Dobry den prajem,
Mam trosku problem s pc. Kaspersky mi stale najde malware, a chce ho po restarte vycistit. Ale restartuje pc a zase sa tam objavi spat.
Mozem poprosit o help?
Prikladam FRST:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Rasty (administrator) on RASTY-PC on 11-03-2015 17:36:46
Running from C:\Users\Rasty\Desktop
Loaded Profiles: Rasty (Available profiles: Rasty)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Box, Inc.) C:\Program Files\Box\Box Sync\BoxSync.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Common Group) C:\Program Files (x86)\MUSTEK 1248UB\Driver\WATCH.exe
(Dropbox, Inc.) C:\Users\Rasty\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
() C:\Program Files\Box\Box Sync\BoxSyncMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Ghisler Software GmbH) C:\Totalcmd\TOTALCMD64.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\klwtblfs.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe
(Opera Software) C:\Program Files (x86)\Opera\opera.exe
(forum.viry.cz) C:\Users\Rasty\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [521272 2010-03-22] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [2598280 2010-06-24] (ELAN Microelectronics Corp.)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [776608 2009-12-19] (Lenovo)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4367808 2009-12-17] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [6988736 2009-12-17] (Lenovo (Beijing) Limited)
HKLM\...\Run: [BoxSync] => C:\Program Files\Box\Box Sync\BoxSync.exe [5705984 2015-02-10] (Box, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [3122528 2010-10-28] (Lenovo)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-06-30] (CyberLink Corp.)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [CloneCDTray] => C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-29] (SlySoft, Inc.)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [icq] => C:\Users\Rasty\AppData\Roaming\ICQM\icq.exe [27598184 2013-06-08] (ICQ)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1840424 2008-06-24] (Nero AG)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [26232152 2015-02-19] (Google)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [OneDrive] => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\OneDrive.exe [281256 2015-03-06] (Microsoft Corporation)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\MountPoints2: {034a2ef5-1c72-11e4-b70b-88ae1de14d87} - G:\setup.exe
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\MountPoints2: {1342a689-cf8e-11e2-a1e6-88ae1de14d87} - C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\default.htm
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Watch.lnk
ShortcutTarget: Watch.lnk -> C:\Program Files (x86)\MUSTEK 1248UB\Driver\WATCH.exe (Common Group)
Startup: C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Rasty\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Watch.lnk
ShortcutTarget: Watch.lnk -> C:\Program Files (x86)\MUSTEK 1248UB\Driver\WATCH.exe (Common Group)
ShellIconOverlayIdentifiers: [ BoxSyncFileLocked] -> {2a607da5-abe8-358e-a881-c0f5faf2d3a5} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncFileLockedByOther] -> {f7d2951f-0b6b-346c-99ec-69cffc30a364} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncNotSynced] -> {5ea95e3d-3e46-3812-b03c-49785fa67d41} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncProblem] -> {a88b7184-bfa1-3d14-8efb-2225df9699bc} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncSynced] -> {c89f9943-8f58-3eca-bd55-a658f53b2f48} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\amd64\FileSyncShell64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\amd64\FileSyncShell64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\amd64\FileSyncShell64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll ()
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\FileSyncShell.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\FileSyncShell.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\FileSyncShell.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rasty\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rasty\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rasty\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=ds ... 753905&ir=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=ds ... 753905&ir=
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.reerd.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.p ... 753905&ir=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.p ... 753905&ir=
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.p ... 753905&ir=
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> {0315EAF4-ABE1-44A1-8974-E7FDAD38DA8D} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.p ... 753905&ir=
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerm ... 5&tsp=5015
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2013-12-11] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-05-20] (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [2013-12-11] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2013-12-11] (Kaspersky Lab ZAO)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14] (Microsoft Corp.)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-05-20] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-29] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-29] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2013-12-11] (Kaspersky Lab ZAO)
Toolbar: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> No Name - {5347542D-5637-006A-76A7-7A786E7484D7} - No File
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: HKLM-x32 {F713DD2F-B93F-4196-88AB-6104F12E643F} http://192.168.1.5/PCViewX.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default
FF Homepage: hxxp://www.google.sk/
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-06] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll [2013-01-24] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-06] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-29] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll [2013-01-24] ( Microsoft Corporation)
FF Plugin-x32: @qq.com/npchrome -> C:\Program Files (x86)\Common Files\Tencent\Npchrome\npchrome.dll [2014-04-14] (Tencent)
FF Plugin-x32: @qq.com/npqscall -> C:\Program Files (x86)\Common Files\Tencent\NPQSCALL\npqscall.dll [2014-04-14] (Tencent)
FF Plugin-x32: @qq.com/TXSSO -> C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.2.1\Bin\npSSOAxCtrlForPTLogin.dll [2013-04-08] (Tencent)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default\user.js [2013-12-09]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default\searchplugins\Mysearchdial.xml [2013-12-15]
FF Extension: S3.Google Translator - C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default\Extensions\s3google@translator.xpi [2014-05-08]
FF Extension: AniWeather - C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi [2014-05-08]
FF HKLM-x32\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-06-07]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Kaspersky виртуелна тастатура - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-06-07]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Gevaarlijke websiteblokkering - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-06-07]
Chrome:
=======
CHR Profile: C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-28]
CHR Extension: (Google Drive) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-28]
CHR Extension: (YouTube) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-28]
CHR Extension: (Google Search) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-28]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2015-02-28]
CHR Extension: (Content Blocker) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2015-02-28]
CHR Extension: (Kaspersky Protection) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpoimibckejjdjcfbdnajaicnklhfplh [2015-02-28]
CHR Extension: (Gmail) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-28]
CHR HKU\S-1-5-21-3387448284-3213569423-970032522-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2013-03-15]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2013-03-15]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2013-03-15]
CHR HKLM-x32\...\Chrome\Extension: [lpoimibckejjdjcfbdnajaicnklhfplh] - https://chrome.google.com/webstore/deta ... icnklhfplh [Not Found]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [28696 2014-12-09] (Box, Inc.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [864032 2009-08-11] (Broadcom Corporation.)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2013-06-14] (Macrovision Europe Ltd.) [File not signed]
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-06-24] (Nero AG)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5436176 2015-02-17] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 cxbu0x64; C:\Windows\System32\DRIVERS\cxbu0x64.sys [191224 2014-05-14] (HID Global Corporation)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-08-25] (Disc Soft Ltd)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
S3 GT680x; C:\Windows\System32\Drivers\gt680x.sys [22528 2007-02-06] ( )
S3 GT680x; C:\Windows\SysWOW64\Drivers\gt680x.sys [22528 2007-02-06] ( )
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [91008 2014-05-20] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [628320 2014-05-20] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-22] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [177864 2015-02-17] (Kaspersky Lab ZAO)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-08-24] (Duplex Secure Ltd.)
U3 ahsd6sf6; C:\Windows\System32\Drivers\ahsd6sf6.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero size file/folder)
U3 BcmSqlStartupSvc; No ImagePath
U3 IGRS; No ImagePath
U2 IviRegMgr; No ImagePath
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
U2 ReadyComm.DirectRouter; No ImagePath
U2 RichVideo; No ImagePath
U3 SQLWriter; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-11 17:36 - 2015-03-11 17:37 - 00026886 _____ () C:\Users\Rasty\Desktop\FRST.txt
2015-03-11 17:36 - 2015-03-11 17:36 - 00000000 ____D () C:\FRST
2015-03-11 17:35 - 2015-03-11 17:35 - 02095616 _____ (Farbar) C:\Users\Rasty\Desktop\FRST64.exe
2015-03-11 17:33 - 2015-03-11 17:34 - 00112640 _____ (forum.viry.cz) C:\Users\Rasty\Desktop\FRSTLauncher.exe
2015-03-11 17:32 - 2015-03-11 17:32 - 00112640 _____ (forum.viry.cz) C:\Users\Rasty\Downloads\FRSTLauncher.exe
2015-03-11 16:55 - 2015-03-11 16:55 - 00000000 ___HD () C:\OneDriveTemp
2015-03-06 06:10 - 2015-03-06 06:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-19 15:19 - 2015-02-19 15:19 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-02-19 15:19 - 2015-02-19 15:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-02-19 15:18 - 2015-02-19 15:19 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-02-19 15:18 - 2015-02-19 15:19 - 00000000 ____D () C:\Program Files\iTunes
2015-02-19 15:18 - 2015-02-19 15:18 - 00000000 ____D () C:\Program Files\iPod
2015-02-19 15:18 - 2015-02-19 15:18 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-02-16 19:15 - 2015-03-10 20:06 - 00000290 __RSH () C:\ProgramData\ntuser.pol
2015-02-09 10:53 - 2015-02-15 10:27 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\ViberPC
2015-02-09 10:53 - 2015-02-09 10:53 - 00000996 _____ () C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber.lnk
2015-02-09 10:53 - 2015-02-09 10:53 - 00000988 _____ () C:\Users\Rasty\Desktop\Viber.lnk
2015-02-09 10:52 - 2015-02-15 10:23 - 00000000 ____D () C:\Users\Rasty\AppData\Local\Viber
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-11 17:29 - 2013-06-07 17:15 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-03-11 17:29 - 2013-06-07 13:46 - 00000000 ____D () C:\Download
2015-03-11 17:04 - 2010-10-28 12:38 - 01805383 _____ () C:\windows\WindowsUpdate.log
2015-03-11 17:04 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-11 17:04 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-11 16:58 - 2013-06-10 08:00 - 00000000 ___RD () C:\Users\Rasty\Dropbox
2015-03-11 16:57 - 2014-12-22 20:48 - 00000000 ____D () C:\Users\Rasty\AppData\Local\Box Sync
2015-03-11 16:57 - 2013-06-10 07:53 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\Dropbox
2015-03-11 16:56 - 2014-07-06 19:20 - 00000000 ___RD () C:\Users\Rasty\Disk Google
2015-03-11 16:55 - 2014-12-22 20:21 - 00000000 ___RD () C:\Users\Rasty\iCloudDrive
2015-03-11 16:55 - 2013-06-10 07:52 - 00000000 ___RD () C:\Users\Rasty\SkyDrive
2015-03-11 16:55 - 2010-10-28 13:39 - 01591534 _____ () C:\FaceProv.log
2015-03-11 16:55 - 2010-10-28 13:34 - 00000000 ____D () C:\ProgramData\VeriFace
2015-03-11 16:54 - 2014-07-06 19:19 - 00000932 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-11 16:54 - 2010-10-28 13:01 - 00050196 _____ () C:\windows\PFRO.log
2015-03-11 16:54 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-11 16:54 - 2009-07-14 05:51 - 00066769 _____ () C:\windows\setupact.log
2015-03-11 16:47 - 2014-07-06 19:19 - 00000936 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-11 16:46 - 2013-06-07 16:44 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\The Bat!
2015-03-11 16:45 - 2013-06-07 14:20 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-03-11 02:31 - 2013-09-10 10:15 - 00003970 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{FAF163ED-F2EF-4F13-87CB-77DC548B5B19}
2015-03-10 19:45 - 2013-06-07 16:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-10 18:51 - 2013-06-07 16:46 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\Skype
2015-03-10 13:48 - 2014-07-06 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-03-08 08:13 - 2013-06-10 18:06 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\uTorrent
2015-03-06 17:52 - 2014-02-20 17:27 - 00002160 _____ () C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-03-06 09:18 - 2013-06-12 21:03 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\vlc
2015-03-05 17:14 - 2013-06-07 19:12 - 00000000 ____D () C:\Jdownloader
2015-03-04 17:51 - 2014-04-14 08:57 - 00000000 ____D () C:\Users\Rasty\Documents\Tencent Files
2015-03-01 15:29 - 2014-07-06 19:19 - 00000000 ____D () C:\Program Files (x86)\Google
2015-03-01 15:27 - 2013-06-07 16:38 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-03-01 15:27 - 2013-06-07 16:38 - 00000000 ____D () C:\Program Files\CCleaner
2015-02-28 19:55 - 2014-09-25 15:17 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-02-28 19:55 - 2013-06-07 16:46 - 00000000 ____D () C:\ProgramData\Skype
2015-02-28 08:06 - 2013-12-06 21:53 - 00000000 ____D () C:\Filmy
2015-02-27 14:07 - 2013-07-10 07:32 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2015-02-24 20:42 - 2009-07-14 06:13 - 00779266 _____ () C:\windows\system32\PerfStringBackup.INI
2015-02-21 21:05 - 2013-06-10 18:07 - 00000000 ____D () C:\uTorrent
2015-02-20 22:58 - 2014-01-30 20:25 - 00000180 _____ () C:\Users\Rasty\advanced_ip_scanner_MAC.bin
2015-02-19 21:55 - 2014-01-07 08:04 - 00000000 ____D () C:\Users\Rasty\AppData\Local\Deployment
2015-02-19 15:18 - 2013-12-13 17:49 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-02-19 12:10 - 2015-01-23 16:37 - 00000971 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-02-19 12:10 - 2015-01-23 16:37 - 00000959 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-02-18 23:41 - 2015-01-23 17:57 - 00000000 ____D () C:\Program Files (x86)\FastShare
2015-02-17 16:06 - 2012-08-13 15:49 - 00177864 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\kneps.sys
2015-02-16 19:15 - 2009-07-14 04:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2015-02-16 19:15 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2015-02-15 21:11 - 2013-06-07 19:11 - 00000000 ____D () C:\Program Files (x86)\JDownloader
2015-02-15 10:29 - 2013-06-10 08:00 - 00001017 _____ () C:\Users\Rasty\Desktop\Dropbox.lnk
2015-02-15 10:29 - 2013-06-10 07:59 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-14 15:02 - 2013-06-07 18:52 - 00000000 ____D () C:\Youtube
2015-02-13 00:22 - 2014-12-22 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Box Sync
2015-02-11 08:51 - 2014-02-03 14:57 - 00000000 ____D () C:\Program Files (x86)\Immo Bypass
2015-02-09 21:25 - 2013-06-09 15:22 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
==================== Files in the root of some directories =======
2013-09-05 17:46 - 2015-02-15 08:29 - 0001106 _____ () C:\Users\Rasty\AppData\Roaming\ex_log.txt
2014-07-15 21:21 - 2014-11-23 23:43 - 0000028 _____ () C:\Users\Rasty\AppData\Roaming\msjqhv.dat
2014-07-15 21:21 - 2014-07-15 21:21 - 0010055 _____ () C:\Users\Rasty\AppData\Roaming\mspqebx.dat
2013-09-10 12:09 - 2013-09-10 12:09 - 0003584 _____ () C:\Users\Rasty\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-10-09 20:52 - 2013-10-09 20:52 - 0007597 _____ () C:\Users\Rasty\AppData\Local\Resmon.ResmonCfg
2014-08-05 08:23 - 2014-08-05 08:30 - 0000041 ___SH () C:\ProgramData\.zreglib
2013-09-04 21:11 - 2013-09-04 21:11 - 0005085 _____ () C:\ProgramData\abhevmgi.xhu
Some content of TEMP:
====================
C:\Users\Rasty\AppData\Local\Temp\125.69128721188144_Update.exe
C:\Users\Rasty\AppData\Local\Temp\21517uninstall.exe
C:\Users\Rasty\AppData\Local\Temp\AskSLib.dll
C:\Users\Rasty\AppData\Local\Temp\bitool.dll
C:\Users\Rasty\AppData\Local\Temp\DeltaTB.exe
C:\Users\Rasty\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp7suqx8.dll
C:\Users\Rasty\AppData\Local\Temp\DTLite4481-0347.exe
C:\Users\Rasty\AppData\Local\Temp\DTLite4491-0356.exe
C:\Users\Rasty\AppData\Local\Temp\FreemakeVideoConverter_4.0.4.3.exe
C:\Users\Rasty\AppData\Local\Temp\Ionic.Zip.dll
C:\Users\Rasty\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Rasty\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Rasty\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Rasty\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Rasty\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Rasty\AppData\Local\Temp\log4net.dll
C:\Users\Rasty\AppData\Local\Temp\ochelper.exe
C:\Users\Rasty\AppData\Local\Temp\OptimizerPro.exe
C:\Users\Rasty\AppData\Local\Temp\ose00000.exe
C:\Users\Rasty\AppData\Local\Temp\qqsafeud.exe
C:\Users\Rasty\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Rasty\AppData\Local\Temp\Sqlite3.dll
C:\Users\Rasty\AppData\Local\Temp\uninst1.exe
C:\Users\Rasty\AppData\Local\Temp\Updater.exe
C:\Users\Rasty\AppData\Local\Temp\uttA3.tmp.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.0.7-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.1.1-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.1.2-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.1.3-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.1.5-win32.exe
C:\Users\Rasty\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Kaspersky Anti-Virus (Disabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AS: Kaspersky Anti-Virus (Disabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Rasty\Desktop" je 100 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACPW06EN
"C:\Program Files\ACD Systems\ACDSee Pro\6.0\ACDSeePro6InTouch2.exe" /pid ACPW06EN [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Rasty (administrator) on RASTY-PC on 11-03-2015 17:41:45
Running from C:\Users\Rasty\Desktop
Loaded Profiles: Rasty (Available profiles: Rasty)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Box, Inc.) C:\Program Files\Box\Box Sync\BoxSync.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Vimicro) C:\Program Files (x86)\USB Camera2\VM332_STI.EXE
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Common Group) C:\Program Files (x86)\MUSTEK 1248UB\Driver\WATCH.exe
(Dropbox, Inc.) C:\Users\Rasty\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
() C:\Program Files\Box\Box Sync\BoxSyncMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Ghisler Software GmbH) C:\Totalcmd\TOTALCMD64.EXE
(forum.viry.cz) C:\Users\Rasty\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [521272 2010-03-22] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [2598280 2010-06-24] (ELAN Microelectronics Corp.)
HKLM\...\Run: [OnekeyStudio] => C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [776608 2009-12-19] (Lenovo)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4367808 2009-12-17] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [6988736 2009-12-17] (Lenovo (Beijing) Limited)
HKLM\...\Run: [BoxSync] => C:\Program Files\Box\Box Sync\BoxSync.exe [5705984 2015-02-10] (Box, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [536576 2010-01-19] (Vimicro)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [3122528 2010-10-28] (Lenovo)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-06-30] (CyberLink Corp.)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [CloneCDTray] => C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-29] (SlySoft, Inc.)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [icq] => C:\Users\Rasty\AppData\Roaming\ICQM\icq.exe [27598184 2013-06-08] (ICQ)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1840424 2008-06-24] (Nero AG)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2014-10-20] (Apple Inc.)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [26232152 2015-02-19] (Google)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\Run: [OneDrive] => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\OneDrive.exe [281256 2015-03-06] (Microsoft Corporation)
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\MountPoints2: {034a2ef5-1c72-11e4-b70b-88ae1de14d87} - G:\setup.exe
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\...\MountPoints2: {1342a689-cf8e-11e2-a1e6-88ae1de14d87} - C:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\default.htm
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Watch.lnk
ShortcutTarget: Watch.lnk -> C:\Program Files (x86)\MUSTEK 1248UB\Driver\WATCH.exe (Common Group)
Startup: C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Rasty\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Watch.lnk
ShortcutTarget: Watch.lnk -> C:\Program Files (x86)\MUSTEK 1248UB\Driver\WATCH.exe (Common Group)
ShellIconOverlayIdentifiers: [ BoxSyncFileLocked] -> {2a607da5-abe8-358e-a881-c0f5faf2d3a5} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncFileLockedByOther] -> {f7d2951f-0b6b-346c-99ec-69cffc30a364} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncNotSynced] -> {5ea95e3d-3e46-3812-b03c-49785fa67d41} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncProblem] -> {a88b7184-bfa1-3d14-8efb-2225df9699bc} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncSynced] -> {c89f9943-8f58-3eca-bd55-a658f53b2f48} => C:\windows\system32\mscoree.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\amd64\FileSyncShell64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\amd64\FileSyncShell64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\amd64\FileSyncShell64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\windows\system32\IcnOvrly.dll ()
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\FileSyncShell.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\FileSyncShell.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Rasty\AppData\Local\Microsoft\OneDrive\17.3.4724.0224\FileSyncShell.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rasty\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rasty\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Rasty\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=ds ... 753905&ir=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.mysearchdial.com/?f=1&a=ds ... 753905&ir=
HKU\S-1-5-21-3387448284-3213569423-970032522-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.reerd.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.p ... 753905&ir=
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.p ... 753905&ir=
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.p ... 753905&ir=
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> {0315EAF4-ABE1-44A1-8974-E7FDAD38DA8D} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://start.mysearchdial.com/results.p ... 753905&ir=
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.searchgol.com/?q={searchTerm ... 5&tsp=5015
SearchScopes: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2013-12-11] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-05-20] (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll [2013-12-11] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2013-12-11] (Kaspersky Lab ZAO)
BHO-x32: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [2009-01-14] (Microsoft Corp.)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-05-20] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-29] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-29] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll [2013-12-11] (Kaspersky Lab ZAO)
Toolbar: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKU\S-1-5-21-3387448284-3213569423-970032522-1000 -> No Name - {5347542D-5637-006A-76A7-7A786E7484D7} - No File
DPF: HKLM {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
DPF: HKLM-x32 {F713DD2F-B93F-4196-88AB-6104F12E643F} http://192.168.1.5/PCViewX.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default
FF Homepage: hxxp://www.google.sk/
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-06] ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll [2013-01-24] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-06] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-29] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll [2013-01-24] ( Microsoft Corporation)
FF Plugin-x32: @qq.com/npchrome -> C:\Program Files (x86)\Common Files\Tencent\Npchrome\npchrome.dll [2014-04-14] (Tencent)
FF Plugin-x32: @qq.com/npqscall -> C:\Program Files (x86)\Common Files\Tencent\NPQSCALL\npqscall.dll [2014-04-14] (Tencent)
FF Plugin-x32: @qq.com/TXSSO -> C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.2.1\Bin\npSSOAxCtrlForPTLogin.dll [2013-04-08] (Tencent)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF user.js: detected! => C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default\user.js [2013-12-09]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default\searchplugins\Mysearchdial.xml [2013-12-15]
FF Extension: S3.Google Translator - C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default\Extensions\s3google@translator.xpi [2014-05-08]
FF Extension: AniWeather - C:\Users\Rasty\AppData\Roaming\Mozilla\Firefox\Profiles\5o1w4zc9.default\Extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi [2014-05-08]
FF HKLM-x32\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-06-07]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Kaspersky виртуелна тастатура - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-06-07]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Gevaarlijke websiteblokkering - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-06-07]
Chrome:
=======
CHR Profile: C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-28]
CHR Extension: (Google Drive) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-28]
CHR Extension: (YouTube) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-28]
CHR Extension: (Google Search) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-28]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2015-02-28]
CHR Extension: (Content Blocker) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2015-02-28]
CHR Extension: (Kaspersky Protection) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpoimibckejjdjcfbdnajaicnklhfplh [2015-02-28]
CHR Extension: (Gmail) - C:\Users\Rasty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-28]
CHR HKU\S-1-5-21-3387448284-3213569423-970032522-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\urladvisor.crx [2013-03-15]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\content_blocker_chrome.crx [2013-03-15]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\ChromeExt\virtkbd.crx [2013-03-15]
CHR HKLM-x32\...\Chrome\Extension: [lpoimibckejjdjcfbdnajaicnklhfplh] - https://chrome.google.com/webstore/deta ... icnklhfplh [Not Found]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [28696 2014-12-09] (Box, Inc.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [864032 2009-08-11] (Broadcom Corporation.)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2013-06-14] (Macrovision Europe Ltd.) [File not signed]
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-06-24] (Nero AG)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5436176 2015-02-17] (TeamViewer GmbH)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 cxbu0x64; C:\Windows\System32\DRIVERS\cxbu0x64.sys [191224 2014-05-14] (HID Global Corporation)
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-08-25] (Disc Soft Ltd)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
S3 GT680x; C:\Windows\System32\Drivers\gt680x.sys [22528 2007-02-06] ( )
S3 GT680x; C:\Windows\SysWOW64\Drivers\gt680x.sys [22528 2007-02-06] ( )
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [91008 2014-05-20] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [628320 2014-05-20] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-06-22] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [177864 2015-02-17] (Kaspersky Lab ZAO)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-08-24] (Duplex Secure Ltd.)
U3 ahsd6sf6; C:\Windows\System32\Drivers\ahsd6sf6.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero size file/folder)
U3 BcmSqlStartupSvc; No ImagePath
U3 IGRS; No ImagePath
U2 IviRegMgr; No ImagePath
S3 lmimirr; system32\DRIVERS\lmimirr.sys [X]
U2 ReadyComm.DirectRouter; No ImagePath
U2 RichVideo; No ImagePath
U3 SQLWriter; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-11 17:38 - 2015-03-11 17:38 - 00040449 _____ () C:\Users\Rasty\Desktop\FRST3.txt
2015-03-11 17:36 - 2015-03-11 17:42 - 00026546 _____ () C:\Users\Rasty\Desktop\FRST.txt
2015-03-11 17:36 - 2015-03-11 17:41 - 00000000 ____D () C:\FRST
2015-03-11 17:35 - 2015-03-11 17:35 - 02095616 _____ (Farbar) C:\Users\Rasty\Desktop\FRST64.exe
2015-03-11 17:33 - 2015-03-11 17:34 - 00112640 _____ (forum.viry.cz) C:\Users\Rasty\Desktop\FRSTLauncher.exe
2015-03-11 17:32 - 2015-03-11 17:32 - 00112640 _____ (forum.viry.cz) C:\Users\Rasty\Downloads\FRSTLauncher.exe
2015-03-11 16:55 - 2015-03-11 16:55 - 00000000 ___HD () C:\OneDriveTemp
2015-03-06 06:10 - 2015-03-06 06:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-02-19 15:19 - 2015-02-19 15:19 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-02-19 15:19 - 2015-02-19 15:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-02-19 15:18 - 2015-02-19 15:19 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-02-19 15:18 - 2015-02-19 15:19 - 00000000 ____D () C:\Program Files\iTunes
2015-02-19 15:18 - 2015-02-19 15:18 - 00000000 ____D () C:\Program Files\iPod
2015-02-19 15:18 - 2015-02-19 15:18 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-02-16 19:15 - 2015-03-10 20:06 - 00000290 __RSH () C:\ProgramData\ntuser.pol
2015-02-09 10:53 - 2015-02-15 10:27 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\ViberPC
2015-02-09 10:53 - 2015-02-09 10:53 - 00000996 _____ () C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Viber.lnk
2015-02-09 10:53 - 2015-02-09 10:53 - 00000988 _____ () C:\Users\Rasty\Desktop\Viber.lnk
2015-02-09 10:52 - 2015-02-15 10:23 - 00000000 ____D () C:\Users\Rasty\AppData\Local\Viber
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-11 17:29 - 2013-06-07 17:15 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2015-03-11 17:29 - 2013-06-07 13:46 - 00000000 ____D () C:\Download
2015-03-11 17:04 - 2010-10-28 12:38 - 01805383 _____ () C:\windows\WindowsUpdate.log
2015-03-11 17:04 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-11 17:04 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-11 16:58 - 2013-06-10 08:00 - 00000000 ___RD () C:\Users\Rasty\Dropbox
2015-03-11 16:57 - 2014-12-22 20:48 - 00000000 ____D () C:\Users\Rasty\AppData\Local\Box Sync
2015-03-11 16:57 - 2013-06-10 07:53 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\Dropbox
2015-03-11 16:56 - 2014-07-06 19:20 - 00000000 ___RD () C:\Users\Rasty\Disk Google
2015-03-11 16:55 - 2014-12-22 20:21 - 00000000 ___RD () C:\Users\Rasty\iCloudDrive
2015-03-11 16:55 - 2013-06-10 07:52 - 00000000 ___RD () C:\Users\Rasty\SkyDrive
2015-03-11 16:55 - 2010-10-28 13:39 - 01591534 _____ () C:\FaceProv.log
2015-03-11 16:55 - 2010-10-28 13:34 - 00000000 ____D () C:\ProgramData\VeriFace
2015-03-11 16:54 - 2014-07-06 19:19 - 00000932 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-11 16:54 - 2010-10-28 13:01 - 00050196 _____ () C:\windows\PFRO.log
2015-03-11 16:54 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-11 16:54 - 2009-07-14 05:51 - 00066769 _____ () C:\windows\setupact.log
2015-03-11 16:47 - 2014-07-06 19:19 - 00000936 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-11 16:46 - 2013-06-07 16:44 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\The Bat!
2015-03-11 16:45 - 2013-06-07 14:20 - 00000830 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-03-11 02:31 - 2013-09-10 10:15 - 00003970 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{FAF163ED-F2EF-4F13-87CB-77DC548B5B19}
2015-03-10 19:45 - 2013-06-07 16:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-10 18:51 - 2013-06-07 16:46 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\Skype
2015-03-10 13:48 - 2014-07-06 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-03-08 08:13 - 2013-06-10 18:06 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\uTorrent
2015-03-06 17:52 - 2014-02-20 17:27 - 00002160 _____ () C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-03-06 09:18 - 2013-06-12 21:03 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\vlc
2015-03-05 17:14 - 2013-06-07 19:12 - 00000000 ____D () C:\Jdownloader
2015-03-04 17:51 - 2014-04-14 08:57 - 00000000 ____D () C:\Users\Rasty\Documents\Tencent Files
2015-03-01 15:29 - 2014-07-06 19:19 - 00000000 ____D () C:\Program Files (x86)\Google
2015-03-01 15:27 - 2013-06-07 16:38 - 00000822 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-03-01 15:27 - 2013-06-07 16:38 - 00000000 ____D () C:\Program Files\CCleaner
2015-02-28 19:55 - 2014-09-25 15:17 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-02-28 19:55 - 2013-06-07 16:46 - 00000000 ____D () C:\ProgramData\Skype
2015-02-28 08:06 - 2013-12-06 21:53 - 00000000 ____D () C:\Filmy
2015-02-27 14:07 - 2013-07-10 07:32 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2015-02-24 20:42 - 2009-07-14 06:13 - 00779266 _____ () C:\windows\system32\PerfStringBackup.INI
2015-02-21 21:05 - 2013-06-10 18:07 - 00000000 ____D () C:\uTorrent
2015-02-20 22:58 - 2014-01-30 20:25 - 00000180 _____ () C:\Users\Rasty\advanced_ip_scanner_MAC.bin
2015-02-19 21:55 - 2014-01-07 08:04 - 00000000 ____D () C:\Users\Rasty\AppData\Local\Deployment
2015-02-19 15:18 - 2013-12-13 17:49 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-02-19 12:10 - 2015-01-23 16:37 - 00000971 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-02-19 12:10 - 2015-01-23 16:37 - 00000959 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-02-18 23:41 - 2015-01-23 17:57 - 00000000 ____D () C:\Program Files (x86)\FastShare
2015-02-17 16:06 - 2012-08-13 15:49 - 00177864 _____ (Kaspersky Lab ZAO) C:\windows\system32\Drivers\kneps.sys
2015-02-16 19:15 - 2009-07-14 04:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2015-02-16 19:15 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2015-02-15 21:11 - 2013-06-07 19:11 - 00000000 ____D () C:\Program Files (x86)\JDownloader
2015-02-15 10:29 - 2013-06-10 08:00 - 00001017 _____ () C:\Users\Rasty\Desktop\Dropbox.lnk
2015-02-15 10:29 - 2013-06-10 07:59 - 00000000 ____D () C:\Users\Rasty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-14 15:02 - 2013-06-07 18:52 - 00000000 ____D () C:\Youtube
2015-02-13 00:22 - 2014-12-22 20:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Box Sync
2015-02-11 08:51 - 2014-02-03 14:57 - 00000000 ____D () C:\Program Files (x86)\Immo Bypass
2015-02-09 21:25 - 2013-06-09 15:22 - 00000000 ____D () C:\ProgramData\YTD Video Downloader
==================== Files in the root of some directories =======
2013-09-05 17:46 - 2015-02-15 08:29 - 0001106 _____ () C:\Users\Rasty\AppData\Roaming\ex_log.txt
2014-07-15 21:21 - 2014-11-23 23:43 - 0000028 _____ () C:\Users\Rasty\AppData\Roaming\msjqhv.dat
2014-07-15 21:21 - 2014-07-15 21:21 - 0010055 _____ () C:\Users\Rasty\AppData\Roaming\mspqebx.dat
2013-09-10 12:09 - 2013-09-10 12:09 - 0003584 _____ () C:\Users\Rasty\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-10-09 20:52 - 2013-10-09 20:52 - 0007597 _____ () C:\Users\Rasty\AppData\Local\Resmon.ResmonCfg
2014-08-05 08:23 - 2014-08-05 08:30 - 0000041 ___SH () C:\ProgramData\.zreglib
2013-09-04 21:11 - 2013-09-04 21:11 - 0005085 _____ () C:\ProgramData\abhevmgi.xhu
Some content of TEMP:
====================
C:\Users\Rasty\AppData\Local\Temp\125.69128721188144_Update.exe
C:\Users\Rasty\AppData\Local\Temp\21517uninstall.exe
C:\Users\Rasty\AppData\Local\Temp\AskSLib.dll
C:\Users\Rasty\AppData\Local\Temp\bitool.dll
C:\Users\Rasty\AppData\Local\Temp\DeltaTB.exe
C:\Users\Rasty\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp7suqx8.dll
C:\Users\Rasty\AppData\Local\Temp\DTLite4481-0347.exe
C:\Users\Rasty\AppData\Local\Temp\DTLite4491-0356.exe
C:\Users\Rasty\AppData\Local\Temp\FreemakeVideoConverter_4.0.4.3.exe
C:\Users\Rasty\AppData\Local\Temp\Ionic.Zip.dll
C:\Users\Rasty\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Rasty\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Rasty\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Rasty\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\Rasty\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Rasty\AppData\Local\Temp\log4net.dll
C:\Users\Rasty\AppData\Local\Temp\ochelper.exe
C:\Users\Rasty\AppData\Local\Temp\OptimizerPro.exe
C:\Users\Rasty\AppData\Local\Temp\ose00000.exe
C:\Users\Rasty\AppData\Local\Temp\qqsafeud.exe
C:\Users\Rasty\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Rasty\AppData\Local\Temp\Sqlite3.dll
C:\Users\Rasty\AppData\Local\Temp\uninst1.exe
C:\Users\Rasty\AppData\Local\Temp\Updater.exe
C:\Users\Rasty\AppData\Local\Temp\uttA3.tmp.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.0.7-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.0.8-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.1.1-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.1.2-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.1.3-win32.exe
C:\Users\Rasty\AppData\Local\Temp\vlc-2.1.5-win32.exe
C:\Users\Rasty\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-10 20:56
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:421.81 GB) (Free:87.07 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:7.82 GB) NTFS
Available physical RAM: 4904.79 MB
Total physical RAM: 8054.85 MB
Percentage of memory in use: 39%
==================== MBR and Partition Table ==================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 26EAAABB)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=421.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\Windows:4DEE705DE0BB9E57
AlternateDataStreams: C:\ProgramData\Temp:9F6F0CCB
==================== Security Center ==================
AV: Kaspersky Anti-Virus (Disabled - Up to date) {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
AS: Kaspersky Anti-Virus (Disabled - Up to date) {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Rasty\Desktop" je 100 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACPW06EN
"C:\Program Files\ACD Systems\ACDSee Pro\6.0\ACDSeePro6InTouch2.exe" /pid ACPW06EN [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Malware v pc a spomaleny pc.
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Malware v pc a spomaleny pc.
ahoj,
vycisti PC s:
MBAM - ADWCleaner - CCleaner
vycisti PC s:
MBAM - ADWCleaner - CCleaner
FRST |ADWCleaner |MBAM |CCleaner |AVPTool
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/
V prípade spokojnosti je možné podporiť fórum https://platba.viry.cz/payment/