Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

vyskakují reklamní okna, zpomaluje inetrnet

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
lilithka
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 09 dub 2015 17:51

vyskakují reklamní okna, zpomaluje inetrnet

#1 Příspěvek od lilithka »

Prosím o pomoc, vyskakují reklamní okna, dlouho se načítají stránky. Když jsem začala pátrat po problemu a narazila na tyto stránky, nějak to samo přestalo :-) Ale to bude asi jen na oko, po projetí spyhuntrem to taky na chvíli přestalo, ale druhý den zas nanovo. Snad jsem podle návodu vše správně pochopila a hodím sem co mi vyjelo:

Logfile of random's system information tool 1.10 (written by random/random)
Run by OP at 2015-04-09 21:29:12
Microsoft Windows 7 Home Premium
System drive C: has 19 GB (17%) free of 110 GB
Total RAM: 2048 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:33:21, on 9.4.2015
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Windows\tsnpstd3.exe
C:\Windows\vsnpstd3.exe
C:\Program Files\ATnotes\ATnotes.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Users\OP\Downloads\SpyHunter\SpyHunter4.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\OP\Downloads\RSIT.exe
C:\Program Files\trend micro\OP.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll
O4 - HKLM\..\Run: [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\Windows\vsnpstd3.exe
O4 - HKCU\..\Run: [ATnotes.exe] C:\Program Files\ATnotes\ATnotes.exe
O4 - HKCU\..\Run: [GamingMouseEditor] "C:\Program Files (x86)\GamingMouseEditor\GamingMouseEditor\GamingMouseEditor.exe" Minimum
O4 - HKCU\..\Run: [GSplay.exe] C:\Users\FonkyFokel\Desktop\GSplay.exe
O4 - HKCU\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ask Update Service (APNMCP) - Unknown owner - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (file missing)
O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe (file missing)
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files (x86)\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 5219 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\suprize_notification_service.job - C:\Program Files\suprize\suprize_notification_service.exe /url='http://cdn.selectbestopt.com/notf_sys/index.html' /crregname='suprize' /appid='73143' /srcid='2913' /bic='ff7644c2d0a2c59e2addec71788f5808' /verifier='2edf504572f7985922eebc4f452b6aef' /installerversion='1.50.3.10' /statsdomain='http://stats.buildomserv.com/data.gif?' /errorsdomain='http://stats.buildomserv.com/data.gif?' /monetizationdomain='http://logs.buildomserv.com/monetization.gif?' /installationtime='1427918304' /runfrom='task' /brwtype='notbg' /postponedhours='6'
C:\Windows\tasks\suprize_updating_service.job - C:\Program Files\suprize\suprize_updating_service.exe /campid=2913 /verid=1 /url=http://cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=suprize_updating_service /funurl=http://stats.buildomserv.com
C:\Windows\tasks\uxWsS4rimCqJi.job - C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe --c=oCwpLWXH8v87RVjHPBYShhxOqA1P8KBL7cGivLF8N3FwFuKssx/i4QUxAVk5QSlCafTITD0lFC0Vkng+V6A85LEXs0cErMuAFeh0AaUcTa9Dth1iS77nNEeOhSPmRYbCnQR4YpQfbZbQIQLrh7kJHAM1FdwtXO9Qsw6uMrOAnLglb72RdlCX2TjYBnE7oDdQOxGjVSDBG2D1FJ1YjvrHy8MCmvXzBOx7c03uCSmZhquvpz5FWm6U5fReaIrVmIkLRDN3TViTFb25LzjSBo4B25Tg7yVCNXdaEc5rUppQ53bHQEkP0Q0SgXzdeeOLSzbkVC0FgavRBc37cB/JMzQ3ng==

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}]
MSS+ Identifier - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09 96128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ApnTBMon"=C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe []
"WinFastDTV"=C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [2014-03-04 103936]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2009-02-06 170496]
"tsnpstd3"=C:\Windows\tsnpstd3.exe [2007-03-30 262144]
"snpstd3"=C:\Windows\vsnpstd3.exe [2006-09-18 843776]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ATnotes.exe"=C:\Program Files\ATnotes\ATnotes.exe [2005-01-05 1015808]
"GamingMouseEditor"=C:\Program Files (x86)\GamingMouseEditor\GamingMouseEditor\GamingMouseEditor.exe Minimum []
"GSplay.exe"=C:\Users\FonkyFokel\Desktop\GSplay.exe []
"WinFast Schedule"=C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2013-01-09 2916352]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2015-03-25 31682144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2009-02-06 170496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mswdceSrv]
C:\Windows\system32\mswdce.vbe msajnmtn mswjxuuf []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv]
C:\Windows\inf\ntvdm.vbe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2015-03-25 31682144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-02-10 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe [2007-03-03 341488]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
C:\PROGRA~1\MCAFEE~1\385C9A~1.150\SSSCHE~1.EXE [2014-04-09 279456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^OP^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MEGAsync.lnk]
C:\PROGRA~2\MEGAsync\MEGAsync.exe [2015-02-27 4019144]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.dvacm"=C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"=C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"=C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.dvacm_vspx6"=c:\PROGRA~1\Corel\CORELV~2\COMMON~1\Vio\Dvacm.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-04-09 21:29:16 ----D---- C:\Program Files\trend micro
2015-04-09 21:29:12 ----D---- C:\rsit
2015-04-07 17:51:32 ----A---- C:\Windows\amcap.exe
2015-04-07 17:51:31 ----A---- C:\Windows\vsnpstd3.exe
2015-04-07 17:51:31 ----A---- C:\Windows\tsnpstd3.exe
2015-04-07 17:51:30 ----A---- C:\Windows\snpstd3.src
2015-04-07 17:51:30 ----A---- C:\Windows\snpstd3.ini
2015-04-07 17:51:29 ----A---- C:\Windows\system32\drivers\snpstd3.sys
2015-04-07 17:51:28 ----D---- C:\Program Files\Common Files\snpstd3
2015-04-07 17:51:28 ----A---- C:\Windows\system32\vsnpstd3.dll
2015-04-07 17:51:28 ----A---- C:\Windows\system32\rsnpstd3.dll
2015-04-07 17:51:28 ----A---- C:\Windows\system32\csnpstd3.dll
2015-04-07 17:51:28 ----A---- C:\Windows\csnpstd3.dll
2015-04-07 17:37:57 ----RD---- C:\Program Files\Skype
2015-04-07 17:37:57 ----D---- C:\Program Files\Common Files\Skype
2015-04-06 19:45:01 ----A---- C:\Windows\system32\drivers\wfeaglxt.sys
2015-04-06 19:26:40 ----A---- C:\Windows\system32\unicows.dll
2015-04-06 19:26:39 ----D---- C:\Program Files\Common Files\ArcSoft
2015-04-06 19:25:43 ----D---- C:\Users\OP\AppData\Roaming\InstallShield Installation Information
2015-04-06 19:25:18 ----D---- C:\Users\OP\AppData\Roaming\InstallShield
2015-04-06 07:15:56 ----D---- C:\Program Files (x86)
2015-04-03 06:42:34 ----A---- C:\Windows\ntbtlog.txt
2015-04-02 17:20:13 ----D---- C:\Users\OP\AppData\Roaming\Mozilla
2015-04-02 16:42:19 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-04-02 16:41:45 ----D---- C:\ProgramData\Malwarebytes
2015-04-02 16:41:45 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2015-04-02 16:41:45 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-04-02 16:41:45 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-04-02 16:41:45 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-04-02 15:52:20 ----D---- C:\UpdateChromeLinksLogs
2015-04-02 15:52:13 ----A---- C:\Windows\system32\msvcr71.dll
2015-04-02 15:52:13 ----A---- C:\Windows\system32\mfc71.dll
2015-04-02 15:52:13 ----A---- C:\Windows\system32\gdiplus.dll
2015-04-02 14:54:02 ----D---- C:\Program Files\Mozilla Firefox
2015-04-02 12:07:44 ----D---- C:\Program Files\Enigma Software Group
2015-03-28 10:34:55 ----D---- C:\Windows\pss
2015-03-22 19:49:03 ----D---- C:\Users\OP\AppData\Roaming\Skype
2015-03-22 19:48:41 ----D---- C:\ProgramData\Skype
2015-03-12 17:36:14 ----D---- C:\Program Files\Common Files\SWF Studio
2015-03-12 17:35:40 ----D---- C:\Users\OP\AppData\Roaming\Disney Interactive
2015-03-11 18:29:17 ----D---- C:\ProgramData\Vivendi Universal Games
2015-03-11 18:29:04 ----D---- C:\Program Files\Na scene(TM)

======List of files/folders modified in the last 1 month======

2015-04-09 21:31:56 ----D---- C:\Windows\Temp
2015-04-09 21:29:16 ----RD---- C:\Program Files
2015-04-09 21:28:56 ----D---- C:\Users\OP\AppData\Roaming\vlc
2015-04-09 10:29:07 ----D---- C:\!stazeno
2015-04-09 08:41:22 ----D---- C:\Windows\System32
2015-04-09 08:41:22 ----D---- C:\Windows\inf
2015-04-09 08:41:22 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-04-07 17:56:21 ----SHD---- C:\System Volume Information
2015-04-07 17:52:42 ----D---- C:\Windows\Prefetch
2015-04-07 17:51:42 ----D---- C:\Windows\system32\catroot
2015-04-07 17:51:40 ----D---- C:\Windows\system32\DriverStore
2015-04-07 17:51:32 ----D---- C:\Windows
2015-04-07 17:51:32 ----A---- C:\Windows\win.ini
2015-04-07 17:51:31 ----D---- C:\Windows\twain_32
2015-04-07 17:51:29 ----D---- C:\Windows\system32\drivers
2015-04-07 17:51:28 ----D---- C:\Program Files\Common Files
2015-04-07 17:51:27 ----HD---- C:\Program Files\InstallShield Installation Information
2015-04-07 17:38:23 ----SHD---- C:\Windows\Installer
2015-04-07 06:54:59 ----D---- C:\Windows\system32\catroot2
2015-04-06 20:26:24 ----D---- C:\Windows\Offline Web Pages
2015-04-06 20:09:39 ----D---- C:\Program Files\CCFile
2015-04-06 19:45:38 ----D---- C:\Windows\system32\WinFast
2015-04-06 19:25:58 ----D---- C:\Program Files\WinFast
2015-04-06 07:41:47 ----HD---- C:\ProgramData
2015-04-06 07:41:47 ----D---- C:\Program Files\GreenTree Applications
2015-04-05 17:43:18 ----D---- C:\Windows\Tasks
2015-04-05 17:43:18 ----D---- C:\Windows\system32\Tasks
2015-04-04 21:27:39 ----D---- C:\Windows\system32\config
2015-04-02 16:57:03 ----D---- C:\Windows\Performance
2015-04-02 16:24:18 ----D---- C:\Users\OP\AppData\Roaming\DAEMON Tools Lite
2015-04-02 16:23:40 ----D---- C:\Windows\Logs
2015-04-02 16:20:02 ----RSD---- C:\Windows\Fonts
2015-04-02 15:56:12 ----D---- C:\AeriaGames
2015-04-02 09:56:57 ----D---- C:\Program Files\Disney princezna - Moje pohádkové dobrodružství
2015-03-28 21:06:27 ----D---- C:\WinFast WorkArea
2015-03-12 17:36:11 ----A---- C:\Windows\disney.ini
2015-03-12 17:35:40 ----D---- C:\Program Files\Disney Interactive
2015-03-11 18:29:18 ----A---- C:\Windows\ka.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-05-12 243128]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO32.SYS [2014-06-10 22688]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-07-14 4194816]
R3 ausbmon;Advanced USB Port Monitor Filter Driver; \??\C:\Windows\system32\drivers\ausbmon.sys [2009-03-02 19744]
R3 esgiguard;esgiguard; \??\C:\Users\OP\Downloads\SpyHunter\esgiguard.sys [2010-01-27 5248]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-03-17 23256]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-04-09 119512]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-03-17 51928]
R3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-14 139776]
R3 SNPSTD3;USB PC Camera (SNPSTD3); C:\Windows\system32\DRIVERS\snpstd3.sys [2007-04-03 10246144]
R3 WFLR6654;WinFast DTV1800 H (XC3028); C:\Windows\system32\drivers\wfeaglxt.sys [2009-10-21 433920]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 DIRECTIO;DIRECTIO; \??\C:\Program Files\PerformanceTest\DirectIo32.sys [2014-04-24 28088]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2014-12-28 17488]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 26176]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 34944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-02-06 109056]
R2 Capture Device Service;Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [2007-03-06 198168]
R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2015-03-17 1080120]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2015-03-17 1871160]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2010-03-10 189728]
R2 TeamViewer;TeamViewer 10; C:\Program Files\TeamViewer\TeamViewer_Service.exe [2015-01-30 5429520]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
S2 APNMCP;Ask Update Service; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe []
S2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-05-18 116648]
S2 mi-raysat_3dsmax9_32;mental ray 3.5 Satellite (32-bit); C:\Program Files (x86)\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe []
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-02-18 315488]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05 267440]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2014-05-18 116648]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [2014-04-09 235696]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: vyskakují reklamní okna, zpomaluje inetrnet

#2 Příspěvek od altrok »

Zdravim :bye:


:arrow: Odinstalujte SpyHunter - odmita ucast na srovnavacich testech antimalwarovych nastroju a nektere zdroje ho radi mezi tzv. rogueware. Zkratka jeho cinnost i ucinnost je velice diskutabilni.

:arrow: Odinstalujte :arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).

:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan, pote na Cleaning
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

lilithka
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 09 dub 2015 17:51

Re: vyskakují reklamní okna, zpomaluje inetrnet

#3 Příspěvek od lilithka »

odinstalovala jsem MCAffe .... ale nevím, kde najít toho Spyhuntera na odinstalování. V programech není. Spouštěla jsem ho vlastně ze stažené a rozbalené složky. Se mnou to bude možná těžší, nejsem až takovej profík na PC. Předem se omlouvám :oops:

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: vyskakují reklamní okna, zpomaluje inetrnet

#4 Příspěvek od altrok »

Nic se nedeje :) Pokracujte tedy dalsimi kroky a pak se k nemu vratime ;)
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

lilithka
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 09 dub 2015 17:51

Re: vyskakují reklamní okna, zpomaluje inetrnet

#5 Příspěvek od lilithka »

povedlo se :|


# AdwCleaner v4.201 - Log vytvořen 09/04/2015 v 22:33:16
# Aktualizováno 08/04/2015 by Xplode
# Databáze : 2015-04-08.1 [Server]
# Operační system : Windows 7 Home Premium (x86)
# Uživatelské jméno : OP - OP-PC
# Spuštěno z : C:\Users\OP\Desktop\adwcleaner_4.201.exe
# Nastavení : Čištění

***** [ Služby ] *****

[#] Služba Smazáno : APNMCP

***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ProgramData\apn
Složka Smazáno : C:\ProgramData\baidu
Složka Smazáno : C:\Program Files\GreenTree Applications
Složka Smazáno : C:\Program Files\Zrychleni Pocitace
Soubor Smazáno : C:\END

***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Klíč Smazáno : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnTbMon]
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IECT3329621
Klíč Smazáno : HKLM\SOFTWARE\Classes\Toolbar.CT3329621
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{3A1209A4-8568-40F0-9B5E-4A06A2A06417}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511831162}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555835562}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566836662}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544834462}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3A1209A4-8568-40F0-9B5E-4A06A2A06417}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110511831162}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Klíč Smazáno : HKCU\Software\Conduit
Klíč Smazáno : HKCU\Software\GlobalUpdate
Klíč Smazáno : HKCU\Software\AppDataLow\Toolbar
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Tbccint
Klíč Smazáno : HKCU\Software\AppDataLow\Software\TbccintSearchScopes
Klíč Smazáno : HKLM\SOFTWARE\Conduit
Klíč Smazáno : HKLM\SOFTWARE\GlobalUpdate
Klíč Smazáno : HKU\.DEFAULT\Software\AskPartnerNetwork
Data Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>

***** [ Prohlížeče ] *****

-\\ Internet Explorer v8.0.7600.16385


-\\ Mozilla Firefox v


-\\ Google Chrome v41.0.2272.118

[C:\Users\OP\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Extension] : bopakagnckmlgajfccecajhnimjiiedh
[C:\Users\OP\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Extension] : aaaailpifkkekipiachodfkfmgmiapmp
[C:\Users\OP\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Startup_URLs] : hxxp://www.search.ask.com/?tpid=SGT-V7&o=APN11 ... 05-29&psv=
[C:\Users\OP\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Default_Search_Provider_Data] : {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}{google:contextualSearchVersion}ie={inputEncoding}",
"usage_count": 0
}
},
"extensions": {
"known_disabled": null,
"settings": {
"aaaailpifkkekipiachodfkfmgmiapmp": {
"ack_external": true,
"active_permissions": {
"api": [ "bookmarks", "contentSettings", "contextMenus", "cookies", "geolocation", "history", "idle", "management", "notifications", "storage", "tabs", "unlimitedStorage", "webRequest", "webRequestBlocking", "webRequestInternal" ],
"explicit_host": [ "chrome://favicon/*", "hxxp://*/*", "hxxps://*/*" ],
"manifest_permissions": [ ],
"scriptable_host": [ "*://*.ask.com/

*************************

AdwCleaner[R0].txt - [6383 bytů] - [09/04/2015 22:31:22]
AdwCleaner[S0].txt - [6256 bytů] - [09/04/2015 22:33:16]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6314 bytů] ##########

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: vyskakují reklamní okna, zpomaluje inetrnet

#6 Příspěvek od altrok »

:arrow: Sikulka :idea: Dejte ted prosim log FRST.txt a prilozte i Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

lilithka
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 09 dub 2015 17:51

Re: vyskakují reklamní okna, zpomaluje inetrnet

#7 Příspěvek od lilithka »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by OP (administrator) on OP-PC on 09-04-2015 22:54:26
Running from C:\Users\OP\Desktop
Loaded Profiles: OP (Available profiles: OP)
Platform: Microsoft Windows 7 Home Premium (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(InterVideo Inc.) C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Leadtek Research Inc.) C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(SONIX) C:\Windows\tsnpstd3.exe
() C:\Windows\vsnpstd3.exe
(Leadtek Research Inc.) C:\Program Files\WinFast\WFDTV\WFWIZ.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\OP\Desktop\FRSTLauncher (2).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [WinFastDTV] => C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [103936 2014-03-04] (Leadtek Research Inc.)
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [170496 2009-02-06] (ArcSoft Inc.)
HKLM\...\Run: [tsnpstd3] => C:\Windows\tsnpstd3.exe [262144 2007-03-30] (SONIX)
HKLM\...\Run: [snpstd3] => C:\Windows\vsnpstd3.exe [843776 2006-09-18] ()
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [ATnotes.exe] => C:\Program Files\ATnotes\ATnotes.exe [1015808 2005-01-05] (Thomas Ascher)
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [GamingMouseEditor] => "C:\Program Files (x86)\GamingMouseEditor\GamingMouseEditor\GamingMouseEditor.exe" Minimum
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [GSplay.exe] => C:\Users\FonkyFokel\Desktop\GSplay.exe
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [WinFast Schedule] => C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2916352 2013-01-09] (Leadtek Research Inc.)
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.)
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\MountPoints2: K - K:\autorun\autorun.exe
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\MountPoints2: {538bc678-d9e8-11e3-980b-00004d22f619} - J:\autoplay.exe
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX32.dll ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX32.dll ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX32.dll ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-866419223-3740971703-2059610383-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-866419223-3740971703-2059610383-1000 -> {46404466-90F4-4AA4-80A2-01FAFD386862} URL =
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\OP\AppData\Roaming\Mozilla\Firefox\Profiles\bcjakel3.default
FF Homepage: seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin HKU\S-1-5-21-866419223-3740971703-2059610383-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\OP\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-07-07] (Unity Technologies ApS)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]

Chrome:
=======
CHR Profile: C:\Users\OP\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Wallet) - C:\Users\OP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2009-02-06] (ArcSoft Inc.)
R2 Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5429520 2015-01-30] (TeamViewer GmbH)
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)
S2 Autodesk Licensing Service; "C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe" [X]
S2 mi-raysat_3dsmax9_32; "C:\Program Files (x86)\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 ausbmon; C:\Windows\system32\drivers\ausbmon.sys [19744 2009-03-02] (AGG Software (http://www.aggsoft.com))
S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo32.sys [28088 2014-04-24] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-05-12] (Disc Soft Ltd)
S3 gdrv; C:\Windows\gdrv.sys [17488 2014-12-28] (Windows (R) 2000 DDK provider)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [22688 2014-06-10] (REALiX(tm))
R3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10246144 2007-04-03] (Sonix Co. Ltd.)
R3 WFLR6654; C:\Windows\System32\drivers\wfeaglxt.sys [433920 2009-10-21] (Leadtek Research Inc.)
S3 esgiguard; \??\C:\Users\OP\Downloads\SpyHunter\esgiguard.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-09 22:54 - 2015-04-09 22:54 - 00008665 _____ () C:\Users\OP\Desktop\FRST.txt
2015-04-09 22:53 - 2015-04-09 22:54 - 00000000 ____D () C:\FRST
2015-04-09 22:52 - 2015-04-09 22:52 - 01135104 _____ (Farbar) C:\Users\OP\Desktop\FRST.exe
2015-04-09 22:50 - 2015-04-09 22:50 - 00112640 _____ (forum.viry.cz) C:\Users\OP\Desktop\FRSTLauncher (2).exe
2015-04-09 22:46 - 2015-04-09 22:46 - 02095616 _____ (Farbar) C:\Users\OP\Desktop\FRST64.exe
2015-04-09 22:31 - 2015-04-09 22:33 - 00000000 ____D () C:\AdwCleaner
2015-04-09 22:04 - 2015-04-09 22:04 - 02217984 _____ () C:\Users\OP\Desktop\adwcleaner_4.201.exe
2015-04-09 21:29 - 2015-04-09 21:33 - 00000000 ____D () C:\rsit
2015-04-09 21:29 - 2015-04-09 21:33 - 00000000 ____D () C:\Program Files\trend micro
2015-04-09 21:28 - 2015-04-09 21:28 - 01107968 _____ () C:\Users\OP\Downloads\RSIT.exe
2015-04-09 19:25 - 2015-04-09 19:59 - 387092480 _____ () C:\Users\OP\Downloads\Zivi-mrtvi.S03E14.Korist.DVDrip.CZ.avi
2015-04-09 19:25 - 2015-04-09 19:57 - 387377152 _____ () C:\Users\OP\Downloads\Zivi-mrtvi.S03E15.Zivot-plny-utrpeni.DVDrip.CZ.avi
2015-04-09 16:09 - 2015-04-09 16:44 - 387360768 _____ () C:\Users\OP\Downloads\Zivi-mrtvi.S03E13.Mezi-trema-ocima.DVDrip.CZ.avi
2015-04-07 17:51 - 2015-04-07 17:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-04-07 17:51 - 2015-04-07 17:51 - 00000000 ____D () C:\Program Files\Common Files\snpstd3
2015-04-07 17:51 - 2007-04-03 19:25 - 10246144 _____ (Sonix Co. Ltd.) C:\Windows\system32\Drivers\snpstd3.sys
2015-04-07 17:51 - 2007-03-30 17:44 - 00262144 _____ (SONIX) C:\Windows\tsnpstd3.exe
2015-04-07 17:51 - 2007-03-30 15:09 - 00061440 _____ ( ) C:\Windows\system32\vsnpstd3.dll
2015-04-07 17:51 - 2007-03-21 15:23 - 00172032 _____ ( ) C:\Windows\system32\rsnpstd3.dll
2015-04-07 17:51 - 2006-09-18 14:12 - 00843776 _____ () C:\Windows\vsnpstd3.exe
2015-04-07 17:51 - 2006-07-03 10:31 - 00094208 _____ (Microsoft Corporation) C:\Windows\amcap.exe
2015-04-07 17:51 - 2005-11-23 13:55 - 00053248 _____ ( ) C:\Windows\system32\csnpstd3.dll
2015-04-07 17:51 - 2005-11-23 13:55 - 00053248 _____ ( ) C:\Windows\csnpstd3.dll
2015-04-07 17:51 - 2004-02-27 17:36 - 00015498 _____ () C:\Windows\snpstd3.ini
2015-04-07 17:51 - 2004-02-27 17:36 - 00013023 _____ () C:\Windows\snpstd3.src
2015-04-07 17:50 - 2009-12-10 17:30 - 00000000 ____D () C:\Users\OP\Downloads\StarCam 370i SN9C105 driver
2015-04-07 17:49 - 2015-04-07 17:50 - 09810527 _____ () C:\Users\OP\Downloads\StarCam370i_SN9C105.zip
2015-04-07 17:39 - 2015-04-07 17:39 - 00000000 ____D () C:\Users\OP\Tracing
2015-04-07 17:37 - 2015-04-07 17:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-07 17:37 - 2015-04-07 17:37 - 00002719 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-07 17:37 - 2015-04-07 17:37 - 00000000 ___RD () C:\Program Files\Skype
2015-04-07 17:37 - 2015-04-07 17:37 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-04-07 17:36 - 2015-04-07 17:36 - 01380960 _____ (Skype Technologies S.A.) C:\Users\OP\Downloads\SkypeSetup.exe
2015-04-07 17:34 - 2015-04-07 17:34 - 00090283 _____ () C:\Users\Public\Documents\Bez názvu.wma
2015-04-06 19:45 - 2009-10-21 18:30 - 00433920 _____ (Leadtek Research Inc.) C:\Windows\system32\Drivers\wfeaglxt.sys
2015-04-06 19:44 - 2015-04-06 19:44 - 02463306 _____ (Leadtek ) C:\Users\OP\Downloads\DTV1800-H---win-7-32bit.exe
2015-04-06 19:27 - 2015-04-06 19:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Connect
2015-04-06 19:26 - 2015-04-06 19:26 - 00000000 ____D () C:\Program Files\Common Files\ArcSoft
2015-04-06 19:26 - 2005-07-16 02:35 - 00245408 _____ (Microsoft Corporation) C:\Windows\system32\unicows.dll
2015-04-06 19:25 - 2015-04-06 20:54 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinFast PVR2
2015-04-06 19:25 - 2015-04-06 19:25 - 00001858 _____ () C:\Users\OP\Desktop\RCConfig.lnk
2015-04-06 19:25 - 2015-04-06 19:25 - 00001698 _____ () C:\Users\OP\Desktop\WinFast PVR2.lnk
2015-04-06 19:25 - 2015-04-06 19:25 - 00000000 ____D () C:\Users\OP\Documents\WFRCConfig
2015-04-06 19:25 - 2015-04-06 19:25 - 00000000 ____D () C:\Users\OP\AppData\Roaming\InstallShield Installation Information
2015-04-06 19:25 - 2015-04-06 19:25 - 00000000 ____D () C:\Users\OP\AppData\Roaming\InstallShield
2015-04-06 19:18 - 2015-04-06 19:21 - 53660897 _____ (Macrovision Corporation) C:\Users\OP\Downloads\WinFastPVR2_setup_20357.exe
2015-04-06 07:15 - 2015-04-06 07:15 - 00000000 ____D () C:\Program Files (x86)
2015-04-05 18:41 - 2015-04-05 18:41 - 00243504 _____ () C:\Users\OP\Downloads\Firefox Setup Stub 37.0.1.exe
2015-04-04 08:40 - 2015-04-04 08:48 - 147779940 _____ () C:\Users\OP\Downloads\Scooby-Doo.Na.stopě.S01E08.Tajemný.lunapark.SDTV.x264-PiP.mp4.crdownload
2015-04-04 08:16 - 2015-04-04 08:25 - 147532360 _____ () C:\Users\OP\Downloads\Scooby-Doo.Na.stopě.S01E17.Sněžný.muž.SDTV.x264-PiP.mp4.crdownload
2015-04-03 23:02 - 2015-04-03 23:35 - 415449088 _____ () C:\Users\OP\Downloads\Zoufale-manzelky-S07E18-CZ---Chvilky-v-Lese-by-Stifler.avi
2015-04-03 21:39 - 2015-04-03 22:11 - 415717376 _____ () C:\Users\OP\Downloads\Zoufale-manzelky-S07E17-CZ---Vsechno-je-jinak-vse-pri-starem-by-Stifler.avi
2015-04-03 19:32 - 2015-04-03 20:09 - 415629312 _____ () C:\Users\OP\Downloads\Zoufale-manzelky-S07E16-CZ---Smysl-Zivota-by-Stifler.avi
2015-04-02 22:50 - 2015-04-02 22:50 - 00001173 _____ () C:\Users\OP\Desktop\Stažené soubory – zástupce.lnk
2015-04-02 20:55 - 2015-04-09 22:34 - 00002728 _____ () C:\Windows\setupact.log
2015-04-02 20:55 - 2015-04-09 22:27 - 00003828 _____ () C:\Windows\PFRO.log
2015-04-02 20:55 - 2015-04-02 20:55 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-02 17:20 - 2015-04-02 17:20 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Mozilla
2015-04-02 16:41 - 2015-04-02 16:41 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-02 15:52 - 2015-04-02 15:52 - 01700352 _____ (Microsoft Corporation) C:\Windows\system32\gdiplus.dll
2015-04-02 15:52 - 2015-04-02 15:52 - 01060864 _____ (Microsoft Corporation) C:\Windows\system32\mfc71.dll
2015-04-02 15:52 - 2015-04-02 15:52 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\msvcr71.dll
2015-04-02 14:54 - 2015-04-05 19:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-02 12:07 - 2015-04-02 12:07 - 00000000 ____D () C:\Program Files\Enigma Software Group
2015-04-01 22:58 - 2015-04-02 15:50 - 00000004 _____ () C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-04-01 21:58 - 2015-04-09 22:34 - 00001278 _____ () C:\Windows\Tasks\suprize_notification_service.job
2015-04-01 21:58 - 2015-04-09 22:34 - 00000986 _____ () C:\Windows\Tasks\uxWsS4rimCqJi.job
2015-04-01 21:58 - 2015-04-09 22:34 - 00000640 _____ () C:\Windows\Tasks\suprize_updating_service.job
2015-03-31 10:14 - 2015-03-31 10:14 - 00004387 _____ () C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi
2015-03-28 10:34 - 2015-03-28 10:34 - 00000000 ____D () C:\Windows\pss
2015-03-22 19:49 - 2015-04-09 22:35 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Skype
2015-03-22 19:49 - 2015-03-22 19:49 - 00000000 ____D () C:\Users\OP\AppData\Local\Skype
2015-03-22 19:48 - 2015-04-07 17:38 - 00000000 ____D () C:\ProgramData\Skype
2015-03-18 11:23 - 2015-03-18 11:23 - 00000000 _____ () C:\Users\OP\Desktop\jentak.txt.txt
2015-03-12 17:36 - 2015-03-12 17:36 - 00000000 ____D () C:\Program Files\Common Files\SWF Studio
2015-03-12 17:35 - 2015-03-12 17:35 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Disney Interactive
2015-03-11 18:29 - 2015-03-11 18:29 - 00001858 _____ () C:\Users\Public\Desktop\Na scéně(TM).lnk
2015-03-11 18:29 - 2015-03-11 18:29 - 00000000 ____D () C:\ProgramData\Vivendi Universal Games
2015-03-11 18:29 - 2015-03-11 18:29 - 00000000 ____D () C:\Program Files\Na scene(TM)

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-09 22:43 - 2014-05-18 15:13 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-09 22:43 - 2014-05-18 15:13 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-09 22:41 - 2009-07-14 06:34 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-09 22:41 - 2009-07-14 06:34 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-09 22:40 - 2014-05-12 14:31 - 01575230 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-09 22:39 - 2015-01-25 23:27 - 00000000 ____D () C:\Users\OP\AppData\Roaming\vlc
2015-04-09 22:38 - 2014-06-26 20:46 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-09 22:37 - 2014-05-12 14:13 - 01689075 _____ () C:\Windows\WindowsUpdate.log
2015-04-09 22:34 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-09 10:29 - 2014-05-12 14:35 - 00000000 ____D () C:\!stazeno
2015-04-07 20:50 - 2014-12-23 11:53 - 00000000 ____D () C:\Users\OP\AppData\Local\CrashDumps
2015-04-07 17:51 - 2014-05-12 15:02 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-04-07 17:51 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\twain_32
2015-04-07 17:51 - 2009-07-14 04:04 - 00000461 _____ () C:\Windows\win.ini
2015-04-07 17:39 - 2014-05-12 14:27 - 00000000 ____D () C:\Users\OP
2015-04-06 20:26 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\Offline Web Pages
2015-04-06 20:09 - 2015-01-30 13:33 - 00000000 ____D () C:\Program Files\CCFile
2015-04-06 19:45 - 2014-05-12 15:01 - 00000000 ____D () C:\Windows\system32\WinFast
2015-04-06 19:25 - 2014-05-12 15:05 - 00000000 ____D () C:\Program Files\WinFast
2015-04-05 18:22 - 2014-05-12 14:47 - 00078664 _____ () C:\Users\OP\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-05 06:46 - 2014-05-18 15:13 - 00002187 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-04-02 16:57 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\Performance
2015-04-02 16:57 - 2009-07-14 06:33 - 00326664 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-02 16:24 - 2014-10-21 13:10 - 00000000 ____D () C:\Users\OP\.gimp-2.4
2015-04-02 16:24 - 2014-05-12 18:17 - 00000000 ____D () C:\Users\OP\AppData\Roaming\DAEMON Tools Lite
2015-04-02 15:56 - 2014-06-08 17:27 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames
2015-04-02 15:56 - 2014-06-08 16:10 - 00000000 ____D () C:\AeriaGames
2015-04-02 15:52 - 2014-12-25 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2015-04-02 12:27 - 2014-10-22 15:07 - 00000000 ____D () C:\Users\OP\.gimp-2.6
2015-04-02 09:56 - 2015-01-03 09:22 - 00000000 ____D () C:\Program Files\Disney princezna - Moje pohádkové dobrodružství
2015-03-30 15:25 - 2014-06-09 22:41 - 00026176 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2015-03-29 18:47 - 2009-07-14 06:53 - 00032550 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-28 21:06 - 2014-05-12 15:09 - 00000000 ____D () C:\WinFast WorkArea
2015-03-12 17:36 - 2014-05-12 18:20 - 00003214 _____ () C:\Windows\disney.ini
2015-03-12 17:35 - 2014-05-12 18:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disney Interactive
2015-03-12 17:35 - 2014-05-12 18:20 - 00000000 ____D () C:\Program Files\Disney Interactive
2015-03-11 18:29 - 2014-05-12 18:12 - 00000179 _____ () C:\Windows\ka.ini
2015-03-11 18:29 - 2014-05-12 18:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Barbie(TM)

==================== Files in the root of some directories =======

2015-03-31 10:14 - 2015-03-31 10:14 - 0004387 _____ () C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi
2014-10-21 12:57 - 2014-10-21 12:57 - 0000880 _____ () C:\Users\OP\AppData\Local\recently-used.xbel
2014-07-14 20:28 - 2014-07-15 10:21 - 0007605 _____ () C:\Users\OP\AppData\Local\Resmon.ResmonCfg
2014-12-30 13:36 - 2014-12-30 13:36 - 0000000 _____ () C:\Users\OP\AppData\Local\{9428E6B3-F727-4C29-8FA2-7EC770CB9E1C}
2015-02-17 00:25 - 2015-02-17 00:25 - 0000000 _____ () C:\Users\OP\AppData\Local\{B48D895F-CD3F-48F6-8FFD-A6B5F05B1BEC}

Some content of TEMP:
====================
C:\Users\OP\AppData\Local\Temp\Quarantine.exe
C:\Users\OP\AppData\Local\Temp\sqlite3.dll
C:\Users\OP\AppData\Local\Temp\Update.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\suprize_notification_service.job => C:\Program Files\suprize\suprize_notification_service.exeă/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='suprize' /appid='73143' /srcid='2913' /bic='ff7644c2d0a2c59e2addec71788f5808' /verifier='2edf504572f7985922eebc4f452b6aef' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif
Task: C:\Windows\Tasks\suprize_updating_service.job => C:\Program Files\suprize\suprize_updating_service.exe¨ /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=suprize_updating_service /funurl=http:/stats.buildomserv.com
Task: C:\Windows\Tasks\uxWsS4rimCqJi.job => C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\OP\Desktop" je 605 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui
"C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mswdceSrv
"C:\Windows\system32\mswdce.vbe" msajnmtn mswjxuuf [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv
C:\Windows\inf\ntvdm.vbe [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload
C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk
C:\PROGRA~1\MCAFEE~1\385C9A~1.150\SSSCHE~1.EXE [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^OP^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MEGAsync.lnk
C:\PROGRA~2\MEGAsync\MEGAsync.exe


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================




Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by OP at 2015-04-09 22:55:18
Running from C:\Users\OP\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

1C Company\Space Rangers 2 - Reboot Add-on (HKLM\...\Space Rangers 2) (Version: - )
Adobe Flash Player 10 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 10.0.12.36 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Advanced USB Port Monitor (HKLM\...\Advanced USB Port Monitor_is1) (Version: 2 - AGG Software)
ATI Catalyst Install Manager (HKLM\...\{37D9C685-0F4B-2D8E-59E3-3CE151CE0051}) (Version: 3.0.754.0 - ATI Technologies, Inc.)
ATI Problem Report Wizard (Version: 3.0.754.0 - ATI Technologies) Hidden
ATnotes Version 9.5 (HKLM\...\ATnotes_is1) (Version: 9.5 - Thomas Ascher)
Automatické vypnutí počítače 1.0 (HKLM\...\Automatické vypnutí počítače (AVP)_is1) (Version: - Aplikator SoftWare)
Barbie(TM) Dobrodružství s koňmi(TM) (HKLM\...\{F827DB7E-9F8F-46BA-9F22-46CE2CEE1D7E}) (Version: 1.00.0000 - )
BS.Player FREE (HKLM\...\BSPlayerf) (Version: 2.68.1077 - AB Team, d.o.o.)
ccc-core-static (Version: 2010.0210.2339.42455 - Název společnosti:) Hidden
CCFile 3.6 (HKLM\...\CCFile_is1) (Version: - www.ccfile.net)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
Codec-TS SDK (HKLM\...\{28FB7853-A6ED-4F67-8635-9F0E863FC0AD}) (Version: - ArcSoft)
Contents (Version: 16.0.0.106 - Corel Corporation) Hidden
Corel VideoStudio Ultimate X6 (HKLM\...\_{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.0.0.106 - Corel Corporation)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Dead Space 3 CZ v1.0 (HKLM\...\{D4329609-4102-4F8C-B83F-7FE024EEA314}_is1) (Version: 1.0 - Visceral Games)
Deadfall Adventures (HKLM\...\Deadfall Adventures_R.G. Mechanics_is1) (Version: - R.G. Mechanics, spider91)
De-interlace SDK (HKLM\...\{9A0E0340-C3D7-42D1-96D4-64179FD456AE}) (Version: - ArcSoft)
Disney Popelka (HKLM\...\{2048F008-BDCD-485E-B552-B60E15BDC668}) (Version: 1.0 - Disney Interactive)
Disney Princezna - Kouzelná cesta (HKLM\...\{E375D72E-5343-4F73-986C-1B00C35F1DFC}) (Version: 1.0 - Disney Interactive Studios)
Disney princezna - Moje pohádkové dobrodružství verzia 1.0 (HKLM\...\Disney princezna - Moje pohádkové dobrodružství_is1) (Version: 1.0 - CzTorrent.net)
Fallout 1.5 - Resurrection verze 1.3 (HKLM\...\{E9C6352B-9B0D-4C4F-9374-72F3F20CB75F}_is1) (Version: 1.3 - Resurrection team)
Fallout2 (HKLM\...\Fallout2) (Version: - )
FormatFactory 3.5.0.0 (HKLM\...\FormatFactory) (Version: 3.5.0.0 - Format Factory)
GIMP 2.6.12-2 (HKLM\...\WinGimp-2.0_is1) (Version: 2.6.12 - The GIMP Team)
Google Chrome (HKLM\...\Google Chrome) (Version: 41.0.2272.118 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
Half-Life 2: Episode One (HKLM\...\Half-Life 2: Episode One_is1) (Version: 2013.09.21 - Valve Corporation)
Heroes of Might and Magic® III Complete (HKLM\...\Heroes of Might and Magic® III) (Version: - )
HWiNFO32 Version 4.38 (HKLM\...\HWiNFO32_is1) (Version: 4.38 - Martin Malík - REALiX)
HydraVision (Version: 4.2.128.0 - ATI Technologies Inc.) Hidden
ICA (Version: 16.0.0.106 - Corel Corporation) Hidden
InterVideo DeviceService (HKLM\...\{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}) (Version: 1.0.0 - InterVideo)
IPM_VS_Pro (Version: 16.0 - Corel Corporation) Hidden
Jewel Quest (HKLM\...\Jewel Quest_is1) (Version: 1.0 - Media Contact LLC)
KALENDARE (HKLM\...\KALENDARE_KALENDARE) (Version: - )
MEGAsync (HKLM\...\MEGAsync) (Version: - Mega Limited)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Games for Windows - LIVE (HKLM\...\{4D243BA7-9AC4-46D1-90E5-EEB88974F501}) (Version: 2.0.687.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}) (Version: 2.0.687.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MSI Star Cam 370i (HKLM\...\{ECD03DA7-5952-406A-8156-5F0C93618D1F}) (Version: 5.20.0.202_WQHL - Sonix)
MultiRes (remove only) (HKLM\...\MultiRes (remove only)) (Version: - )
MyDefrag v4.3.1 (HKLM\...\MyDefrag v4.3.1_is1) (Version: 4.0.0.0 - J.C. Kessels)
Na scéně(TM) (HKLM\...\{25F2658C-9F46-4DF6-8D5C-61B4CAC04E5F}) (Version: 1.00.0000 - )
OpenOffice.org 3.4.1 (HKLM\...\{1E0AF527-0B8E-4F8A-BA27-CB3C359998C6}) (Version: 3.41.9593 - Apache Software Foundation)
PerformanceTest v8.0 (HKLM\...\PerformanceTest 8_is1) (Version: 8.0.1034.0 - Passmark Software)
Prasátko a jeho velký piknik (HKLM\...\{1D6FB37A-CBCA-11D6-8940-0002A5E32BEF}) (Version: - )
Rajče průvodce verze 1.59.54.269 (HKLM\...\rajce.net_is1) (Version: - rajce.net)
Setup (Version: 16.0.0.106 - Corel Corporation) Hidden
Share (Version: 16.0.0.106 - Corel Corporation) Hidden
Skins (Version: 2010.0210.2339.42455 - ATI) Hidden
Skype™ 7.3 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
SlimPDF Reader 1.0 (HKLM\...\{7E1FEE27-F869-4D4B-8AA3-64C7FD99BD7C}_is1) (Version: 1.0 - Investintech.com Inc.)
SmartSound Common Data (HKLM\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Common Data (Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks 5 (HKLM\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (Version: 5.1.6 - SmartSound Software Inc.) Hidden
Sweet Home 3D version 4.5 (HKLM\...\Sweet Home 3D_is1) (Version: - eTeks)
TeamViewer 10 (HKLM\...\TeamViewer) (Version: 10.0.38475 - TeamViewer)
Toddler Keys (HKLM\...\{7339E7E7-FB6A-46EC-8303-D31E655EF617}) (Version: 00.97.0000 - none)
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: 8.51a - Ghisler Software GmbH)
TT-SB SDK (HKLM\...\{AF9848E2-5F19-4E49-9E6E-044FBDC28404}) (Version: - ArcSoft)
UFO:AI 2.2 (HKLM\...\UFO:Alien Invasion) (Version: 2.2 - UFO:AI Team)
Ulead VideoStudio 11 (HKLM\...\InstallShield_{F99F9E24-EE2F-47FD-AEB0-FDB82859B5C9}) (Version: 11.0.0.0000 - InterVideo Digital Technology Corporation)
Unity Web Player (HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\UnityWebPlayer) (Version: 4.5.2f1 - Unity Technologies ApS)
Video Rotator V1.0 (HKLM\...\Video Rotator_is1) (Version: - VideoRotator.com)
VideoStudio (Version: 11.0.0.0000 - InterVideo Digital Technology Corporation) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
VSClassic (Version: 16.0.0.106 - Corel Corporation) Hidden
VSHelp (Version: 16.0.0.106 - Corel Corporation) Hidden
VSUltimate (Version: 16.0.0.106 - Corel Corporation) Hidden
Warface Launcher (Beta) (HKLM\...\{28D1723C-31C4-4A83-9799-DFFB3739026D}) (Version: 1.0.0 - Crytek GmbH)
Winamp (HKLM\...\Winamp) (Version: 5.66 - Nullsoft, Inc)
Windows Media Encoder 9 Series (HKLM\...\Windows Media Encoder 9) (Version: - )
WinFast Multimedia Driver Installation (HKLM\...\{418EC9DD-25EE-4C3F-8827-B7AA9B26405B}) (Version: - Multimedia)
WinFast PVR2 (HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\{C92C584E-C781-475E-A8E2-C67D993A6B95}) (Version: 2.0.3.57 - Leadtek)
WinRAR 5.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
Winx Club (HKLM\...\Winx Club_is1) (Version: - )
World of Tanks (HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net)

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-866419223-3740971703-2059610383-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\OP\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)

==================== Restore Points =========================

07-04-2015 17:51:10 Instalováno MSI Star Cam 370i

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {50F08B29-3D2D-456D-BB47-A7FD73A69D6B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-05-18] (Google Inc.)
Task: {718BD64E-2FB6-4DBD-8EA2-2DBBAC17AF4E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {72830944-FD6B-4F38-A341-DD4A21D586BC} - System32\Tasks\suprize_updating_service => C:\Program Files\suprize\suprize_updating_service.exe
Task: {9D1DEF5D-AC27-4230-A51F-EB617C3D694C} - System32\Tasks\MyDefrag v4.3.1 Monthly => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticMonthly.MyD [2010-05-21] ()
Task: {A58D397D-AAB3-4C45-9E9A-E29835A2767E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {B3F70B61-99EC-49CA-B4B3-C9FAA9AC6303} - System32\Tasks\suprize_notification_service => C:\Program Files\suprize\suprize_notification_service.exe
Task: {BC427ABE-D583-4DF2-A252-850F20A2EACC} - System32\Tasks\MyDefrag v4.3.1 Daily => C:\Program Files\MyDefrag v4.3.1\Scripts\AutomaticDaily.MyD [2010-05-21] ()
Task: {BE8233CF-E872-4AE6-AE3A-E78E11325A54} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-05-18] (Google Inc.)
Task: {F9BD7C74-7F95-4355-A16C-22ED5D8B6C2B} - System32\Tasks\uxWsS4rimCqJi => C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\suprize_notification_service.job => C:\Program Files\suprize\suprize_notification_service.exeă/url='http:/cdn.selectbestopt.com/notf_sys/index.html' /crregname='suprize' /appid='73143' /srcid='2913' /bic='ff7644c2d0a2c59e2addec71788f5808' /verifier='2edf504572f7985922eebc4f452b6aef' /installerversion='1.50.3.10' /statsdomain='http:/stats.buildomserv.com/data.gif?' /errorsdomain='http:/stats.buildomserv.com/data.gif?' /monetizationdomain='http:/logs.buildomserv.com/monetization.gif
Task: C:\Windows\Tasks\suprize_updating_service.job => C:\Program Files\suprize\suprize_updating_service.exe¨ /campid=2913 /verid=1 /url=http:/cdn.buildomserv.com/txt/@CAMPID@/@VER@/file.txt /appid=73143 /taskname=suprize_updating_service /funurl=http:/stats.buildomserv.com
Task: C:\Windows\Tasks\uxWsS4rimCqJi.job => C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe

==================== Loaded Modules (whitelisted) ==============

2014-05-01 16:15 - 2014-05-01 16:15 - 00463360 _____ () C:\ProgramData\MEGAsync\ShellExtX32.dll
2015-04-07 17:51 - 2006-09-18 14:12 - 00843776 _____ () C:\Windows\vsnpstd3.exe
2015-04-06 19:25 - 2009-04-01 14:07 - 00303188 _____ () C:\Program Files\WinFast\WFDTV\RTL283XACCESS.dll
2015-04-06 19:25 - 2008-12-02 11:04 - 00007680 _____ () C:\Program Files\WinFast\WFDTV\WIZLANGCZE.dll
2015-04-06 19:25 - 2010-11-15 11:05 - 00073728 _____ () C:\Program Files\WinFast\WFDTV\RCConfig\RCKeysInfoIO.dll
2015-04-05 06:46 - 2015-03-30 23:07 - 01174856 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\libglesv2.dll
2015-04-05 06:46 - 2015-03-30 23:07 - 00080200 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\libegl.dll
2015-04-05 06:46 - 2015-03-30 23:07 - 09279304 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\pdf.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00113171 _____ () C:\Program Files\VideoLAN\VLC\libvlc.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 02396691 _____ () C:\Program Files\VideoLAN\VLC\libvlccore.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00268307 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libdshow_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00027667 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00031251 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 11148307 _____ () C:\Program Files\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01248787 _____ () C:\Program Files\VideoLAN\VLC\plugins\misc\libxml_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00066579 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 02043411 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00100371 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00244243 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00076307 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libaccess_vdr_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00045587 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00060947 _____ () C:\Program Files\VideoLAN\VLC\plugins\stream_filter\libsmooth_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00531475 _____ () C:\Program Files\VideoLAN\VLC\plugins\stream_filter\libhttplive_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00708627 _____ () C:\Program Files\VideoLAN\VLC\plugins\stream_filter\libdash_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00114195 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libzip_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00040467 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libstream_filter_rar_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00014867 _____ () C:\Program Files\VideoLAN\VLC\plugins\stream_filter\librecord_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00133139 _____ () C:\Program Files\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01512467 _____ () C:\Program Files\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00296979 _____ () C:\Program Files\VideoLAN\VLC\plugins\lua\liblua_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00054291 _____ () C:\Program Files\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00038419 _____ () C:\Program Files\VideoLAN\VLC\plugins\control\libglobalhotkeys_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00189971 _____ () C:\Program Files\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00091667 _____ () C:\Program Files\VideoLAN\VLC\plugins\demux\libavi_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00116755 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libaccess_http_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00292371 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libpng_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00017939 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01280019 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00018451 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libdts_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00336403 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00344595 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00198675 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libflac_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00027155 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libg711_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00015891 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01393171 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00146451 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00022035 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00733203 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00018963 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00026131 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00171027 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libopus_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00019475 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\liba52_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00019987 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 10447379 _____ () C:\Program Files\VideoLAN\VLC\plugins\codec\libavcodec_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00746515 _____ () C:\Program Files\VideoLAN\VLC\plugins\text_renderer\libfreetype_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00026643 _____ () C:\Program Files\VideoLAN\VLC\plugins\sse2\libi420_yuy2_sse2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00019987 _____ () C:\Program Files\VideoLAN\VLC\plugins\mmx\libi420_yuy2_mmx_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00587283 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_filter\libswscale_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00113683 _____ () C:\Program Files\VideoLAN\VLC\plugins\sse2\libi420_rgb_sse2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00027667 _____ () C:\Program Files\VideoLAN\VLC\plugins\sse2\libi422_yuy2_sse2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00019987 _____ () C:\Program Files\VideoLAN\VLC\plugins\mmx\libi422_yuy2_mmx_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00053779 _____ () C:\Program Files\VideoLAN\VLC\plugins\mmx\libi420_rgb_mmx_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00016915 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libyuy2_i422_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00015379 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libgrey_yuv_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00032275 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00018963 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00020499 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libyuy2_i420_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00017427 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00015379 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_chroma\libi422_i420_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00015379 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_filter\libscale_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00013843 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_filter\libyuvp_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00068115 _____ () C:\Program Files\VideoLAN\VLC\plugins\video_output\libdirect3d_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00013843 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_mixer\libfloat_mixer_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00018963 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00130579 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libmpgatofixed32_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00168979 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libdtstofloat32_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00058899 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\liba52tofloat32_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 01496083 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00019475 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libsimple_channel_mixer_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00013331 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\liba52tospdif_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00014355 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libdtstospdif_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00014867 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libdolby_surround_decoder_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00014355 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libugly_resampler_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00015379 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libtrivial_channel_mixer_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00025619 _____ () C:\Program Files\VideoLAN\VLC\plugins\audio_filter\libaudio_format_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00072211 _____ () C:\Program Files\VideoLAN\VLC\plugins\access\libaccess_mms_plugin.dll
2014-07-23 01:29 - 2014-07-23 01:29 - 00036371 _____ () C:\Program Files\VideoLAN\VLC\plugins\meta_engine\libfolder_plugin.dll
2015-04-05 06:46 - 2015-03-30 23:07 - 14974280 _____ () C:\Program Files\Google\Chrome\Application\41.0.2272.118\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-866419223-3740971703-2059610383-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\OP\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.0.0.138

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\Windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^OP^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MEGAsync.lnk => C:\Windows\pss\MEGAsync.lnk.Startup
MSCONFIG\startupreg: ArcSoft Connection Service => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: LogMeIn Hamachi Ui => "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
MSCONFIG\startupreg: mswdceSrv => "C:\Windows\system32\mswdce.vbe" msajnmtn mswjxuuf
MSCONFIG\startupreg: NtVdmSrv => C:\Windows\inf\ntvdm.vbe
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: StartCCC => "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: UVS11 Preload => C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe

==================== Accounts: =============================

Administrator (S-1-5-21-866419223-3740971703-2059610383-500 - Administrator - Disabled)
Guest (S-1-5-21-866419223-3740971703-2059610383-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-866419223-3740971703-2059610383-1004 - Limited - Enabled)
OP (S-1-5-21-866419223-3740971703-2059610383-1000 - Administrator - Enabled) => C:\Users\OP

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (04/07/2015 08:50:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: vlc.exe, verze: 2.1.5.0, časové razítko: 0x00000004
Název chybujícího modulu: ntdll.dll, verze: 6.1.7600.16385, časové razítko: 0x4a5bdadb
Kód výjimky: 0xc0000374
Posun chyby: 0x000c283b
ID chybujícího procesu: 0x148c
Čas spuštění chybující aplikace: 0xvlc.exe0
Cesta k chybující aplikaci: vlc.exe1
Cesta k chybujícímu modulu: vlc.exe2
ID zprávy: vlc.exe3

Error: (04/07/2015 05:51:09 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {74c30fce-fc01-4bff-9381-b1002e66b77d}

Error: (04/07/2015 00:59:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: vlc.exe, verze: 2.1.5.0, časové razítko: 0x00000004
Název chybujícího modulu: vlc.exe, verze: 2.1.5.0, časové razítko: 0x00000004
Kód výjimky: 0xc0000005
Posun chyby: 0x000019b0
ID chybujícího procesu: 0x990
Čas spuštění chybující aplikace: 0xvlc.exe0
Cesta k chybující aplikaci: vlc.exe1
Cesta k chybujícímu modulu: vlc.exe2
ID zprávy: vlc.exe3

Error: (04/06/2015 07:45:22 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {17622be6-0ab4-4fa7-8a93-f3865fd6c8aa}

Error: (04/06/2015 07:25:25 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {6bf1188a-c890-41b3-9531-50f6d98fd5dc}

Error: (04/06/2015 07:19:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: _isFDCB.exe, verze: 12.0.0.58849, časové razítko: 0x45b1a378
Název chybujícího modulu: ISRT.dll_unloaded, verze: 0.0.0.0, časové razítko: 0x45b1a352
Kód výjimky: 0xc0000005
Posun chyby: 0x03de2e20
ID chybujícího procesu: 0x16c8
Čas spuštění chybující aplikace: 0x_isFDCB.exe0
Cesta k chybující aplikaci: _isFDCB.exe1
Cesta k chybujícímu modulu: _isFDCB.exe2
ID zprávy: _isFDCB.exe3

Error: (04/06/2015 07:11:37 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {4ab14408-e6f4-4fff-a15c-7723cb7ce2c6}

Error: (04/06/2015 11:48:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: vlc.exe, verze: 2.1.5.0, časové razítko: 0x00000004
Název chybujícího modulu: ntdll.dll, verze: 6.1.7600.16385, časové razítko: 0x4a5bdadb
Kód výjimky: 0xc0000374
Posun chyby: 0x000c283b
ID chybujícího procesu: 0x1330
Čas spuštění chybující aplikace: 0xvlc.exe0
Cesta k chybující aplikaci: vlc.exe1
Cesta k chybujícímu modulu: vlc.exe2
ID zprávy: vlc.exe3

Error: (04/04/2015 00:42:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: vlc.exe, verze: 2.1.5.0, časové razítko: 0x00000004
Název chybujícího modulu: vlc.exe, verze: 2.1.5.0, časové razítko: 0x00000004
Kód výjimky: 0xc0000005
Posun chyby: 0x000019b0
ID chybujícího procesu: 0xa74
Čas spuštění chybující aplikace: 0xvlc.exe0
Cesta k chybující aplikaci: vlc.exe1
Cesta k chybujícímu modulu: vlc.exe2
ID zprávy: vlc.exe3

Error: (04/03/2015 08:58:27 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Generování kontextu aktivace pro Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1 se nezdařilo.
Závislé sestavení Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" nelze najít.
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.


System errors:
=============
Error: (04/09/2015 10:34:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Autodesk Licensing Service neuspěla při spuštění v důsledku následující chyby:
%%2

Error: (04/09/2015 10:33:48 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správce služeb se pokusil o opravnou akci (Restartovat službu) po nečekaném ukončení služby Windows Search, ale tato akce selhala kvůli následující chybě:
%%1056

Error: (04/09/2015 10:33:18 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 2 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (04/09/2015 10:33:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Ochrana softwaru byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (04/09/2015 10:33:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (04/09/2015 10:33:16 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (04/09/2015 10:33:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Ulead Burning Helper byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (04/09/2015 10:33:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Protexis Licensing V2 byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (04/09/2015 10:33:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Capture Device Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (04/09/2015 10:33:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba ArcSoft Connect Daemon byla neočekávaně ukončena. Tento stav nastal již 1krát.


Microsoft Office Sessions:
=========================
Error: (04/07/2015 08:50:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: vlc.exe2.1.5.000000004ntdll.dll6.1.7600.163854a5bdadbc0000374000c283b148c01d07163acc1374aC:\Program Files\VideoLAN\VLC\vlc.exeC:\Windows\SYSTEM32\ntdll.dllf7c95b75-dd56-11e4-a1e3-001a4d22f619

Error: (04/07/2015 05:51:09 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Přístup byl odepřen.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {74c30fce-fc01-4bff-9381-b1002e66b77d}

Error: (04/07/2015 00:59:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: vlc.exe2.1.5.000000004vlc.exe2.1.5.000000004c0000005000019b099001d07121ca5010afC:\Program Files\VideoLAN\VLC\vlc.exeC:\Program Files\VideoLAN\VLC\vlc.exe2248ed2c-dd15-11e4-8faf-001a4d22f619

Error: (04/06/2015 07:45:22 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Přístup byl odepřen.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {17622be6-0ab4-4fa7-8a93-f3865fd6c8aa}

Error: (04/06/2015 07:25:25 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Přístup byl odepřen.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {6bf1188a-c890-41b3-9531-50f6d98fd5dc}

Error: (04/06/2015 07:19:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: _isFDCB.exe12.0.0.5884945b1a378ISRT.dll_unloaded0.0.0.045b1a352c000000503de2e2016c801d0708cad0d943aC:\Users\OP\AppData\Local\Temp\_isFDCB.exeISRT.dll0f1982e2-dc81-11e4-bcd3-001a4d22f619

Error: (04/06/2015 07:11:37 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Přístup byl odepřen.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {4ab14408-e6f4-4fff-a15c-7723cb7ce2c6}

Error: (04/06/2015 11:48:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: vlc.exe2.1.5.000000004ntdll.dll6.1.7600.163854a5bdadbc0000374000c283b133001d0704ee22553f6C:\Program Files\VideoLAN\VLC\vlc.exeC:\Windows\SYSTEM32\ntdll.dll241c2b63-dc42-11e4-bcd3-001a4d22f619

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: vyskakují reklamní okna, zpomaluje inetrnet

#8 Příspěvek od altrok »

:arrow: Nemate nainstalovany antivir, takze doporucuju nejaky nainstalovat. Z free reseni doporucim napr. avast nebo Aviru (ve free verzi je anglicky).

:arrow: Velikost plochy by nemela presahovat 200 MB. Zpomaluje se pak start i samotny chod celeho PC.


  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah mi vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\MountPoints2: K - K:\autorun\autorun.exe
    HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\MountPoints2: {538bc678-d9e8-11e3-980b-00004d22f619} - J:\autoplay.exe
    
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-866419223-3740971703-2059610383-1000 -> {46404466-90F4-4AA4-80A2-01FAFD386862} URL = 
    S3 esgiguard; \??\C:\Users\OP\Downloads\SpyHunter\esgiguard.sys [X]
    C:\Users\OP\Downloads\SpyHunter
    
    2015-04-09 22:50 - 2015-04-09 22:50 - 00112640 _____ (forum.viry.cz) C:\Users\OP\Desktop\FRSTLauncher (2).exe
    2015-04-09 22:31 - 2015-04-09 22:33 - 00000000 ____D () C:\AdwCleaner
    2015-04-09 22:04 - 2015-04-09 22:04 - 02217984 _____ () C:\Users\OP\Desktop\adwcleaner_4.201.exe
    2015-04-09 21:29 - 2015-04-09 21:33 - 00000000 ____D () C:\rsit
    2015-04-09 21:29 - 2015-04-09 21:33 - 00000000 ____D () C:\Program Files\trend micro
    2015-04-09 21:28 - 2015-04-09 21:28 - 01107968 _____ () C:\Users\OP\Downloads\RSIT.exe
    2015-04-07 17:36 - 2015-04-07 17:36 - 01380960 _____ (Skype Technologies S.A.) C:\Users\OP\Downloads\SkypeSetup.exe
    2015-04-02 12:07 - 2015-04-02 12:07 - 00000000 ____D () C:\Program Files\Enigma Software Group
    2015-04-01 22:58 - 2015-04-02 15:50 - 00000004 _____ () C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
    2015-04-01 21:58 - 2015-04-09 22:34 - 00001278 _____ () C:\Windows\Tasks\suprize_notification_service.job
    2015-04-01 21:58 - 2015-04-09 22:34 - 00000986 _____ () C:\Windows\Tasks\uxWsS4rimCqJi.job
    2015-04-01 21:58 - 2015-04-09 22:34 - 00000640 _____ () C:\Windows\Tasks\suprize_updating_service.job
    2015-03-31 10:14 - 2015-03-31 10:14 - 00004387 _____ () C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi
    
    DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
    DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mswdceSrv
    C:\Windows\system32\mswdce.vbe
    C:\Windows\system32\mswdce.inf
    DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv
    C:\Windows\inf\ntvdm.vbe
    C:\Windows\inf\ntvdm.inf
    DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk
    
    Task: {72830944-FD6B-4F38-A341-DD4A21D586BC} - System32\Tasks\suprize_updating_service => C:\Program Files\suprize\suprize_updating_service.exe
    C:\Program Files\suprize
    Task: {B3F70B61-99EC-49CA-B4B3-C9FAA9AC6303} - System32\Tasks\suprize_notification_service => C:\Program Files\suprize\suprize_notification_service.exe
    Task: {F9BD7C74-7F95-4355-A16C-22ED5D8B6C2B} - System32\Tasks\uxWsS4rimCqJi => C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe
    C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\suprize_notification_service.job
    Task: C:\Windows\Tasks\suprize_updating_service.job
    Task: C:\Windows\Tasks\uxWsS4rimCqJi.job => C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe
    Hosts:
    EmptyTemp:
    End
:arrow: Dneska to balim, takze to dokoncime zitra... po techto krocich by se pocitaci melo znatelne ulevit... dobrou noc :o
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

lilithka
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 09 dub 2015 17:51

Re: vyskakují reklamní okna, zpomaluje inetrnet

#9 Příspěvek od lilithka »

Ok, provedu zítra, taky valim spat. Děkuji moc za rady, zítra se ozvu :idea:

lilithka
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 09 dub 2015 17:51

Re: vyskakují reklamní okna, zpomaluje inetrnet

#10 Příspěvek od lilithka »

Dobré ráno,

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 11-03-2015
Ran by OP at 2015-04-10 07:43:33 Run:1
Running from C:\Users\OP\Desktop
Loaded Profiles: OP (Available profiles: OP)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\MountPoints2: K - K:\autorun\autorun.exe
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\MountPoints2: {538bc678-d9e8-11e3-980b-00004d22f619} - J:\autoplay.exe

SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-866419223-3740971703-2059610383-1000 -> {46404466-90F4-4AA4-80A2-01FAFD386862} URL =
S3 esgiguard; \??\C:\Users\OP\Downloads\SpyHunter\esgiguard.sys [X]
C:\Users\OP\Downloads\SpyHunter

2015-04-09 22:50 - 2015-04-09 22:50 - 00112640 _____ (forum.viry.cz) C:\Users\OP\Desktop\FRSTLauncher (2).exe
2015-04-09 22:31 - 2015-04-09 22:33 - 00000000 ____D () C:\AdwCleaner
2015-04-09 22:04 - 2015-04-09 22:04 - 02217984 _____ () C:\Users\OP\Desktop\adwcleaner_4.201.exe
2015-04-09 21:29 - 2015-04-09 21:33 - 00000000 ____D () C:\rsit
2015-04-09 21:29 - 2015-04-09 21:33 - 00000000 ____D () C:\Program Files\trend micro
2015-04-09 21:28 - 2015-04-09 21:28 - 01107968 _____ () C:\Users\OP\Downloads\RSIT.exe
2015-04-07 17:36 - 2015-04-07 17:36 - 01380960 _____ (Skype Technologies S.A.) C:\Users\OP\Downloads\SkypeSetup.exe
2015-04-02 12:07 - 2015-04-02 12:07 - 00000000 ____D () C:\Program Files\Enigma Software Group
2015-04-01 22:58 - 2015-04-02 15:50 - 00000004 _____ () C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7
2015-04-01 21:58 - 2015-04-09 22:34 - 00001278 _____ () C:\Windows\Tasks\suprize_notification_service.job
2015-04-01 21:58 - 2015-04-09 22:34 - 00000986 _____ () C:\Windows\Tasks\uxWsS4rimCqJi.job
2015-04-01 21:58 - 2015-04-09 22:34 - 00000640 _____ () C:\Windows\Tasks\suprize_updating_service.job
2015-03-31 10:14 - 2015-03-31 10:14 - 00004387 _____ () C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi

DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mswdceSrv
C:\Windows\system32\mswdce.vbe
C:\Windows\system32\mswdce.inf
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv
C:\Windows\inf\ntvdm.vbe
C:\Windows\inf\ntvdm.inf
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk

Task: {72830944-FD6B-4F38-A341-DD4A21D586BC} - System32\Tasks\suprize_updating_service => C:\Program Files\suprize\suprize_updating_service.exe
C:\Program Files\suprize
Task: {B3F70B61-99EC-49CA-B4B3-C9FAA9AC6303} - System32\Tasks\suprize_notification_service => C:\Program Files\suprize\suprize_notification_service.exe
Task: {F9BD7C74-7F95-4355-A16C-22ED5D8B6C2B} - System32\Tasks\uxWsS4rimCqJi => C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe
C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\suprize_notification_service.job
Task: C:\Windows\Tasks\suprize_updating_service.job
Task: C:\Windows\Tasks\uxWsS4rimCqJi.job => C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe
Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
"HKU\S-1-5-21-866419223-3740971703-2059610383-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K" => Key deleted successfully.
"HKU\S-1-5-21-866419223-3740971703-2059610383-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{538bc678-d9e8-11e3-980b-00004d22f619}" => Key deleted successfully.
HKCR\CLSID\{538bc678-d9e8-11e3-980b-00004d22f619} => Key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-866419223-3740971703-2059610383-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{46404466-90F4-4AA4-80A2-01FAFD386862}" => Key deleted successfully.
HKCR\CLSID\{46404466-90F4-4AA4-80A2-01FAFD386862} => Key not found.
esgiguard => Service deleted successfully.
"C:\Users\OP\Downloads\SpyHunter" => File/Directory not found.
C:\Users\OP\Desktop\FRSTLauncher (2).exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\OP\Desktop\adwcleaner_4.201.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Users\OP\Downloads\RSIT.exe => Moved successfully.
C:\Users\OP\Downloads\SkypeSetup.exe => Moved successfully.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\Windows\system32\029B560A371F4E00AB32838EBC01B9E7 => Moved successfully.
C:\Windows\Tasks\suprize_notification_service.job => Moved successfully.
C:\Windows\Tasks\uxWsS4rimCqJi.job => Moved successfully.
C:\Windows\Tasks\suprize_updating_service.job => Moved successfully.
C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi => Moved successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mswdceSrv => Key Deleted successfully.
"C:\Windows\system32\mswdce.vbe" => File/Directory not found.
"C:\Windows\system32\mswdce.inf" => File/Directory not found.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NtVdmSrv => Key Deleted successfully.
"C:\Windows\inf\ntvdm.vbe" => File/Directory not found.
"C:\Windows\inf\ntvdm.inf" => File/Directory not found.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => Key Deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{72830944-FD6B-4F38-A341-DD4A21D586BC}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72830944-FD6B-4F38-A341-DD4A21D586BC}" => Key deleted successfully.
C:\Windows\System32\Tasks\suprize_updating_service => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\suprize_updating_service" => Key deleted successfully.
"C:\Program Files\suprize" => File/Directory not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B3F70B61-99EC-49CA-B4B3-C9FAA9AC6303}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B3F70B61-99EC-49CA-B4B3-C9FAA9AC6303}" => Key deleted successfully.
C:\Windows\System32\Tasks\suprize_notification_service => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\suprize_notification_service" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F9BD7C74-7F95-4355-A16C-22ED5D8B6C2B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F9BD7C74-7F95-4355-A16C-22ED5D8B6C2B}" => Key deleted successfully.
C:\Windows\System32\Tasks\uxWsS4rimCqJi => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\uxWsS4rimCqJi" => Key deleted successfully.
"C:\Users\OP\AppData\Roaming\uxWsS4rimCqJi.exe" => File/Directory not found.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
Task: C:\Windows\Tasks\suprize_notification_service.job not found.
Task: C:\Windows\Tasks\suprize_updating_service.job not found.
C:\Windows\Tasks\uxWsS4rimCqJi.job not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.9 GB temporary data.


The system needed a reboot.

==== End of Fixlog 07:43:57 ====

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: vyskakují reklamní okna, zpomaluje inetrnet

#11 Příspěvek od altrok »

Krasne dopoledne i Vam,

to nejhorsi mame za sebou, takze pokracujeme :)

Start -> spustit -> services.msc
Na sluzbu Windows Update 2x kliknete levym mysitkem a nastavte
  • Typ spousteni: Automaticky (Zpozdene spusteni)
  • o kousek niz kliknete na tlacitko Spustit
  • po uspesnem spusteni kliknete vpravo dole na Pouzit.
Nasledne otevrete nabidku start a dolu vepiste Windows Update, po par vterinach se Vam nahore ukaze hledana polozka, kterou spustte.
V otevrenem okne vyberte vlevo moznost Vyhledat aktualizace, po par minutach (az bude aktualizace nalezeny) je nainstalujte pomoci tlacitka Instalovat aktualizace. Nemate vubec aktualizovany system, takze tato operace muze trvat az nekolik hodin - muzete na PC pracovat, ale pravdepodobne bude pomalejsi a bude vyzadovat nekolik delsich restartu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

lilithka
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 09 dub 2015 17:51

Re: vyskakují reklamní okna, zpomaluje inetrnet

#12 Příspěvek od lilithka »

hotovo :)

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: vyskakují reklamní okna, zpomaluje inetrnet

#13 Příspěvek od altrok »

Znovu vyhledejte aktualizace a presvedcte se, ze jsou vsechny dulezite nainstalovane (nebude nalezena zadna dulezita aktualizace). Pokud je vse v poradku, dejte jeste aktualni logy z FRST.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

lilithka
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 09 dub 2015 17:51

Re: vyskakují reklamní okna, zpomaluje inetrnet

#14 Příspěvek od lilithka »

myslíte tohle?

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by OP (administrator) on OP-PC on 10-04-2015 15:11:47
Running from C:\Users\OP\Desktop
Loaded Profiles: OP (Available profiles: OP)
Platform: Microsoft Windows 7 Home Premium (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(InterVideo Inc.) C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Leadtek Research Inc.) C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(SONIX) C:\Windows\tsnpstd3.exe
() C:\Windows\vsnpstd3.exe
(Thomas Ascher) C:\Program Files\ATnotes\ATnotes.exe
(Leadtek Research Inc.) C:\Program Files\WinFast\WFDTV\WFWIZ.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(VideoLAN) C:\Program Files\VideoLAN\VLC\vlc.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [WinFastDTV] => C:\Program Files\WinFast\WFDTV\DTVSchdl.exe [103936 2014-03-04] (Leadtek Research Inc.)
HKLM\...\Run: [ArcSoft Connection Service] => C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [170496 2009-02-06] (ArcSoft Inc.)
HKLM\...\Run: [tsnpstd3] => C:\Windows\tsnpstd3.exe [262144 2007-03-30] (SONIX)
HKLM\...\Run: [snpstd3] => C:\Windows\vsnpstd3.exe [843776 2006-09-18] ()
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [ATnotes.exe] => C:\Program Files\ATnotes\ATnotes.exe [1015808 2005-01-05] (Thomas Ascher)
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [GamingMouseEditor] => "C:\Program Files (x86)\GamingMouseEditor\GamingMouseEditor\GamingMouseEditor.exe" Minimum
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [GSplay.exe] => C:\Users\FonkyFokel\Desktop\GSplay.exe
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [WinFast Schedule] => C:\Program Files\WinFast\WFDTV\WFWIZ.exe [2916352 2013-01-09] (Leadtek Research Inc.)
HKU\S-1-5-21-866419223-3740971703-2059610383-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31682144 2015-03-25] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX32.dll ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX32.dll ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX32.dll ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-866419223-3740971703-2059610383-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\OP\AppData\Roaming\Mozilla\Firefox\Profiles\bcjakel3.default
FF Homepage: seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll [2011-03-09] ( Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin HKU\S-1-5-21-866419223-3740971703-2059610383-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\OP\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-07-07] (Unity Technologies ApS)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [Not Found]

Chrome:
=======
CHR Profile: C:\Users\OP\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Wallet) - C:\Users\OP\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-18]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2009-02-06] (ArcSoft Inc.)
R2 Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [198168 2007-03-06] (InterVideo Inc.)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5429520 2015-01-30] (TeamViewer GmbH)
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2004-12-13] (Ulead Systems, Inc.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)
S2 Autodesk Licensing Service; "C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe" [X]
S2 mi-raysat_3dsmax9_32; "C:\Program Files (x86)\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 ausbmon; C:\Windows\system32\drivers\ausbmon.sys [19744 2009-03-02] (AGG Software (http://www.aggsoft.com))
S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo32.sys [28088 2014-04-24] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-05-12] (Disc Soft Ltd)
S3 gdrv; C:\Windows\gdrv.sys [17488 2014-12-28] (Windows (R) 2000 DDK provider)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [22688 2014-06-10] (REALiX(tm))
R3 SNPSTD3; C:\Windows\System32\DRIVERS\snpstd3.sys [10246144 2007-04-03] (Sonix Co. Ltd.)
R3 WFLR6654; C:\Windows\System32\drivers\wfeaglxt.sys [433920 2009-10-21] (Leadtek Research Inc.)
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-10 15:07 - 2015-04-10 15:07 - 98855403 _____ () C:\Users\OP\Downloads\Scooby.a.Scrappy.Doo.S01E07.Dračí.obluda.z.Tokya.SDTV.x264-PiP.mp4.crdownload
2015-04-10 14:01 - 2015-04-10 14:10 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-10 14:01 - 2015-02-26 21:20 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-10 13:35 - 2014-09-15 02:42 - 02377216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-04-10 13:35 - 2011-04-09 08:13 - 03957632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-10 13:35 - 2011-04-09 08:13 - 03901824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-10 13:35 - 2011-04-09 07:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-04-10 13:35 - 2010-12-18 07:29 - 00541184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-10 13:27 - 2012-06-03 00:19 - 00053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-10 13:27 - 2012-06-03 00:19 - 00045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-10 13:26 - 2012-06-03 00:19 - 01933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-10 13:26 - 2012-06-03 00:19 - 00577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-10 13:26 - 2012-06-03 00:19 - 00035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-10 13:26 - 2012-06-03 00:12 - 02422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-10 13:26 - 2012-06-03 00:12 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-10 13:26 - 2012-06-02 15:19 - 00171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-10 13:26 - 2012-06-02 15:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-09 22:55 - 2015-04-09 22:55 - 00037651 _____ () C:\Users\OP\Desktop\Addition.txt
2015-04-09 22:54 - 2015-04-10 15:12 - 00008169 _____ () C:\Users\OP\Desktop\FRST.txt
2015-04-09 22:53 - 2015-04-10 15:11 - 00000000 ____D () C:\FRST
2015-04-09 22:52 - 2015-04-09 22:52 - 01135104 _____ (Farbar) C:\Users\OP\Desktop\FRST.exe
2015-04-09 22:46 - 2015-04-09 22:46 - 02095616 _____ (Farbar) C:\Users\OP\Desktop\FRST64.exe
2015-04-09 19:25 - 2015-04-09 19:59 - 387092480 _____ () C:\Users\OP\Downloads\Zivi-mrtvi.S03E14.Korist.DVDrip.CZ.avi
2015-04-09 19:25 - 2015-04-09 19:57 - 387377152 _____ () C:\Users\OP\Downloads\Zivi-mrtvi.S03E15.Zivot-plny-utrpeni.DVDrip.CZ.avi
2015-04-09 16:09 - 2015-04-09 16:44 - 387360768 _____ () C:\Users\OP\Downloads\Zivi-mrtvi.S03E13.Mezi-trema-ocima.DVDrip.CZ.avi
2015-04-07 17:51 - 2015-04-07 17:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-04-07 17:51 - 2015-04-07 17:51 - 00000000 ____D () C:\Program Files\Common Files\snpstd3
2015-04-07 17:51 - 2007-04-03 19:25 - 10246144 _____ (Sonix Co. Ltd.) C:\Windows\system32\Drivers\snpstd3.sys
2015-04-07 17:51 - 2007-03-30 17:44 - 00262144 _____ (SONIX) C:\Windows\tsnpstd3.exe
2015-04-07 17:51 - 2007-03-30 15:09 - 00061440 _____ ( ) C:\Windows\system32\vsnpstd3.dll
2015-04-07 17:51 - 2007-03-21 15:23 - 00172032 _____ ( ) C:\Windows\system32\rsnpstd3.dll
2015-04-07 17:51 - 2006-09-18 14:12 - 00843776 _____ () C:\Windows\vsnpstd3.exe
2015-04-07 17:51 - 2006-07-03 10:31 - 00094208 _____ (Microsoft Corporation) C:\Windows\amcap.exe
2015-04-07 17:51 - 2005-11-23 13:55 - 00053248 _____ ( ) C:\Windows\system32\csnpstd3.dll
2015-04-07 17:51 - 2005-11-23 13:55 - 00053248 _____ ( ) C:\Windows\csnpstd3.dll
2015-04-07 17:51 - 2004-02-27 17:36 - 00015498 _____ () C:\Windows\snpstd3.ini
2015-04-07 17:51 - 2004-02-27 17:36 - 00013023 _____ () C:\Windows\snpstd3.src
2015-04-07 17:50 - 2009-12-10 17:30 - 00000000 ____D () C:\Users\OP\Downloads\StarCam 370i SN9C105 driver
2015-04-07 17:49 - 2015-04-07 17:50 - 09810527 _____ () C:\Users\OP\Downloads\StarCam370i_SN9C105.zip
2015-04-07 17:39 - 2015-04-07 17:39 - 00000000 ____D () C:\Users\OP\Tracing
2015-04-07 17:37 - 2015-04-07 17:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-04-07 17:37 - 2015-04-07 17:37 - 00002719 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-04-07 17:37 - 2015-04-07 17:37 - 00000000 ___RD () C:\Program Files\Skype
2015-04-07 17:37 - 2015-04-07 17:37 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-04-07 17:34 - 2015-04-07 17:34 - 00090283 _____ () C:\Users\Public\Documents\Bez názvu.wma
2015-04-06 19:45 - 2009-10-21 18:30 - 00433920 _____ (Leadtek Research Inc.) C:\Windows\system32\Drivers\wfeaglxt.sys
2015-04-06 19:44 - 2015-04-06 19:44 - 02463306 _____ (Leadtek ) C:\Users\OP\Downloads\DTV1800-H---win-7-32bit.exe
2015-04-06 19:27 - 2015-04-06 19:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft Connect
2015-04-06 19:26 - 2015-04-06 19:26 - 00000000 ____D () C:\Program Files\Common Files\ArcSoft
2015-04-06 19:26 - 2005-07-16 02:35 - 00245408 _____ (Microsoft Corporation) C:\Windows\system32\unicows.dll
2015-04-06 19:25 - 2015-04-06 20:54 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinFast PVR2
2015-04-06 19:25 - 2015-04-06 19:25 - 00001858 _____ () C:\Users\OP\Desktop\RCConfig.lnk
2015-04-06 19:25 - 2015-04-06 19:25 - 00001698 _____ () C:\Users\OP\Desktop\WinFast PVR2.lnk
2015-04-06 19:25 - 2015-04-06 19:25 - 00000000 ____D () C:\Users\OP\Documents\WFRCConfig
2015-04-06 19:25 - 2015-04-06 19:25 - 00000000 ____D () C:\Users\OP\AppData\Roaming\InstallShield Installation Information
2015-04-06 19:25 - 2015-04-06 19:25 - 00000000 ____D () C:\Users\OP\AppData\Roaming\InstallShield
2015-04-06 19:18 - 2015-04-06 19:21 - 53660897 _____ (Macrovision Corporation) C:\Users\OP\Downloads\WinFastPVR2_setup_20357.exe
2015-04-06 07:15 - 2015-04-06 07:15 - 00000000 ____D () C:\Program Files (x86)
2015-04-05 18:41 - 2015-04-05 18:41 - 00243504 _____ () C:\Users\OP\Downloads\Firefox Setup Stub 37.0.1.exe
2015-04-04 08:40 - 2015-04-04 08:48 - 147779940 _____ () C:\Users\OP\Downloads\Scooby-Doo.Na.stopě.S01E08.Tajemný.lunapark.SDTV.x264-PiP.mp4.crdownload
2015-04-04 08:16 - 2015-04-04 08:25 - 147532360 _____ () C:\Users\OP\Downloads\Scooby-Doo.Na.stopě.S01E17.Sněžný.muž.SDTV.x264-PiP.mp4.crdownload
2015-04-03 23:02 - 2015-04-03 23:35 - 415449088 _____ () C:\Users\OP\Downloads\Zoufale-manzelky-S07E18-CZ---Chvilky-v-Lese-by-Stifler.avi
2015-04-03 21:39 - 2015-04-03 22:11 - 415717376 _____ () C:\Users\OP\Downloads\Zoufale-manzelky-S07E17-CZ---Vsechno-je-jinak-vse-pri-starem-by-Stifler.avi
2015-04-03 19:32 - 2015-04-03 20:09 - 415629312 _____ () C:\Users\OP\Downloads\Zoufale-manzelky-S07E16-CZ---Smysl-Zivota-by-Stifler.avi
2015-04-02 22:50 - 2015-04-02 22:50 - 00001173 _____ () C:\Users\OP\Desktop\Stažené soubory – zástupce.lnk
2015-04-02 20:55 - 2015-04-10 14:25 - 00002952 _____ () C:\Windows\setupact.log
2015-04-02 20:55 - 2015-04-09 22:27 - 00003828 _____ () C:\Windows\PFRO.log
2015-04-02 20:55 - 2015-04-02 20:55 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-02 17:20 - 2015-04-02 17:20 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Mozilla
2015-04-02 16:41 - 2015-04-02 16:41 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-02 15:52 - 2015-04-02 15:52 - 01700352 _____ (Microsoft Corporation) C:\Windows\system32\gdiplus.dll
2015-04-02 15:52 - 2015-04-02 15:52 - 01060864 _____ (Microsoft Corporation) C:\Windows\system32\mfc71.dll
2015-04-02 15:52 - 2015-04-02 15:52 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\msvcr71.dll
2015-04-02 14:54 - 2015-04-05 19:06 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-28 10:34 - 2015-03-28 10:34 - 00000000 ____D () C:\Windows\pss
2015-03-22 19:49 - 2015-04-10 14:26 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Skype
2015-03-22 19:49 - 2015-03-22 19:49 - 00000000 ____D () C:\Users\OP\AppData\Local\Skype
2015-03-22 19:48 - 2015-04-07 17:38 - 00000000 ____D () C:\ProgramData\Skype
2015-03-18 11:23 - 2015-03-18 11:23 - 00000000 _____ () C:\Users\OP\Desktop\jentak.txt.txt
2015-03-12 17:36 - 2015-03-12 17:36 - 00000000 ____D () C:\Program Files\Common Files\SWF Studio
2015-03-12 17:35 - 2015-03-12 17:35 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Disney Interactive
2015-03-11 18:29 - 2015-03-11 18:29 - 00001858 _____ () C:\Users\Public\Desktop\Na scéně(TM).lnk
2015-03-11 18:29 - 2015-03-11 18:29 - 00000000 ____D () C:\ProgramData\Vivendi Universal Games
2015-03-11 18:29 - 2015-03-11 18:29 - 00000000 ____D () C:\Program Files\Na scene(TM)

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-04-10 15:09 - 2014-05-12 14:13 - 02031944 _____ () C:\Windows\WindowsUpdate.log
2015-04-10 15:02 - 2015-01-25 23:27 - 00000000 ____D () C:\Users\OP\AppData\Roaming\vlc
2015-04-10 14:38 - 2014-06-26 20:46 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-10 14:33 - 2009-07-14 06:34 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-10 14:33 - 2009-07-14 06:34 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-10 14:31 - 2014-05-12 14:31 - 01576554 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-10 14:25 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-10 14:25 - 2009-07-14 06:33 - 00309992 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-10 13:48 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-09 10:29 - 2014-05-12 14:35 - 00000000 ____D () C:\!stazeno
2015-04-07 20:50 - 2014-12-23 11:53 - 00000000 ____D () C:\Users\OP\AppData\Local\CrashDumps
2015-04-07 17:51 - 2014-05-12 15:02 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-04-07 17:51 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\twain_32
2015-04-07 17:51 - 2009-07-14 04:04 - 00000461 _____ () C:\Windows\win.ini
2015-04-07 17:39 - 2014-05-12 14:27 - 00000000 ____D () C:\Users\OP
2015-04-06 20:26 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\Offline Web Pages
2015-04-06 20:09 - 2015-01-30 13:33 - 00000000 ____D () C:\Program Files\CCFile
2015-04-06 19:45 - 2014-05-12 15:01 - 00000000 ____D () C:\Windows\system32\WinFast
2015-04-06 19:25 - 2014-05-12 15:05 - 00000000 ____D () C:\Program Files\WinFast
2015-04-05 18:22 - 2014-05-12 14:47 - 00078664 _____ () C:\Users\OP\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-05 06:46 - 2014-05-18 15:13 - 00002187 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-04-02 16:57 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\Performance
2015-04-02 16:24 - 2014-10-21 13:10 - 00000000 ____D () C:\Users\OP\.gimp-2.4
2015-04-02 16:24 - 2014-05-12 18:17 - 00000000 ____D () C:\Users\OP\AppData\Roaming\DAEMON Tools Lite
2015-04-02 15:56 - 2014-06-08 17:27 - 00000000 ____D () C:\Users\OP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames
2015-04-02 15:56 - 2014-06-08 16:10 - 00000000 ____D () C:\AeriaGames
2015-04-02 15:52 - 2014-12-25 17:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2015-04-02 12:27 - 2014-10-22 15:07 - 00000000 ____D () C:\Users\OP\.gimp-2.6
2015-04-02 09:56 - 2015-01-03 09:22 - 00000000 ____D () C:\Program Files\Disney princezna - Moje pohádkové dobrodružství
2015-03-30 15:25 - 2014-06-09 22:41 - 00026176 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2015-03-29 18:47 - 2009-07-14 06:53 - 00032550 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-28 21:06 - 2014-05-12 15:09 - 00000000 ____D () C:\WinFast WorkArea
2015-03-12 17:36 - 2014-05-12 18:20 - 00003214 _____ () C:\Windows\disney.ini
2015-03-12 17:35 - 2014-05-12 18:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disney Interactive
2015-03-12 17:35 - 2014-05-12 18:20 - 00000000 ____D () C:\Program Files\Disney Interactive
2015-03-11 18:29 - 2014-05-12 18:12 - 00000179 _____ () C:\Windows\ka.ini
2015-03-11 18:29 - 2014-05-12 18:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Barbie(TM)

==================== Files in the root of some directories =======

2014-10-21 12:57 - 2014-10-21 12:57 - 0000880 _____ () C:\Users\OP\AppData\Local\recently-used.xbel
2014-07-14 20:28 - 2014-07-15 10:21 - 0007605 _____ () C:\Users\OP\AppData\Local\Resmon.ResmonCfg
2014-12-30 13:36 - 2014-12-30 13:36 - 0000000 _____ () C:\Users\OP\AppData\Local\{9428E6B3-F727-4C29-8FA2-7EC770CB9E1C}
2015-02-17 00:25 - 2015-02-17 00:25 - 0000000 _____ () C:\Users\OP\AppData\Local\{B48D895F-CD3F-48F6-8FFD-A6B5F05B1BEC}

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-04-04 20:28

==================== End Of Log ============================

lilithka
Návštěvník
Návštěvník
Příspěvky: 15
Registrován: 09 dub 2015 17:51

Re: vyskakují reklamní okna, zpomaluje inetrnet

#15 Příspěvek od lilithka »

Zdravím, chci se zeptat, budem ještě nějak pokračovat? Nebo už je to vše. Problem s vyskakovacími okny už teda nemám. Takže děkuji moc :wink:

Zamčeno