014.
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__siteunder_protection.expi
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__siteunder_protection.valu
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__total_impressions_today.e
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__total_impressions_today.v
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__total_impressions_today_s
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__total_impressions_today_s
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__verions_data.expiration",
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__ICM_LITE__verions_data.value", "%7B
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__defualt_browser__.expiration", "Fri
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.__defualt_browser__.value", "%22ff%22
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb._installer_additional_info.expiration
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb._installer_additional_info.value", "%
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.installer.expiration", "Fri Feb 01 20
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.installer.value", "%7B%22InstallerIde
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.monetization_plugin_bundledUrls.expir
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.monetization_plugin_bundledWithHash.e
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.monetization_plugin_bundledWithHash.v
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.monetization_plugin_notBundledArr_.ex
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.monetization_plugin_notBundledArr_.va
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.monetization_plugin_regBundledWithSof
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.internaldb.monetization_plugin_regBundledWithSof
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.lastDailyReport", "1410629327371");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.lastUpdate", "1410629322108");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.manifesturl", "");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.name", "Shop-Up");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.newtab", "");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.opensearch", "");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.pluginsurl", "http://js.newclientgenservice.com/
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.pluginsversion", 129);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.publisher", "Winportal");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.searchstatus", 0);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.setnewtab", false);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.thankyou", "");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.updateinterval", 360);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.42822.ver", 137);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.apps", "42822");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.bic", "148700f40a928fb8d0ded490a004f593");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.cid", 42822);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.firstrun", false);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.hadappinstalled", true);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.installationdate", 1410629321);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.installerAdditionalInfo", "{\"asw\":[67108872, 5, 0]}"
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.modetype", "production");
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.reportInstall", true);
user_pref("extensions.aa346f15bf72e4205b29d52ad46792214bf4b3822f1de4b298f70c0a27f6ca2b8com42822.statsDailyCounter", 1);
---- FireFox user.js and prefs.js backups ----

prefs_25.12.2014_1712_.backup

ProfilePath: C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\htyvuhpd.default-1358181912570

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_25.12.2014_1712_.backup

ProfilePath: C:\Users\Martin\AppData\Roaming\Broad Intelligence\MediaCoder\Profiles\892k55lj.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_25.12.2014_1712_.backup

ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\ktuvflc9.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_25.12.2014_1712_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~3\Simajo The Travel Móstery Game not found
C:\Users\Alík\AppData\Roaming\coreavc.ini not found
C:\Users\Alík\AppData\Roaming\Youdagames not found
C:\Users\Alík\AppData\Roaming\GetRightToGo not found
C:\PROGRA~3\Simajo The Travel Móstery Game not found
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\ktuvflc9.default\extensions\toolbar@ask.com not found
"C:\Windows\Installer\1c9c76.msi" not found
"C:\Windows\Installer\a5b6b.msi" not found
"C:\Users\Alík\AppData\Roaming\ATI" not found
"C:\Users\Alík\AppData\Roaming\ICQ" not found
"C:\Users\Alík\AppData\Roaming\vlc" not found
"C:\Users\Alík\AppData\Roaming\FUEL" not found
"C:\Users\Alík\AppData\Roaming\Sony" not found
"C:\Users\Alík\AppData\Roaming\TERA" not found
"C:\Users\Alík\AppData\Roaming\Logia" not found
"C:\Users\Alík\AppData\Roaming\Raptr" not found
"C:\Users\Alík\AppData\Roaming\SPORE" not found
"C:\Users\Alík\AppData\Roaming\Steam" not found
"C:\Users\Alík\AppData\Roaming\Theta" not found
"C:\Users\Alík\AppData\Roaming\Unity" not found
"C:\Users\Alík\AppData\Roaming\Modiac" not found
"C:\Users\Alík\AppData\Roaming\Origin" not found
"C:\Users\Alík\AppData\Roaming\Winamp" not found
"C:\Users\Alík\AppData\Roaming\AnvSoft" not found
"C:\Users\Alík\AppData\Roaming\Gamelab" not found
"C:\Users\Alík\AppData\Roaming\GRETECH" not found
"C:\Users\Alík\AppData\Roaming\Samsung" not found
"C:\Users\Alík\AppData\Roaming\TP-LINK" not found
"C:\Users\Alík\AppData\Roaming\Tunngle" not found
"C:\Users\Alík\AppData\Roaming\Ubisoft" not found
"C:\Users\Alík\AppData\Roaming\ViberPC" not found
"C:\Users\Alík\AppData\Roaming\_MDLogs" not found
C:\PROGRA~2\intelliScore Polyphonic WAV to MIDI Converter Demo deleted
C:\PROGRA~2\Warner Bros. Interactive Entertainment deleted
C:\user.js deleted
C:\PROGRA~3\ICQ deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Martin\AppData\Local\CRE deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\AVG Secure Search deleted
C:\Windows\wininit.ini deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted
"C:\Users\Alík\AppData\Local\{24180157-2E59-4E44-9B43-01083A523492}" deleted
"C:\Users\Alík\AppData\Local\{7CD7A493-9701-4F75-BADE-E37A27F1BBB1}" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\ALK~1\AppData\Roaming\Mozilla\Firefox\Profiles\falarzhh.default-1399235657348
user_pref("browser.startup.homepage", "http://www.bing.com/?pc=U223|http://www ... m/?pc=U223");
user_pref("keyword.URL", "http://www.bing.com/search?FORM=U223DF&PC=U223&q=");

==== Firefox Extensions ======================

ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\ktuvflc9.default
- Personas - %ProfilePath%\extensions\personas@christopher.beard
- FBFan - %ProfilePath%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA99}
- QAssistant - %ProfilePath%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
- 8675f4b3-2f19-11ed-2d6b-0800600c0a16 - %ProfilePath%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a16}
- 8675f4b3-2f19-11ed-2d6b-0800600c0a19 - %ProfilePath%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a19}
- DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
- Stylish - %ProfilePath%\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
- Get Styles - %ProfilePath%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA80}.xpi
- Usage Stat - %ProfilePath%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA96}.xpi
- VFT Flv - %ProfilePath%\extensions\{8675f4b3-2f19-11ed-2d6b-1823600c0a19}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Skype extension - %AppDir%\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================


==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\Alík\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

Google Chrome Version: 24.0.1312.52 (Possible outdated, latest Stable version: 39.0.2171.95)


Seznam Li\u0161ti\u010Dka - Email - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam Li\u0161ti\u010Dka - Slovn\u00EDk - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
AT_Pocoyo - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijcedejkdfecaehkiljocofobfbnkpg
Seznam Li\u0161ti\u010Dka - Rychl\u00E1 volba - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
Naruto Theme 3 - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikgdgaejnjhhgmeaogdkhccoeinefkon

==== Chromium Startpages ======================

C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.seznam.cz/?clid=13415",
"homepage": "http://www.seznam.cz/?clid=13415",

C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.google.com/",
"homepage": "http://www.google.com/",


==== Chromium Fix ======================

C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_youtube.conduitapps.com_0.localstorage deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_youtube.conduitapps.com_0.localstorage-journal deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.incredibar.com_0.localstorage deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_search.incredibar.com_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toolbarstats.s3.amazonaws.com_0.localstorage deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_toolbarstats.s3.amazonaws.com_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_lp.click2saveapp.com_0.localstorage deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_lp.click2saveapp.com_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_isearch.avg.com_0.localstorage-journal deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.agame.com_0.localstorage deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.agame.com_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_delivery.thepiratebay.se_0.localstorage deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_delivery.thepiratebay.se_0.localstorage-journal deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_thepiratebay.se_0.localstorage deleted successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_thepiratebay.se_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"tab"="$ActiveDomain/page/Tabs/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"tab"="$ActiveDomain/page/Tabs/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\059103D1F2AE2884A90A9464776548A2 deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D102849DF9E46C14D9627DC3FCE9FA9F deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D948201D-4E9F-41C6-9D26-D73CCF9EAFF9} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1D301950-EA2F-4882-9AA0-49467756842A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\059103D1F2AE2884A90A9464776548A2 deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D102849DF9E46C14D9627DC3FCE9FA9F deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Alík\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Alík\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Guest\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Guest\AppData\Local\Mozilla\Firefox\Profiles\htyvuhpd.default-1358181912570\Cache emptied successfully
C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\ktuvflc9.default\personas\cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=80 folders=34 22056825 bytes)

==== Empty Temp Folders ======================

C:\Users\AlÝk\AppData\Local\temp emptied successfully
C:\Users\Alík\AppData\Local\temp emptied successfully
C:\Users\AppData\AppData\Local\temp emptied successfully
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Guest\AppData\Local\temp emptied successfully
C:\Users\Martin\AppData\Local\temp emptied successfully
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Users\System\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\ALK~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\PROGRA~3\SystemRequirementsLab" not deleted

==== EOF on źt 25.12.2014 at 17:22:11,30 ======================

altrok
Moderátor
Moderátor
Příspěvky: 7328
Registrován: 15 Lis 2012 22:26
Místo/Bydliště: Znojmo

Re: Mbam problém.

#14 Příspěvek od altrok »

:arrow: Dejte novy log FRST.txt, prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Alex05
Návštěvník
Návštěvník
Příspěvky: 114
Registrován: 19 Led 2013 00:21

Re: Mbam problém.

#15 Příspěvek od Alex05 »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-12-2014
Ran by Alík (administrator) on MARTIN-PC on 26-12-2014 00:41:09
Running from C:\Users\Alík\Desktop
Loaded Profile: Alík (Available profiles: Alík & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Tablet Driver) C:\Windows\System32\drivers\WTSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
(AMD) C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Almico Software (www.almico.com)) C:\Program Files (x86)\SpeedFan\speedfan.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_15_0_0_246.exe
(forum.viry.cz) C:\Users\Alík\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9642528 2009-12-03] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [ATICustomerCare] => C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe [307200 2009-06-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-17] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-2302441451-1502683710-4223808985-1003\...\Run: [HydraVisionDesktopManager] => C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [385024 2009-12-14] (AMD)
HKU\S-1-5-21-2302441451-1502683710-4223808985-1003\...\Run: [uTorrent] => C:\Users\Alík\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-11-13] (BitTorrent Inc.)
HKU\S-1-5-21-2302441451-1502683710-4223808985-1003\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30528608 2014-11-27] (Skype Technologies S.A.)
HKU\S-1-5-21-2302441451-1502683710-4223808985-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2302441451-1502683710-4223808985-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2302441451-1502683710-4223808985-1003\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/1ewenusDefaultPack/U223_FRPage
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2302441451-1502683710-4223808985-1003 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: WebTransBHO Class -> {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} -> C:\ProgramData\LangSoft\WebIE.dll ()
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll ()
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll ()
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll ()
Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Alík\AppData\Roaming\Mozilla\Firefox\Profiles\falarzhh.default-1399235657348
FF SearchEngineOrder.3: Bing
FF Homepage: hxxp://www.bing.com/?pc=U223|hxxp://www.bing.com/?pc=U223
FF Keyword.URL: hxxp://www.bing.com/search?FORM=U223DF&PC=U223&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_246.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.0 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2302441451-1502683710-4223808985-1003: facebook.com/fbDesktopPlugin -> C:\Users\Alík\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF Plugin HKU\S-1-5-21-2302441451-1502683710-4223808985-1003: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF Extension: Skype extension - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2014-12-09]

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Users\Al\u00EDk\AppData\Local\Google\Chrome\User Data\PepperFlash\11.6.602.167\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Facebook Desktop) - C:\Users\Al\u00EDk\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Profile: C:\Users\Alík\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Alík\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-28]
CHR Extension: (Disk Google) - C:\Users\Alík\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-28]
CHR Extension: (YouTube) - C:\Users\Alík\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-28]
CHR Extension: (Vyhledávání Google) - C:\Users\Alík\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-28]
CHR Extension: (Gmail) - C:\Users\Alík\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-28]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-03-13] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-03-13] (BlueStack Systems, Inc.)
S2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [770832 2014-03-13] (BlueStack Systems, Inc.)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-07-25] ()
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [575488 2008-09-08] (Nokia.) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH) [File not signed]
R2 WinTabService; C:\Windows\System32\Drivers\WTSRV.EXE [53248 2007-05-31] (Tablet Driver) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2010-11-08] ()
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [121616 2014-03-13] (BlueStack Systems)
R0 BtHidBus; C:\Windows\System32\Drivers\BtHidBus.sys [23304 2009-09-24] (IVT Corporation.)
S3 btnetBUs; C:\Windows\System32\Drivers\btnetBus.sys [27776 2009-09-24] ()
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-11-29] (Disc Soft Ltd)
S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-09-17] (EnTech Taiwan)
S3 IvtBtBUs; C:\Windows\System32\Drivers\IvtBtBus.sys [30344 2009-08-26] (IVT Corporation.)
S3 libusb0; C:\Windows\SysWOW64\drivers\libusb0.sys [33792 2005-03-09] () [File not signed]
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2010-11-08] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [748648 2010-08-12] (Realtek Semiconductor Corporation )
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 Tablet2k; C:\Windows\System32\Drivers\Tablet2k.sys [26112 2007-04-16] (Windows (R) Server 2003 DDK provider) [File not signed]
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R1 truecrypt; C:\Windows\SysWow64\drivers\truecrypt.sys [222160 2010-01-02] (TrueCrypt Foundation)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [34808 2014-11-15] ()
U3 TrueSight; C:\Windows\SysWOW64\drivers\TrueSight.sys [29160 2014-08-28] ()
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-26 00:41 - 2014-12-26 00:42 - 00017285 _____ () C:\Users\Alík\Desktop\FRST.txt
2014-12-26 00:40 - 2014-12-26 00:41 - 00000000 ____D () C:\FRST
2014-12-26 00:38 - 2014-12-26 00:38 - 02122240 _____ (Farbar) C:\Users\Alík\Desktop\FRST64.exe
2014-12-26 00:38 - 2014-12-26 00:38 - 00112640 _____ (forum.viry.cz) C:\Users\Alík\Desktop\FRSTLauncher.exe
2014-12-26 00:29 - 2014-12-26 00:29 - 00002293 _____ () C:\Users\Alík\Desktop\co říct.txt
2014-12-25 17:19 - 2014-12-25 17:19 - 00000000 ____D () C:\Users\AlÝk\AppData\Roaming\Macromedia
2014-12-25 17:19 - 2014-12-25 17:19 - 00000000 ____D () C:\Users\AlŢk
2014-12-25 17:19 - 2014-12-25 16:44 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-12-25 16:47 - 2014-12-25 17:22 - 00037482 _____ () C:\zoek-results.log
2014-12-25 16:44 - 2014-12-25 17:15 - 00000000 ____D () C:\zoek_backup
2014-12-25 16:18 - 2014-12-25 16:18 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-25 16:14 - 2014-12-25 17:20 - 00024700 _____ () C:\Windows\PFRO.log
2014-12-25 11:24 - 2014-12-25 13:18 - 00000000 ____D () C:\rsit
2014-12-25 02:03 - 2014-12-25 02:15 - 00000000 ____D () C:\Users\Alík\Desktop\Nová složka
2014-12-25 01:59 - 2014-12-25 01:59 - 00000000 ____D () C:\ProgramData\Riot Games
2014-12-25 01:49 - 2014-12-25 01:49 - 00001319 _____ () C:\Users\Public\Desktop\League of Legends.lnk
2014-12-25 01:49 - 2014-12-25 01:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2014-12-25 01:41 - 2014-12-25 01:50 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\Riot Games
2014-12-18 13:28 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 13:28 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-18 06:37 - 2014-12-18 06:37 - 00000000 ____D () C:\Users\Alík\Documents\Diablo III
2014-12-18 04:13 - 2014-12-18 04:27 - 00000000 ____D () C:\Windows\rescache
2014-12-17 18:05 - 2014-12-17 18:05 - 00000803 _____ () C:\Users\Public\Desktop\Diablo III.lnk
2014-12-17 17:52 - 2014-12-17 18:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2014-12-17 17:30 - 2014-12-23 22:17 - 00000000 ____D () C:\Users\Alík\AppData\Local\Battle.net
2014-12-17 17:30 - 2014-12-17 17:49 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\Battle.net
2014-12-17 17:30 - 2014-12-17 17:30 - 00000000 ____D () C:\Users\Alík\AppData\Local\Blizzard Entertainment
2014-12-17 17:29 - 2014-12-17 17:29 - 00000797 _____ () C:\Users\Public\Desktop\Battle.net.lnk
2014-12-17 17:29 - 2014-12-17 17:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2014-12-14 11:13 - 2014-12-14 11:13 - 00000000 ____D () C:\ProgramData\SystemRequirementsLab
2014-12-14 01:00 - 2014-12-25 17:21 - 00001120 _____ () C:\Windows\setupact.log
2014-12-14 01:00 - 2014-12-14 01:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-10 18:40 - 2014-12-10 18:40 - 00000000 ____D () C:\Users\Alík\Documents\WB Games
2014-12-10 18:40 - 2014-12-10 18:40 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\Steam
2014-12-10 15:48 - 2014-12-10 15:48 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-10 06:35 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-10 06:35 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-10 06:35 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-10 06:35 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-10 06:35 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-10 06:35 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-10 06:35 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-10 06:35 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-10 06:35 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-10 06:35 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-10 06:20 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-10 06:20 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-10 06:20 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-10 06:20 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-10 06:20 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-10 06:20 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-10 06:20 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-10 06:20 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-10 06:20 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-10 06:20 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-10 06:20 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-10 06:20 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-10 06:20 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-10 06:20 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-10 06:20 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-10 06:20 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-10 06:20 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-10 06:20 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-10 06:20 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-10 06:20 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-10 06:20 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-10 06:20 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-10 06:20 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-10 06:20 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-10 06:20 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-10 06:20 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-10 06:20 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-10 06:20 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-10 06:20 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 06:20 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-10 06:20 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-10 06:20 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-10 06:20 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-10 06:20 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-10 06:20 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-10 06:20 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-10 06:20 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-10 06:20 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-10 06:20 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-10 06:20 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-10 06:20 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-10 06:20 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-10 06:20 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-10 06:20 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-10 06:20 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-10 06:20 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-10 06:20 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-10 06:20 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-10 06:20 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-10 06:20 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-10 06:20 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-10 06:20 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-10 06:20 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-10 06:20 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-10 06:20 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-10 06:20 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-10 06:20 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-10 06:20 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-10 06:20 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-10 06:20 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-10 06:20 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-10 06:20 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-10 06:20 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-10 06:20 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-10 06:20 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-10 06:16 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-10 06:16 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-10 06:16 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-10 06:16 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-10 06:16 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-10 06:16 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-10 06:16 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-10 06:16 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-10 06:16 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-10 06:16 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-10 06:16 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-10 06:16 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-10 06:16 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-10 06:16 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-09 18:09 - 2014-12-09 18:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-12-06 09:00 - 2014-12-06 09:00 - 00000000 ____D () C:\Users\Alík\Documents\Telltale Games
2014-12-06 09:00 - 2014-12-06 09:00 - 00000000 ____D () C:\ProgramData\REVOLT
2014-11-30 17:25 - 2014-11-30 17:25 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2014-11-29 15:46 - 2014-11-29 15:46 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\Among the sleep
2014-11-29 15:36 - 2014-11-29 15:36 - 00283064 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2014-11-29 15:36 - 2014-11-29 15:36 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-26 00:37 - 2014-01-13 23:53 - 00000193 _____ () C:\Windows\WORDPAD.INI
2014-12-26 00:37 - 2013-01-29 20:10 - 00000000 ____D () C:\Program Files\trend micro
2014-12-26 00:16 - 2013-12-20 22:31 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\Skype
2014-12-25 23:47 - 2014-02-04 22:48 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-25 21:22 - 2013-08-29 15:06 - 00000000 ____D () C:\Program Files (x86)\SpeedFan
2014-12-25 19:34 - 2013-08-07 18:19 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-12-25 18:52 - 2013-12-21 14:42 - 01321322 _____ () C:\Windows\WindowsUpdate.log
2014-12-25 17:28 - 2009-07-14 05:45 - 00023584 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-25 17:28 - 2009-07-14 05:45 - 00023584 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-25 17:23 - 2010-04-28 16:24 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\uTorrent
2014-12-25 17:22 - 2010-04-15 13:26 - 00000008 __RSH () C:\Users\Alík\ntuser.pol
2014-12-25 17:22 - 2010-04-15 13:26 - 00000000 ____D () C:\Users\Alík
2014-12-25 17:21 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-25 17:12 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-12-25 16:12 - 2014-01-14 23:09 - 00000000 ____D () C:\AdwCleaner
2014-12-25 15:19 - 2014-05-06 10:13 - 00000000 ____D () C:\Users\Alík\Desktop\blbosti
2014-12-25 08:51 - 2009-07-14 06:08 - 00032568 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-25 02:42 - 2012-10-23 17:26 - 00000000 ____D () C:\Users\Alík\AppData\Local\PMB Files
2014-12-25 02:09 - 2012-10-23 17:26 - 00000000 ____D () C:\ProgramData\PMB Files
2014-12-20 20:45 - 2013-12-17 00:34 - 00000000 ____D () C:\Users\Alík\AppData\Local\CrashDumps
2014-12-20 19:10 - 2009-07-14 16:18 - 00677560 _____ () C:\Windows\system32\perfh005.dat
2014-12-20 19:10 - 2009-07-14 16:18 - 00146478 _____ () C:\Windows\system32\perfc005.dat
2014-12-20 19:10 - 2009-07-14 06:13 - 01611666 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-18 23:13 - 2013-08-07 21:39 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-12-17 23:31 - 2012-11-09 16:32 - 00000000 ____D () C:\Users\Alík\Desktop\Škola
2014-12-17 18:05 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-12-14 11:13 - 2011-03-17 17:30 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-12-14 00:09 - 2010-04-29 13:26 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\DAEMON Tools Lite
2014-12-11 06:18 - 2013-01-22 17:25 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-10 18:32 - 2013-10-15 12:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hry
2014-12-10 15:48 - 2014-04-30 23:58 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-10 15:48 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-10 15:48 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-10 06:47 - 2009-12-21 00:18 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-12-10 06:46 - 2013-08-05 00:49 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-10 06:37 - 2009-12-20 23:52 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-10 06:00 - 2013-01-14 17:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-12-09 21:47 - 2013-03-23 18:00 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-09 21:47 - 2013-03-23 18:00 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-09 21:47 - 2011-08-06 18:50 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-04 22:19 - 2011-02-19 08:50 - 00000000 ____D () C:\Users\Alík\AppData\Roaming\.minecraft
2014-12-04 20:13 - 2014-10-12 15:33 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-04 20:13 - 2010-11-26 15:28 - 00000000 ____D () C:\ProgramData\Skype
2014-12-01 05:47 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\Offline Web Pages
2014-11-29 15:46 - 2014-04-12 22:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics

Some content of TEMP:
====================
C:\Users\Alík\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Alík\AppData\Local\Temp\sfareca00001.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Al�k\Desktop" je 172 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlueStacks Agent
C:\Program Files (x86)\BlueStacks\HD-Agent.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raptr
C:\PROGRA~2\Raptr\raptrstub.exe --startup [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent
"C:\Users\Al�k\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Přílohy
Addition.rar
(17.84 KiB) Staženo 51 x

Odpovědět