- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu bude na plose ulozen fixlog, jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [Google Update] => C:\Users\Rodiče\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-17] (Google Inc.) HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd) HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess? GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1003\User: Group Policy restriction detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1001\User: Group Policy restriction detected <======= ATTENTION CHR HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Toolbar: HKLM - No Name - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No File Toolbar: HKLM - No Name - {CFBC2741-0C1F-11D6-9224-004F490BED09} - No File Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File FF Plugin: @microsoft.com/GENUINE -> disabled No File S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x32.sys [X] S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x32.sys [X] S3 TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [X] C:\Program Files\TuneUp Utilities 2013 2015-04-20 00:38 - 2015-04-20 00:38 - 00029696 _____ () C:\Users\Rodiče\AppData\Local\MSGBOX.EXE 2015-04-20 00:38 - 2015-04-20 00:38 - 00015327 _____ () C:\Users\Rodiče\Desktop\LM.bat 2015-04-20 00:19 - 2015-04-20 00:19 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Rodiče\Desktop\tdsskiller.exe 2015-04-19 23:14 - 2015-04-19 23:57 - 00000000 ____D () C:\Users\Rodiče\Desktop\mbar 2015-04-19 23:13 - 2015-04-19 23:14 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Rodiče\Desktop\mbar-1.09.1.1004.exe 2015-04-19 22:38 - 2015-04-20 00:40 - 00025792 _____ () C:\Users\Rodiče\Desktop\FRST.txt 2015-04-19 22:36 - 2015-04-19 22:36 - 00112640 _____ (forum.viry.cz) C:\Users\Rodiče\Desktop\FRSTLauncher.exe 2015-04-19 08:55 - 2015-04-19 09:26 - 00000000 ____D () C:\Program Files\trend micro 2015-04-19 08:55 - 2015-04-19 08:56 - 00000000 ____D () C:\rsit 2015-04-19 08:55 - 2015-04-19 08:55 - 01107968 _____ () C:\Users\Rodiče\Downloads\RSIT.exe C:\Users\Rodiče\esetsmartinstaller_csy.exe DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Rodi�e^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk Task: C:\Windows\Tasks\Ad-Aware Update (Weekly).job => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000Core.job Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000UA.job Task: C:\Windows\Tasks\User_Feed_Synchronization-{FF976561-0582-47FC-8BE5-0AEA2EC306C5}.job => C:\Windows\system32\msfeedssync.exe Hosts: EmptyTemp: End

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o rána
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Posílám fixlog:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 19-04-2015 01
Ran by Rodiče at 2015-04-20 01:20:05 Run:1
Running from C:\Users\Rodiče\Desktop
Loaded Profiles: Rodiče (Available profiles: Rodiče & Lenka & NFSU)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [Google Update] => C:\Users\Rodiče\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-17] (Google Inc.)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess?
GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1003\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1001\User: Group Policy restriction detected <======= ATTENTION
CHR HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Toolbar: HKLM - No Name - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No File
Toolbar: HKLM - No Name - {CFBC2741-0C1F-11D6-9224-004F490BED09} - No File
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x32.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x32.sys [X]
S3 TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [X]
C:\Program Files\TuneUp Utilities 2013
2015-04-20 00:38 - 2015-04-20 00:38 - 00029696 _____ () C:\Users\Rodiče\AppData\Local\MSGBOX.EXE
2015-04-20 00:38 - 2015-04-20 00:38 - 00015327 _____ () C:\Users\Rodiče\Desktop\LM.bat
2015-04-20 00:19 - 2015-04-20 00:19 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Rodiče\Desktop\tdsskiller.exe
2015-04-19 23:14 - 2015-04-19 23:57 - 00000000 ____D () C:\Users\Rodiče\Desktop\mbar
2015-04-19 23:13 - 2015-04-19 23:14 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Rodiče\Desktop\mbar-1.09.1.1004.exe
2015-04-19 22:38 - 2015-04-20 00:40 - 00025792 _____ () C:\Users\Rodiče\Desktop\FRST.txt
2015-04-19 22:36 - 2015-04-19 22:36 - 00112640 _____ (forum.viry.cz) C:\Users\Rodiče\Desktop\FRSTLauncher.exe
2015-04-19 08:55 - 2015-04-19 09:26 - 00000000 ____D () C:\Program Files\trend micro
2015-04-19 08:55 - 2015-04-19 08:56 - 00000000 ____D () C:\rsit
2015-04-19 08:55 - 2015-04-19 08:55 - 01107968 _____ () C:\Users\Rodiče\Downloads\RSIT.exe
C:\Users\Rodiče\esetsmartinstaller_csy.exe
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Rodi�e^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk
Task: C:\Windows\Tasks\Ad-Aware Update (Weekly).job => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000Core.job
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000UA.job
Task: C:\Windows\Tasks\User_Feed_Synchronization-{FF976561-0582-47FC-8BE5-0AEA2EC306C5}.job => C:\Windows\system32\msfeedssync.exe
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\LogonHoursAction => value deleted successfully.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DontDisplayLogonHoursWarnings => value deleted successfully.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}" => Key deleted successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1003\User => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1001\User => Moved successfully.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Google" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} => value deleted successfully.
HKCR\CLSID\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CFBC2741-0C1F-11D6-9224-004F490BED09} => value deleted successfully.
HKCR\CLSID\{CFBC2741-0C1F-11D6-9224-004F490BED09} => Key not found.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} => value deleted successfully.
HKCR\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} => Key not found.
"HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0" => Key deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
cpuz135 => Service deleted successfully.
cpuz136 => Service deleted successfully.
TuneUpUtilitiesDrv => Service deleted successfully.
"C:\Program Files\TuneUp Utilities 2013" => File/Directory not found.
C:\Users\Rodiče\AppData\Local\MSGBOX.EXE => Moved successfully.
C:\Users\Rodiče\Desktop\LM.bat => Moved successfully.
C:\Users\Rodiče\Desktop\tdsskiller.exe => Moved successfully.
C:\Users\Rodiče\Desktop\mbar => Moved successfully.
C:\Users\Rodiče\Desktop\mbar-1.09.1.1004.exe => Moved successfully.
"C:\Users\Rodiče\Desktop\FRST.txt" => File/Directory not found.
C:\Users\Rodiče\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
C:\Users\Rodiče\Downloads\RSIT.exe => Moved successfully.
C:\Users\Rodiče\esetsmartinstaller_csy.exe => Moved successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Rodi�e^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk => Key Deleted Successfully.
C:\Windows\Tasks\Ad-Aware Update (Weekly).job => Moved successfully.
C:\Windows\Tasks\Google Software Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000Core.job not found.
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000UA.job not found.
C:\Windows\Tasks\User_Feed_Synchronization-{FF976561-0582-47FC-8BE5-0AEA2EC306C5}.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.8 GB temporary data.
The system needed a reboot.
==== End of Fixlog 01:28:16 ====
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 19-04-2015 01
Ran by Rodiče at 2015-04-20 01:20:05 Run:1
Running from C:\Users\Rodiče\Desktop
Loaded Profiles: Rodiče (Available profiles: Rodiče & Lenka & NFSU)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [Google Update] => C:\Users\Rodiče\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-17] (Google Inc.)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5489944 2014-12-12] (Piriform Ltd)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess?
GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1003\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1001\User: Group Policy restriction detected <======= ATTENTION
CHR HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Toolbar: HKLM - No Name - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No File
Toolbar: HKLM - No Name - {CFBC2741-0C1F-11D6-9224-004F490BED09} - No File
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> No Name - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
S3 cpuz135; \??\C:\Windows\TEMP\cpuz135\cpuz135_x32.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x32.sys [X]
S3 TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys [X]
C:\Program Files\TuneUp Utilities 2013
2015-04-20 00:38 - 2015-04-20 00:38 - 00029696 _____ () C:\Users\Rodiče\AppData\Local\MSGBOX.EXE
2015-04-20 00:38 - 2015-04-20 00:38 - 00015327 _____ () C:\Users\Rodiče\Desktop\LM.bat
2015-04-20 00:19 - 2015-04-20 00:19 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Rodiče\Desktop\tdsskiller.exe
2015-04-19 23:14 - 2015-04-19 23:57 - 00000000 ____D () C:\Users\Rodiče\Desktop\mbar
2015-04-19 23:13 - 2015-04-19 23:14 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Rodiče\Desktop\mbar-1.09.1.1004.exe
2015-04-19 22:38 - 2015-04-20 00:40 - 00025792 _____ () C:\Users\Rodiče\Desktop\FRST.txt
2015-04-19 22:36 - 2015-04-19 22:36 - 00112640 _____ (forum.viry.cz) C:\Users\Rodiče\Desktop\FRSTLauncher.exe
2015-04-19 08:55 - 2015-04-19 09:26 - 00000000 ____D () C:\Program Files\trend micro
2015-04-19 08:55 - 2015-04-19 08:56 - 00000000 ____D () C:\rsit
2015-04-19 08:55 - 2015-04-19 08:55 - 01107968 _____ () C:\Users\Rodiče\Downloads\RSIT.exe
C:\Users\Rodiče\esetsmartinstaller_csy.exe
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Rodi�e^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk
Task: C:\Windows\Tasks\Ad-Aware Update (Weekly).job => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000Core.job
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000UA.job
Task: C:\Windows\Tasks\User_Feed_Synchronization-{FF976561-0582-47FC-8BE5-0AEA2EC306C5}.job => C:\Windows\system32\msfeedssync.exe
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => value deleted successfully.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\LogonHoursAction => value deleted successfully.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DontDisplayLogonHoursWarnings => value deleted successfully.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}" => Key deleted successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1003\User => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3533039139-1052968357-1368303399-1001\User => Moved successfully.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Google" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} => value deleted successfully.
HKCR\CLSID\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{CFBC2741-0C1F-11D6-9224-004F490BED09} => value deleted successfully.
HKCR\CLSID\{CFBC2741-0C1F-11D6-9224-004F490BED09} => Key not found.
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} => value deleted successfully.
HKCR\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} => Key not found.
"HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0" => Key deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
cpuz135 => Service deleted successfully.
cpuz136 => Service deleted successfully.
TuneUpUtilitiesDrv => Service deleted successfully.
"C:\Program Files\TuneUp Utilities 2013" => File/Directory not found.
C:\Users\Rodiče\AppData\Local\MSGBOX.EXE => Moved successfully.
C:\Users\Rodiče\Desktop\LM.bat => Moved successfully.
C:\Users\Rodiče\Desktop\tdsskiller.exe => Moved successfully.
C:\Users\Rodiče\Desktop\mbar => Moved successfully.
C:\Users\Rodiče\Desktop\mbar-1.09.1.1004.exe => Moved successfully.
"C:\Users\Rodiče\Desktop\FRST.txt" => File/Directory not found.
C:\Users\Rodiče\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
C:\Users\Rodiče\Downloads\RSIT.exe => Moved successfully.
C:\Users\Rodiče\esetsmartinstaller_csy.exe => Moved successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xvid => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => Key Deleted successfully.
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Rodi�e^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk => Key Deleted Successfully.
C:\Windows\Tasks\Ad-Aware Update (Weekly).job => Moved successfully.
C:\Windows\Tasks\Google Software Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000Core.job not found.
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3533039139-1052968357-1368303399-1000UA.job not found.
C:\Windows\Tasks\User_Feed_Synchronization-{FF976561-0582-47FC-8BE5-0AEA2EC306C5}.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.8 GB temporary data.
The system needed a reboot.
==== End of Fixlog 01:28:16 ====
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
POZOR - TATO UTILITA MA VELKOU SCHOPNOST MAZAT - NESPOUSTEJTE JI BEZ DOPORUCENI RADCE
- Vypnete antiviry a vsechny real-time ochrany
- spustte ComboFix jako spravce (lepe pod uctem s administratorskym opravnenim)
- s licencnimi podminkami souhlaste - Ano
- pokud je nabidnuta instalace konzoly pro zotaveni, souhlaste
- v prubehu skenovani nechte PC v klidu - nic nespoustejte a do okna ComboFixu neklikejte
- vysledek skenu naleznete v C:\ComboFix.txt, jehoz obsah mi zkopirujte do pristi odpovedi.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Dobrý den, posílám log:
ComboFix 15-04-16.01 - Rodiče 20.04.2015 2:02.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3070.1210 [GMT 2:00]
Spuštěný z: c:\users\RodiŔe\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\DFREB69.tmp
c:\windows\msdownld.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_npf
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-03-20 do 2015-04-20 )))))))))))))))))))))))))))))))
.
.
2015-04-20 12:14 . 2015-04-20 12:26 -------- d-----w- c:\users\Rodiče\AppData\Local\temp
2015-04-20 12:14 . 2015-04-20 12:14 -------- d-----w- c:\users\NFSU\AppData\Local\temp
2015-04-20 12:14 . 2015-04-20 12:14 -------- d-----w- c:\users\Lenka\AppData\Local\temp
2015-04-20 12:14 . 2015-04-20 12:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-04-19 21:17 . 2015-04-19 21:17 -------- d-----w- c:\programdata\Malwarebytes
2015-04-19 21:16 . 2015-04-19 23:29 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-04-19 21:16 . 2015-04-19 21:16 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-04-19 21:15 . 2015-04-19 21:15 92888 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-04-19 20:37 . 2015-04-19 23:30 -------- d-----w- C:\FRST
2015-04-15 12:02 . 2015-03-23 03:06 860160 ----a-w- c:\windows\system32\appraiser.dll
2015-04-15 12:02 . 2015-03-23 03:06 576000 ----a-w- c:\windows\system32\generaltel.dll
2015-04-15 12:02 . 2015-03-23 03:06 630784 ----a-w- c:\windows\system32\invagent.dll
2015-04-15 12:02 . 2015-03-23 03:06 331264 ----a-w- c:\windows\system32\devinv.dll
2015-04-15 12:02 . 2015-03-23 03:06 26112 ----a-w- c:\windows\system32\acmigration.dll
2015-04-15 12:02 . 2015-03-23 02:59 896000 ----a-w- c:\windows\system32\aeinv.dll
2015-04-15 12:02 . 2015-03-23 03:06 202752 ----a-w- c:\windows\system32\aepdu.dll
2015-04-15 12:02 . 2015-03-23 03:06 159744 ----a-w- c:\windows\system32\aepic.dll
2015-04-15 12:02 . 2015-03-04 04:16 249784 ----a-w- c:\windows\system32\clfs.sys
2015-04-15 12:02 . 2015-03-04 04:10 58880 ----a-w- c:\windows\system32\clfsw32.dll
2015-04-15 12:00 . 2015-03-25 03:00 3088384 ----a-w- c:\windows\system32\wucltux.dll
2015-04-15 12:00 . 2015-03-25 03:00 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-04-15 12:00 . 2015-03-25 03:00 33792 ----a-w- c:\windows\system32\wuapp.exe
2015-04-15 12:00 . 2015-03-25 03:00 131584 ----a-w- c:\windows\system32\wuauclt.exe
2015-04-15 12:00 . 2015-03-25 03:00 92672 ----a-w- c:\windows\system32\wudriver.dll
2015-04-15 12:00 . 2015-03-25 03:00 566784 ----a-w- c:\windows\system32\wuapi.dll
2015-04-15 12:00 . 2015-03-25 03:00 35328 ----a-w- c:\windows\system32\wups2.dll
2015-04-15 12:00 . 2015-03-25 03:00 29696 ----a-w- c:\windows\system32\wups.dll
2015-04-15 12:00 . 2015-03-25 03:00 2020864 ----a-w- c:\windows\system32\wuaueng.dll
2015-04-15 12:00 . 2015-03-25 03:00 173056 ----a-w- c:\windows\system32\wuwebv.dll
2015-04-15 12:00 . 2015-03-25 03:00 50176 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-04-15 11:59 . 2015-02-25 03:03 514560 ----a-w- c:\windows\system32\drivers\http.sys
2015-04-15 11:59 . 2015-03-10 03:08 1237504 ----a-w- c:\windows\system32\msxml3.dll
2015-04-15 11:59 . 2015-03-10 03:05 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-04-07 11:32 . 2015-04-07 11:31 291312 ----a-w- c:\windows\system32\aswBoot.exe
2015-04-07 11:31 . 2015-04-07 11:31 43112 ----a-w- c:\windows\avastSS.scr
2015-04-06 04:58 . 2015-04-06 04:58 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
2015-04-06 04:56 . 2015-04-06 04:59 -------- d-----w- c:\program files\Microsoft SQL Server
2015-04-06 04:48 . 2015-04-06 04:48 -------- d-----w- c:\program files\Microsoft Analysis Services
2015-04-04 20:44 . 2015-04-04 20:45 -------- d-s---w- c:\windows\system32\GWX
2015-04-02 13:26 . 2015-04-02 13:26 3039416 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\1029\MSOINTL.DLL
2015-03-31 08:22 . 2015-03-31 08:22 550064 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSOSQM.EXE
2015-03-31 08:22 . 2015-03-31 08:22 26825912 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2015-03-31 08:22 . 2015-03-31 08:22 112452792 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSORES.DLL
2015-03-23 17:18 . 2015-03-23 17:18 -------- d-----w- c:\users\Rodiče\Tracing
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-04-20 03:06 . 2015-04-20 03:06 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{01A76777-1CDB-47D9-80DC-D2948FAD243B}\offreg.dll
2015-04-15 17:57 . 2012-04-03 06:33 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-04-15 17:57 . 2011-06-13 16:03 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-04-07 11:32 . 2014-01-02 17:36 106912 ----a-w- c:\windows\system32\drivers\aswStm.sys
2015-04-07 11:32 . 2014-06-23 04:41 24144 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-04-07 11:32 . 2013-03-14 05:27 208024 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-04-07 11:32 . 2013-03-14 05:27 49904 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-04-07 11:32 . 2012-11-04 19:41 81728 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2015-04-07 11:32 . 2008-04-01 14:46 427736 ----a-w- c:\windows\system32\drivers\aswSP.sys
2015-04-07 11:32 . 2008-02-24 21:37 73440 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-04-07 11:30 . 2011-11-20 07:47 788272 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-03-17 04:57 . 2015-04-15 12:01 248832 ----a-w- c:\windows\system32\schannel.dll
2015-03-14 10:06 . 2015-04-17 11:30 9119072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{01A76777-1CDB-47D9-80DC-D2948FAD243B}\mpengine.dll
2015-02-26 03:11 . 2015-03-11 06:09 2381312 ----a-w- c:\windows\system32\win32k.sys
2015-02-24 03:23 . 2009-10-03 15:14 246920 ------w- c:\windows\system32\MpSigStub.exe
2015-02-20 04:13 . 2015-03-11 06:08 26624 ----a-w- c:\windows\system32\lpk.dll
2015-02-20 04:13 . 2015-03-11 06:08 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-02-20 04:13 . 2015-03-11 06:08 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-02-20 04:13 . 2015-03-11 06:08 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-02-20 03:09 . 2015-03-11 06:08 299008 ----a-w- c:\windows\system32\atmfd.dll
2015-02-17 13:29 . 2015-02-17 13:29 1247912 ----a-w- c:\windows\system32\FM20.DLL
2015-02-04 10:23 . 2015-02-04 10:23 875688 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-02-04 02:54 . 2015-03-11 06:08 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2015-02-03 03:16 . 2015-03-11 06:08 78784 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2015-02-03 03:12 . 2015-03-11 06:08 179200 ----a-w- c:\windows\system32\wintrust.dll
2015-02-03 03:12 . 2015-03-11 06:08 617984 ----a-w- c:\windows\system32\wmdrmsdk.dll
2015-02-03 03:12 . 2015-03-11 06:10 1230848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2015-02-03 03:12 . 2015-03-11 06:08 171520 ----a-w- c:\windows\system32\ubpm.dll
2015-02-03 03:12 . 2015-03-11 06:07 4096 ----a-w- c:\windows\system32\msdxm.ocx
2015-02-03 03:12 . 2015-03-11 06:07 4096 ----a-w- c:\windows\system32\dxmasf.dll
2015-02-03 03:12 . 2015-03-11 06:07 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-02-03 03:12 . 2015-03-11 06:08 1329664 ----a-w- c:\windows\system32\quartz.dll
2015-02-03 03:12 . 2015-03-11 06:08 519680 ----a-w- c:\windows\system32\qdvd.dll
2015-02-03 03:12 . 2015-03-11 06:08 442880 ----a-w- c:\windows\system32\AUDIOKSE.dll
2015-02-03 03:12 . 2015-03-11 06:08 157184 ----a-w- c:\windows\system32\pcasvc.dll
2015-02-03 03:12 . 2015-03-11 06:08 28160 ----a-w- c:\windows\system32\pcadm.dll
2015-02-03 03:12 . 2015-03-11 06:07 8192 ----a-w- c:\windows\system32\spwmp.dll
2015-02-03 03:12 . 2015-03-11 06:08 504320 ----a-w- c:\windows\system32\msscp.dll
2015-02-03 03:12 . 2015-03-11 06:08 265216 ----a-w- c:\windows\system32\msnetobj.dll
2015-02-03 03:12 . 2015-03-11 06:07 10752 ----a-w- c:\windows\system32\msmmsp.dll
2015-02-03 03:12 . 2015-03-11 06:08 3209728 ----a-w- c:\windows\system32\mf.dll
2015-02-03 03:12 . 2015-03-11 06:08 354816 ----a-w- c:\windows\system32\mfplat.dll
2015-02-03 03:12 . 2015-03-11 06:07 103424 ----a-w- c:\windows\system32\mfps.dll
2015-02-03 03:12 . 2015-03-11 06:08 489984 ----a-w- c:\windows\system32\evr.dll
2015-02-03 03:12 . 2015-03-11 06:07 275968 ----a-w- c:\windows\system32\EncDump.dll
2015-02-03 03:12 . 2015-03-11 06:08 988160 ----a-w- c:\windows\system32\drmv2clt.dll
2015-02-03 03:12 . 2015-03-11 06:08 406016 ----a-w- c:\windows\system32\drmmgrtn.dll
2015-02-03 03:12 . 2015-03-11 06:08 1174528 ----a-w- c:\windows\system32\crypt32.dll
2015-02-03 03:12 . 2015-03-11 06:08 1005056 ----a-w- c:\windows\system32\cryptui.dll
2015-02-03 03:12 . 2015-03-11 06:08 103936 ----a-w- c:\windows\system32\cryptnet.dll
2015-02-03 03:12 . 2015-03-11 06:08 143872 ----a-w- c:\windows\system32\cryptsvc.dll
2015-02-03 03:12 . 2015-03-11 06:07 81408 ----a-w- c:\windows\system32\cryptsp.dll
2015-02-03 03:12 . 2015-03-11 06:08 744960 ----a-w- c:\windows\system32\blackbox.dll
2015-02-03 03:12 . 2015-03-11 06:08 475136 ----a-w- c:\windows\system32\audiosrv.dll
2015-02-03 03:12 . 2015-03-11 06:08 374784 ----a-w- c:\windows\system32\AudioEng.dll
2015-02-03 03:12 . 2015-03-11 06:07 50688 ----a-w- c:\windows\system32\appidapi.dll
2015-02-03 03:12 . 2015-03-11 06:07 195584 ----a-w- c:\windows\system32\AudioSes.dll
2015-02-03 03:12 . 2015-03-11 06:07 27648 ----a-w- c:\windows\system32\appidsvc.dll
2015-02-03 03:11 . 2015-03-11 06:08 50176 ----a-w- c:\windows\system32\rrinstaller.exe
2015-02-03 03:11 . 2015-03-11 06:07 9728 ----a-w- c:\windows\system32\pcawrk.exe
2015-02-03 03:11 . 2015-03-11 06:07 8192 ----a-w- c:\windows\system32\pcalua.exe
2015-02-03 03:11 . 2015-03-11 06:07 23040 ----a-w- c:\windows\system32\mfpmp.exe
2015-02-03 03:11 . 2015-03-11 06:08 100864 ----a-w- c:\windows\system32\audiodg.exe
2015-02-03 03:11 . 2015-03-11 06:07 96768 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-02-03 03:11 . 2015-03-11 06:07 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-02-03 03:11 . 2015-03-11 06:07 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2015-02-03 03:10 . 2015-03-11 06:07 8704 ----a-w- c:\windows\system32\pcaevts.dll
2015-02-03 03:09 . 2015-03-11 06:07 2048 ----a-w- c:\windows\system32\mferror.dll
2015-02-03 03:00 . 2015-03-11 06:08 593920 ----a-w- c:\windows\system32\drivers\PEAuth.sys
2015-02-03 02:26 . 2015-03-11 06:07 50176 ----a-w- c:\windows\system32\drivers\appid.sys
2015-01-30 23:56 . 2015-03-11 06:08 370488 ----a-w- c:\windows\system32\drivers\cng.sys
2015-01-28 06:46 . 2015-01-28 06:49 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-01-27 23:36 . 2015-02-11 06:56 1167520 ----a-w- c:\windows\system32\aitstatic.exe
2006-03-20 14:37 . 2008-02-24 21:47 5689344 ----a-w- c:\program files\mplayerc.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-04-07 11:31 644608 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2015-02-26 31346784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMail"="c:\program files\Seznam\Postak\Postak.exe" [2008-02-21 453936]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-04-07 5512912]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SJphone 1.65.lnk]
backup=c:\windows\pss\SJphone 1.65.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SJphone 1.65.lnk
.
[HKLM\~\startupfolder\C:^Users^Rodiče^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
path=c:\users\Rodiče\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScanRegistry]
C:\W [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StillImageMonitor]
C:\W [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2013-04-21 19:43 59720 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
2014-05-28 04:46 455512 ----a-w- c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2010-11-20 21:29 144384 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eyeBeam SIP Client]
2006-05-31 16:05 18550784 ----a-w- c:\program files\CounterPath\X-Lite\x-lite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_DFFE5E47E07B1E117C76A22C295BA5AC]
2015-04-13 21:55 812872 ----a-w- c:\users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleDriveSync]
2015-02-19 13:24 26232152 ----a-w- c:\program files\Google\Drive\googledrivesync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KONICA MINOLTA magicolor 2400W STD]
2005-07-23 11:52 184320 ----a-w- c:\windows\System32\MSTMON_S.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchList]
2007-03-21 12:41 145496 ----a-w- c:\program files\Pinnacle\Studio 11\LaunchList2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2008-08-21 01:18 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-11-02 08:38 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecSche]
2003-11-12 09:08 466944 ----a-w- c:\program files\TVR\RecSche.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-03-26 11:21 5369856 ----a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2010-11-20 21:29 1174016 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2009-07-14 01:14 65024 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
R2 gupdate1ca24ec3816786f;Služba Google Update (gupdate1ca24ec3816786f);c:\program files\Google\Update\GoogleUpdate.exe [2014-10-30 107912]
R3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-04-07 3205216]
R3 AVHybrid;AVHybrid service;c:\windows\system32\DRIVERS\AVHybrid.sys [2005-04-29 999680]
R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [2011-10-10 20504]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-03-13 102912]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2008-11-25 47360]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-17 1343400]
R3 WMSVC;Služba webové správy;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 9728]
R3 xxxHpSAMD;xxxHpSAMD;c:\windows\system32\drivers\HpSAMD.sys [2009-07-14 67152]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2015-04-07 788272]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2015-04-07 427736]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2015-04-07 24144]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2015-04-07 73440]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2015-04-07 106912]
S2 CSHelper;CopySafe Helper Service;c:\program files\Common Files\ArtistScope\CSHelper32.exe [2012-09-26 236536]
S2 HP DS Service;HP DS Service;c:\program files\HP\HPBDSService\HPBDSService.exe [2010-10-27 13824]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-27 145920]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-01-02 315488]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-04-07 220240]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
*Deregistered* - aswFsBlk
*Deregistered* - aswTdi
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-06-16 12:38 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-04-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 17:57]
.
2015-04-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-11 20:14]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.papeweb.cz/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do Microsoft Excelu - c:\progra~1\MICROS~3\Office15\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Rodiče\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Rodiče\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do OneNotu - c:\progra~1\MICROS~3\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.10.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} - hxxps://maxibps.postovnisporitelna.cz/Comp/CSOBEnroll.dll
FF - ProfilePath - c:\users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search/?trackid=sp-006
FF - prefs.js: browser.search.selectedEngine - Google (avast)
FF - prefs.js: browser.startup.homepage - hxxp://www.papeweb.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search/?trackid=sp-006
.
.
------- Asociace souborů -------
.
txtfile="c:\program files\PSPad editor\PSPad.exe" "%1"
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{40498DEF-8B13-44A6-A1A7-69DFE36E9210} - (no file)
MSConfigStartUp-Anti-phishing Domain Advisor - c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe
MSConfigStartUp-ComplexWebServer - c:\complexwebserver\bin\ServiceDirect.exe
MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-Freebie Notes - c:\program files\Power Soft\Freebie Notes\FreebieNotes.exe
MSConfigStartUp-Google Quick Search Box - c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-KBD - c:\hp\KBD\KbdStub.EXE
MSConfigStartUp-SpywareTerminator - c:\program files\Spyware Terminator\SpywareTerminatorShield.exe
MSConfigStartUp-SSDMonitor - c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
MSConfigStartUp-StartCCC - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MSConfigStartUp-WinDVRCtrl - c:\windows\WDVRCtrl.exe
AddRemove-{C71BC882-811F-4A92-8121-3EE55319556A}}_is1 - c:\orsia\Am_Denik\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_17_0_0_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_17_0_0_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4692)
c:\program files\Zoner\Callisto 4\Program\fshex40.dll
c:\program files\Zoner\Callisto 4\Program\FShEx40Res.CZ
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lvhidsvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\tcpsvcs.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2015-04-20 14:48:09 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-04-20 12:47
.
Před spuštěním: 8 828 547 072
Po spuštění: 8 075 665 408
.
- - End Of File - - 9714864E32DD38F209B68D2B3A04EE28
A36C5E4F47E84449FF07ED3517B43A31
ComboFix 15-04-16.01 - Rodiče 20.04.2015 2:02.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3070.1210 [GMT 2:00]
Spuštěný z: c:\users\RodiŔe\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\DFREB69.tmp
c:\windows\msdownld.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_npf
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-03-20 do 2015-04-20 )))))))))))))))))))))))))))))))
.
.
2015-04-20 12:14 . 2015-04-20 12:26 -------- d-----w- c:\users\Rodiče\AppData\Local\temp
2015-04-20 12:14 . 2015-04-20 12:14 -------- d-----w- c:\users\NFSU\AppData\Local\temp
2015-04-20 12:14 . 2015-04-20 12:14 -------- d-----w- c:\users\Lenka\AppData\Local\temp
2015-04-20 12:14 . 2015-04-20 12:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-04-19 21:17 . 2015-04-19 21:17 -------- d-----w- c:\programdata\Malwarebytes
2015-04-19 21:16 . 2015-04-19 23:29 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-04-19 21:16 . 2015-04-19 21:16 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-04-19 21:15 . 2015-04-19 21:15 92888 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-04-19 20:37 . 2015-04-19 23:30 -------- d-----w- C:\FRST
2015-04-15 12:02 . 2015-03-23 03:06 860160 ----a-w- c:\windows\system32\appraiser.dll
2015-04-15 12:02 . 2015-03-23 03:06 576000 ----a-w- c:\windows\system32\generaltel.dll
2015-04-15 12:02 . 2015-03-23 03:06 630784 ----a-w- c:\windows\system32\invagent.dll
2015-04-15 12:02 . 2015-03-23 03:06 331264 ----a-w- c:\windows\system32\devinv.dll
2015-04-15 12:02 . 2015-03-23 03:06 26112 ----a-w- c:\windows\system32\acmigration.dll
2015-04-15 12:02 . 2015-03-23 02:59 896000 ----a-w- c:\windows\system32\aeinv.dll
2015-04-15 12:02 . 2015-03-23 03:06 202752 ----a-w- c:\windows\system32\aepdu.dll
2015-04-15 12:02 . 2015-03-23 03:06 159744 ----a-w- c:\windows\system32\aepic.dll
2015-04-15 12:02 . 2015-03-04 04:16 249784 ----a-w- c:\windows\system32\clfs.sys
2015-04-15 12:02 . 2015-03-04 04:10 58880 ----a-w- c:\windows\system32\clfsw32.dll
2015-04-15 12:00 . 2015-03-25 03:00 3088384 ----a-w- c:\windows\system32\wucltux.dll
2015-04-15 12:00 . 2015-03-25 03:00 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-04-15 12:00 . 2015-03-25 03:00 33792 ----a-w- c:\windows\system32\wuapp.exe
2015-04-15 12:00 . 2015-03-25 03:00 131584 ----a-w- c:\windows\system32\wuauclt.exe
2015-04-15 12:00 . 2015-03-25 03:00 92672 ----a-w- c:\windows\system32\wudriver.dll
2015-04-15 12:00 . 2015-03-25 03:00 566784 ----a-w- c:\windows\system32\wuapi.dll
2015-04-15 12:00 . 2015-03-25 03:00 35328 ----a-w- c:\windows\system32\wups2.dll
2015-04-15 12:00 . 2015-03-25 03:00 29696 ----a-w- c:\windows\system32\wups.dll
2015-04-15 12:00 . 2015-03-25 03:00 2020864 ----a-w- c:\windows\system32\wuaueng.dll
2015-04-15 12:00 . 2015-03-25 03:00 173056 ----a-w- c:\windows\system32\wuwebv.dll
2015-04-15 12:00 . 2015-03-25 03:00 50176 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-04-15 11:59 . 2015-02-25 03:03 514560 ----a-w- c:\windows\system32\drivers\http.sys
2015-04-15 11:59 . 2015-03-10 03:08 1237504 ----a-w- c:\windows\system32\msxml3.dll
2015-04-15 11:59 . 2015-03-10 03:05 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-04-07 11:32 . 2015-04-07 11:31 291312 ----a-w- c:\windows\system32\aswBoot.exe
2015-04-07 11:31 . 2015-04-07 11:31 43112 ----a-w- c:\windows\avastSS.scr
2015-04-06 04:58 . 2015-04-06 04:58 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
2015-04-06 04:56 . 2015-04-06 04:59 -------- d-----w- c:\program files\Microsoft SQL Server
2015-04-06 04:48 . 2015-04-06 04:48 -------- d-----w- c:\program files\Microsoft Analysis Services
2015-04-04 20:44 . 2015-04-04 20:45 -------- d-s---w- c:\windows\system32\GWX
2015-04-02 13:26 . 2015-04-02 13:26 3039416 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\1029\MSOINTL.DLL
2015-03-31 08:22 . 2015-03-31 08:22 550064 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSOSQM.EXE
2015-03-31 08:22 . 2015-03-31 08:22 26825912 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2015-03-31 08:22 . 2015-03-31 08:22 112452792 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSORES.DLL
2015-03-23 17:18 . 2015-03-23 17:18 -------- d-----w- c:\users\Rodiče\Tracing
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-04-20 03:06 . 2015-04-20 03:06 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{01A76777-1CDB-47D9-80DC-D2948FAD243B}\offreg.dll
2015-04-15 17:57 . 2012-04-03 06:33 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-04-15 17:57 . 2011-06-13 16:03 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-04-07 11:32 . 2014-01-02 17:36 106912 ----a-w- c:\windows\system32\drivers\aswStm.sys
2015-04-07 11:32 . 2014-06-23 04:41 24144 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-04-07 11:32 . 2013-03-14 05:27 208024 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-04-07 11:32 . 2013-03-14 05:27 49904 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-04-07 11:32 . 2012-11-04 19:41 81728 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2015-04-07 11:32 . 2008-04-01 14:46 427736 ----a-w- c:\windows\system32\drivers\aswSP.sys
2015-04-07 11:32 . 2008-02-24 21:37 73440 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-04-07 11:30 . 2011-11-20 07:47 788272 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-03-17 04:57 . 2015-04-15 12:01 248832 ----a-w- c:\windows\system32\schannel.dll
2015-03-14 10:06 . 2015-04-17 11:30 9119072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{01A76777-1CDB-47D9-80DC-D2948FAD243B}\mpengine.dll
2015-02-26 03:11 . 2015-03-11 06:09 2381312 ----a-w- c:\windows\system32\win32k.sys
2015-02-24 03:23 . 2009-10-03 15:14 246920 ------w- c:\windows\system32\MpSigStub.exe
2015-02-20 04:13 . 2015-03-11 06:08 26624 ----a-w- c:\windows\system32\lpk.dll
2015-02-20 04:13 . 2015-03-11 06:08 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-02-20 04:13 . 2015-03-11 06:08 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-02-20 04:13 . 2015-03-11 06:08 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-02-20 03:09 . 2015-03-11 06:08 299008 ----a-w- c:\windows\system32\atmfd.dll
2015-02-17 13:29 . 2015-02-17 13:29 1247912 ----a-w- c:\windows\system32\FM20.DLL
2015-02-04 10:23 . 2015-02-04 10:23 875688 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-02-04 02:54 . 2015-03-11 06:08 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2015-02-03 03:16 . 2015-03-11 06:08 78784 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2015-02-03 03:12 . 2015-03-11 06:08 179200 ----a-w- c:\windows\system32\wintrust.dll
2015-02-03 03:12 . 2015-03-11 06:08 617984 ----a-w- c:\windows\system32\wmdrmsdk.dll
2015-02-03 03:12 . 2015-03-11 06:10 1230848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2015-02-03 03:12 . 2015-03-11 06:08 171520 ----a-w- c:\windows\system32\ubpm.dll
2015-02-03 03:12 . 2015-03-11 06:07 4096 ----a-w- c:\windows\system32\msdxm.ocx
2015-02-03 03:12 . 2015-03-11 06:07 4096 ----a-w- c:\windows\system32\dxmasf.dll
2015-02-03 03:12 . 2015-03-11 06:07 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-02-03 03:12 . 2015-03-11 06:08 1329664 ----a-w- c:\windows\system32\quartz.dll
2015-02-03 03:12 . 2015-03-11 06:08 519680 ----a-w- c:\windows\system32\qdvd.dll
2015-02-03 03:12 . 2015-03-11 06:08 442880 ----a-w- c:\windows\system32\AUDIOKSE.dll
2015-02-03 03:12 . 2015-03-11 06:08 157184 ----a-w- c:\windows\system32\pcasvc.dll
2015-02-03 03:12 . 2015-03-11 06:08 28160 ----a-w- c:\windows\system32\pcadm.dll
2015-02-03 03:12 . 2015-03-11 06:07 8192 ----a-w- c:\windows\system32\spwmp.dll
2015-02-03 03:12 . 2015-03-11 06:08 504320 ----a-w- c:\windows\system32\msscp.dll
2015-02-03 03:12 . 2015-03-11 06:08 265216 ----a-w- c:\windows\system32\msnetobj.dll
2015-02-03 03:12 . 2015-03-11 06:07 10752 ----a-w- c:\windows\system32\msmmsp.dll
2015-02-03 03:12 . 2015-03-11 06:08 3209728 ----a-w- c:\windows\system32\mf.dll
2015-02-03 03:12 . 2015-03-11 06:08 354816 ----a-w- c:\windows\system32\mfplat.dll
2015-02-03 03:12 . 2015-03-11 06:07 103424 ----a-w- c:\windows\system32\mfps.dll
2015-02-03 03:12 . 2015-03-11 06:08 489984 ----a-w- c:\windows\system32\evr.dll
2015-02-03 03:12 . 2015-03-11 06:07 275968 ----a-w- c:\windows\system32\EncDump.dll
2015-02-03 03:12 . 2015-03-11 06:08 988160 ----a-w- c:\windows\system32\drmv2clt.dll
2015-02-03 03:12 . 2015-03-11 06:08 406016 ----a-w- c:\windows\system32\drmmgrtn.dll
2015-02-03 03:12 . 2015-03-11 06:08 1174528 ----a-w- c:\windows\system32\crypt32.dll
2015-02-03 03:12 . 2015-03-11 06:08 1005056 ----a-w- c:\windows\system32\cryptui.dll
2015-02-03 03:12 . 2015-03-11 06:08 103936 ----a-w- c:\windows\system32\cryptnet.dll
2015-02-03 03:12 . 2015-03-11 06:08 143872 ----a-w- c:\windows\system32\cryptsvc.dll
2015-02-03 03:12 . 2015-03-11 06:07 81408 ----a-w- c:\windows\system32\cryptsp.dll
2015-02-03 03:12 . 2015-03-11 06:08 744960 ----a-w- c:\windows\system32\blackbox.dll
2015-02-03 03:12 . 2015-03-11 06:08 475136 ----a-w- c:\windows\system32\audiosrv.dll
2015-02-03 03:12 . 2015-03-11 06:08 374784 ----a-w- c:\windows\system32\AudioEng.dll
2015-02-03 03:12 . 2015-03-11 06:07 50688 ----a-w- c:\windows\system32\appidapi.dll
2015-02-03 03:12 . 2015-03-11 06:07 195584 ----a-w- c:\windows\system32\AudioSes.dll
2015-02-03 03:12 . 2015-03-11 06:07 27648 ----a-w- c:\windows\system32\appidsvc.dll
2015-02-03 03:11 . 2015-03-11 06:08 50176 ----a-w- c:\windows\system32\rrinstaller.exe
2015-02-03 03:11 . 2015-03-11 06:07 9728 ----a-w- c:\windows\system32\pcawrk.exe
2015-02-03 03:11 . 2015-03-11 06:07 8192 ----a-w- c:\windows\system32\pcalua.exe
2015-02-03 03:11 . 2015-03-11 06:07 23040 ----a-w- c:\windows\system32\mfpmp.exe
2015-02-03 03:11 . 2015-03-11 06:08 100864 ----a-w- c:\windows\system32\audiodg.exe
2015-02-03 03:11 . 2015-03-11 06:07 96768 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-02-03 03:11 . 2015-03-11 06:07 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-02-03 03:11 . 2015-03-11 06:07 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2015-02-03 03:10 . 2015-03-11 06:07 8704 ----a-w- c:\windows\system32\pcaevts.dll
2015-02-03 03:09 . 2015-03-11 06:07 2048 ----a-w- c:\windows\system32\mferror.dll
2015-02-03 03:00 . 2015-03-11 06:08 593920 ----a-w- c:\windows\system32\drivers\PEAuth.sys
2015-02-03 02:26 . 2015-03-11 06:07 50176 ----a-w- c:\windows\system32\drivers\appid.sys
2015-01-30 23:56 . 2015-03-11 06:08 370488 ----a-w- c:\windows\system32\drivers\cng.sys
2015-01-28 06:46 . 2015-01-28 06:49 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-01-27 23:36 . 2015-02-11 06:56 1167520 ----a-w- c:\windows\system32\aitstatic.exe
2006-03-20 14:37 . 2008-02-24 21:47 5689344 ----a-w- c:\program files\mplayerc.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-04-07 11:31 644608 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2015-02-26 31346784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMail"="c:\program files\Seznam\Postak\Postak.exe" [2008-02-21 453936]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-04-07 5512912]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SJphone 1.65.lnk]
backup=c:\windows\pss\SJphone 1.65.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SJphone 1.65.lnk
.
[HKLM\~\startupfolder\C:^Users^Rodiče^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
path=c:\users\Rodiče\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScanRegistry]
C:\W [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StillImageMonitor]
C:\W [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2013-04-21 19:43 59720 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
2014-05-28 04:46 455512 ----a-w- c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2010-11-20 21:29 144384 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eyeBeam SIP Client]
2006-05-31 16:05 18550784 ----a-w- c:\program files\CounterPath\X-Lite\x-lite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_DFFE5E47E07B1E117C76A22C295BA5AC]
2015-04-13 21:55 812872 ----a-w- c:\users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleDriveSync]
2015-02-19 13:24 26232152 ----a-w- c:\program files\Google\Drive\googledrivesync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KONICA MINOLTA magicolor 2400W STD]
2005-07-23 11:52 184320 ----a-w- c:\windows\System32\MSTMON_S.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchList]
2007-03-21 12:41 145496 ----a-w- c:\program files\Pinnacle\Studio 11\LaunchList2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2008-08-21 01:18 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-11-02 08:38 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecSche]
2003-11-12 09:08 466944 ----a-w- c:\program files\TVR\RecSche.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-03-26 11:21 5369856 ----a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2010-11-20 21:29 1174016 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2009-07-14 01:14 65024 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
R2 gupdate1ca24ec3816786f;Služba Google Update (gupdate1ca24ec3816786f);c:\program files\Google\Update\GoogleUpdate.exe [2014-10-30 107912]
R3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-04-07 3205216]
R3 AVHybrid;AVHybrid service;c:\windows\system32\DRIVERS\AVHybrid.sys [2005-04-29 999680]
R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [2011-10-10 20504]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-03-13 102912]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2008-11-25 47360]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-17 1343400]
R3 WMSVC;Služba webové správy;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 9728]
R3 xxxHpSAMD;xxxHpSAMD;c:\windows\system32\drivers\HpSAMD.sys [2009-07-14 67152]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2015-04-07 788272]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2015-04-07 427736]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2015-04-07 24144]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2015-04-07 73440]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2015-04-07 106912]
S2 CSHelper;CopySafe Helper Service;c:\program files\Common Files\ArtistScope\CSHelper32.exe [2012-09-26 236536]
S2 HP DS Service;HP DS Service;c:\program files\HP\HPBDSService\HPBDSService.exe [2010-10-27 13824]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-27 145920]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-01-02 315488]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-04-07 220240]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
*Deregistered* - aswFsBlk
*Deregistered* - aswTdi
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-06-16 12:38 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-04-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 17:57]
.
2015-04-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-11 20:14]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.papeweb.cz/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do Microsoft Excelu - c:\progra~1\MICROS~3\Office15\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Rodiče\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Rodiče\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do OneNotu - c:\progra~1\MICROS~3\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.10.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} - hxxps://maxibps.postovnisporitelna.cz/Comp/CSOBEnroll.dll
FF - ProfilePath - c:\users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search/?trackid=sp-006
FF - prefs.js: browser.search.selectedEngine - Google (avast)
FF - prefs.js: browser.startup.homepage - hxxp://www.papeweb.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search/?trackid=sp-006
.
.
------- Asociace souborů -------
.
txtfile="c:\program files\PSPad editor\PSPad.exe" "%1"
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{40498DEF-8B13-44A6-A1A7-69DFE36E9210} - (no file)
MSConfigStartUp-Anti-phishing Domain Advisor - c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe
MSConfigStartUp-ComplexWebServer - c:\complexwebserver\bin\ServiceDirect.exe
MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
MSConfigStartUp-Freebie Notes - c:\program files\Power Soft\Freebie Notes\FreebieNotes.exe
MSConfigStartUp-Google Quick Search Box - c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-KBD - c:\hp\KBD\KbdStub.EXE
MSConfigStartUp-SpywareTerminator - c:\program files\Spyware Terminator\SpywareTerminatorShield.exe
MSConfigStartUp-SSDMonitor - c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
MSConfigStartUp-StartCCC - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
MSConfigStartUp-WinDVRCtrl - c:\windows\WDVRCtrl.exe
AddRemove-{C71BC882-811F-4A92-8121-3EE55319556A}}_is1 - c:\orsia\Am_Denik\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_17_0_0_169_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_17_0_0_169_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(4692)
c:\program files\Zoner\Callisto 4\Program\fshex40.dll
c:\program files\Zoner\Callisto 4\Program\FShEx40Res.CZ
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lvhidsvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\tcpsvcs.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2015-04-20 14:48:09 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-04-20 12:47
.
Před spuštěním: 8 828 547 072
Po spuštění: 8 075 665 408
.
- - End Of File - - 9714864E32DD38F209B68D2B3A04EE28
A36C5E4F47E84449FF07ED3517B43A31
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
- Otevrete Poznamkovy blok (Start -> Spustit -> notepad)
- zkopirujte do nej skript nize a ulozte jej take do korenoveho adresare jako CFScript (Typ souboru: Textovy dokument)
Kód: Vybrat vše
KillAll:: File:: c:\windows\Tasks\Google Software Updater.job RegLock:: [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] ClearJavaCache:: Reboot:: - Tento CFScript.txt chytte, doslova pretahnete nad ikonu ComboFixu a pustte.

- Po restartu na Vas vyskoci log, jehoz obsah mi vlozte do dalsi odpovedi.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Dobrý den, posílám další log:
ComboFix 15-04-19.01 - Rodiče 20.04.2015 15:46:02.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3070.1634 [GMT 2:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\Google Software Updater.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-03-20 do 2015-04-20 )))))))))))))))))))))))))))))))
.
.
2015-04-20 19:04 . 2015-04-20 19:04 -------- d-----w- c:\users\NFSU\AppData\Local\temp
2015-04-20 19:04 . 2015-04-20 19:04 -------- d-----w- c:\users\Lenka\AppData\Local\temp
2015-04-20 19:04 . 2015-04-20 19:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-04-20 12:14 . 2015-04-20 19:11 -------- d-----w- c:\users\Rodiče\AppData\Local\temp
2015-04-19 21:17 . 2015-04-19 21:17 -------- d-----w- c:\programdata\Malwarebytes
2015-04-19 21:16 . 2015-04-19 23:29 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-04-19 21:16 . 2015-04-19 21:16 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-04-19 21:15 . 2015-04-19 21:15 92888 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-04-19 20:37 . 2015-04-19 23:30 -------- d-----w- C:\FRST
2015-04-15 12:02 . 2015-03-23 03:06 860160 ----a-w- c:\windows\system32\appraiser.dll
2015-04-15 12:02 . 2015-03-23 03:06 576000 ----a-w- c:\windows\system32\generaltel.dll
2015-04-15 12:02 . 2015-03-23 03:06 630784 ----a-w- c:\windows\system32\invagent.dll
2015-04-15 12:02 . 2015-03-23 03:06 331264 ----a-w- c:\windows\system32\devinv.dll
2015-04-15 12:02 . 2015-03-23 03:06 26112 ----a-w- c:\windows\system32\acmigration.dll
2015-04-15 12:02 . 2015-03-23 02:59 896000 ----a-w- c:\windows\system32\aeinv.dll
2015-04-15 12:02 . 2015-03-23 03:06 202752 ----a-w- c:\windows\system32\aepdu.dll
2015-04-15 12:02 . 2015-03-23 03:06 159744 ----a-w- c:\windows\system32\aepic.dll
2015-04-15 12:02 . 2015-03-04 04:16 249784 ----a-w- c:\windows\system32\clfs.sys
2015-04-15 12:02 . 2015-03-04 04:10 58880 ----a-w- c:\windows\system32\clfsw32.dll
2015-04-15 12:00 . 2015-03-25 03:00 3088384 ----a-w- c:\windows\system32\wucltux.dll
2015-04-15 12:00 . 2015-03-25 03:00 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-04-15 12:00 . 2015-03-25 03:00 33792 ----a-w- c:\windows\system32\wuapp.exe
2015-04-15 12:00 . 2015-03-25 03:00 131584 ----a-w- c:\windows\system32\wuauclt.exe
2015-04-15 12:00 . 2015-03-25 03:00 92672 ----a-w- c:\windows\system32\wudriver.dll
2015-04-15 12:00 . 2015-03-25 03:00 566784 ----a-w- c:\windows\system32\wuapi.dll
2015-04-15 12:00 . 2015-03-25 03:00 35328 ----a-w- c:\windows\system32\wups2.dll
2015-04-15 12:00 . 2015-03-25 03:00 29696 ----a-w- c:\windows\system32\wups.dll
2015-04-15 12:00 . 2015-03-25 03:00 2020864 ----a-w- c:\windows\system32\wuaueng.dll
2015-04-15 12:00 . 2015-03-25 03:00 173056 ----a-w- c:\windows\system32\wuwebv.dll
2015-04-15 12:00 . 2015-03-25 03:00 50176 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-04-15 11:59 . 2015-02-25 03:03 514560 ----a-w- c:\windows\system32\drivers\http.sys
2015-04-15 11:59 . 2015-03-10 03:08 1237504 ----a-w- c:\windows\system32\msxml3.dll
2015-04-15 11:59 . 2015-03-10 03:05 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-04-07 11:32 . 2015-04-07 11:31 291312 ----a-w- c:\windows\system32\aswBoot.exe
2015-04-07 11:31 . 2015-04-07 11:31 43112 ----a-w- c:\windows\avastSS.scr
2015-04-06 04:58 . 2015-04-06 04:58 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
2015-04-06 04:56 . 2015-04-06 04:59 -------- d-----w- c:\program files\Microsoft SQL Server
2015-04-06 04:48 . 2015-04-06 04:48 -------- d-----w- c:\program files\Microsoft Analysis Services
2015-04-04 20:44 . 2015-04-04 20:45 -------- d-s---w- c:\windows\system32\GWX
2015-04-02 13:26 . 2015-04-02 13:26 3039416 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\1029\MSOINTL.DLL
2015-03-31 08:22 . 2015-03-31 08:22 550064 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSOSQM.EXE
2015-03-31 08:22 . 2015-03-31 08:22 26825912 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2015-03-31 08:22 . 2015-03-31 08:22 112452792 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSORES.DLL
2015-03-23 17:18 . 2015-03-23 17:18 -------- d-----w- c:\users\Rodiče\Tracing
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-04-15 17:57 . 2012-04-03 06:33 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-04-15 17:57 . 2011-06-13 16:03 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-04-07 11:32 . 2014-01-02 17:36 106912 ----a-w- c:\windows\system32\drivers\aswStm.sys
2015-04-07 11:32 . 2014-06-23 04:41 24144 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-04-07 11:32 . 2013-03-14 05:27 208024 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-04-07 11:32 . 2013-03-14 05:27 49904 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-04-07 11:32 . 2012-11-04 19:41 81728 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2015-04-07 11:32 . 2008-04-01 14:46 427736 ----a-w- c:\windows\system32\drivers\aswSP.sys
2015-04-07 11:32 . 2008-02-24 21:37 73440 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-04-07 11:30 . 2011-11-20 07:47 788272 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-03-17 04:57 . 2015-04-15 12:01 248832 ----a-w- c:\windows\system32\schannel.dll
2015-03-14 10:06 . 2015-04-17 11:30 9119072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{01A76777-1CDB-47D9-80DC-D2948FAD243B}\mpengine.dll
2015-02-26 03:11 . 2015-03-11 06:09 2381312 ----a-w- c:\windows\system32\win32k.sys
2015-02-24 03:23 . 2009-10-03 15:14 246920 ------w- c:\windows\system32\MpSigStub.exe
2015-02-20 04:13 . 2015-03-11 06:08 26624 ----a-w- c:\windows\system32\lpk.dll
2015-02-20 04:13 . 2015-03-11 06:08 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-02-20 04:13 . 2015-03-11 06:08 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-02-20 04:13 . 2015-03-11 06:08 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-02-20 03:09 . 2015-03-11 06:08 299008 ----a-w- c:\windows\system32\atmfd.dll
2015-02-17 13:29 . 2015-02-17 13:29 1247912 ----a-w- c:\windows\system32\FM20.DLL
2015-02-04 10:23 . 2015-02-04 10:23 875688 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-02-04 02:54 . 2015-03-11 06:08 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2015-02-03 03:16 . 2015-03-11 06:08 78784 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2015-02-03 03:12 . 2015-03-11 06:08 179200 ----a-w- c:\windows\system32\wintrust.dll
2015-02-03 03:12 . 2015-03-11 06:08 617984 ----a-w- c:\windows\system32\wmdrmsdk.dll
2015-02-03 03:12 . 2015-03-11 06:10 1230848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2015-02-03 03:12 . 2015-03-11 06:08 171520 ----a-w- c:\windows\system32\ubpm.dll
2015-02-03 03:12 . 2015-03-11 06:07 4096 ----a-w- c:\windows\system32\msdxm.ocx
2015-02-03 03:12 . 2015-03-11 06:07 4096 ----a-w- c:\windows\system32\dxmasf.dll
2015-02-03 03:12 . 2015-03-11 06:07 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-02-03 03:12 . 2015-03-11 06:08 1329664 ----a-w- c:\windows\system32\quartz.dll
2015-02-03 03:12 . 2015-03-11 06:08 519680 ----a-w- c:\windows\system32\qdvd.dll
2015-02-03 03:12 . 2015-03-11 06:08 442880 ----a-w- c:\windows\system32\AUDIOKSE.dll
2015-02-03 03:12 . 2015-03-11 06:08 157184 ----a-w- c:\windows\system32\pcasvc.dll
2015-02-03 03:12 . 2015-03-11 06:08 28160 ----a-w- c:\windows\system32\pcadm.dll
2015-02-03 03:12 . 2015-03-11 06:07 8192 ----a-w- c:\windows\system32\spwmp.dll
2015-02-03 03:12 . 2015-03-11 06:08 504320 ----a-w- c:\windows\system32\msscp.dll
2015-02-03 03:12 . 2015-03-11 06:08 265216 ----a-w- c:\windows\system32\msnetobj.dll
2015-02-03 03:12 . 2015-03-11 06:07 10752 ----a-w- c:\windows\system32\msmmsp.dll
2015-02-03 03:12 . 2015-03-11 06:08 3209728 ----a-w- c:\windows\system32\mf.dll
2015-02-03 03:12 . 2015-03-11 06:08 354816 ----a-w- c:\windows\system32\mfplat.dll
2015-02-03 03:12 . 2015-03-11 06:07 103424 ----a-w- c:\windows\system32\mfps.dll
2015-02-03 03:12 . 2015-03-11 06:08 489984 ----a-w- c:\windows\system32\evr.dll
2015-02-03 03:12 . 2015-03-11 06:07 275968 ----a-w- c:\windows\system32\EncDump.dll
2015-02-03 03:12 . 2015-03-11 06:08 988160 ----a-w- c:\windows\system32\drmv2clt.dll
2015-02-03 03:12 . 2015-03-11 06:08 406016 ----a-w- c:\windows\system32\drmmgrtn.dll
2015-02-03 03:12 . 2015-03-11 06:08 1174528 ----a-w- c:\windows\system32\crypt32.dll
2015-02-03 03:12 . 2015-03-11 06:08 1005056 ----a-w- c:\windows\system32\cryptui.dll
2015-02-03 03:12 . 2015-03-11 06:08 103936 ----a-w- c:\windows\system32\cryptnet.dll
2015-02-03 03:12 . 2015-03-11 06:08 143872 ----a-w- c:\windows\system32\cryptsvc.dll
2015-02-03 03:12 . 2015-03-11 06:07 81408 ----a-w- c:\windows\system32\cryptsp.dll
2015-02-03 03:12 . 2015-03-11 06:08 744960 ----a-w- c:\windows\system32\blackbox.dll
2015-02-03 03:12 . 2015-03-11 06:08 475136 ----a-w- c:\windows\system32\audiosrv.dll
2015-02-03 03:12 . 2015-03-11 06:08 374784 ----a-w- c:\windows\system32\AudioEng.dll
2015-02-03 03:12 . 2015-03-11 06:07 50688 ----a-w- c:\windows\system32\appidapi.dll
2015-02-03 03:12 . 2015-03-11 06:07 195584 ----a-w- c:\windows\system32\AudioSes.dll
2015-02-03 03:12 . 2015-03-11 06:07 27648 ----a-w- c:\windows\system32\appidsvc.dll
2015-02-03 03:11 . 2015-03-11 06:08 50176 ----a-w- c:\windows\system32\rrinstaller.exe
2015-02-03 03:11 . 2015-03-11 06:07 9728 ----a-w- c:\windows\system32\pcawrk.exe
2015-02-03 03:11 . 2015-03-11 06:07 8192 ----a-w- c:\windows\system32\pcalua.exe
2015-02-03 03:11 . 2015-03-11 06:07 23040 ----a-w- c:\windows\system32\mfpmp.exe
2015-02-03 03:11 . 2015-03-11 06:08 100864 ----a-w- c:\windows\system32\audiodg.exe
2015-02-03 03:11 . 2015-03-11 06:07 96768 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-02-03 03:11 . 2015-03-11 06:07 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-02-03 03:11 . 2015-03-11 06:07 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2015-02-03 03:10 . 2015-03-11 06:07 8704 ----a-w- c:\windows\system32\pcaevts.dll
2015-02-03 03:09 . 2015-03-11 06:07 2048 ----a-w- c:\windows\system32\mferror.dll
2015-02-03 03:00 . 2015-03-11 06:08 593920 ----a-w- c:\windows\system32\drivers\PEAuth.sys
2015-02-03 02:26 . 2015-03-11 06:07 50176 ----a-w- c:\windows\system32\drivers\appid.sys
2015-01-30 23:56 . 2015-03-11 06:08 370488 ----a-w- c:\windows\system32\drivers\cng.sys
2015-01-28 06:46 . 2015-01-28 06:49 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-01-27 23:36 . 2015-02-11 06:56 1167520 ----a-w- c:\windows\system32\aitstatic.exe
2006-03-20 14:37 . 2008-02-24 21:47 5689344 ----a-w- c:\program files\mplayerc.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-04-07 11:31 644608 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2015-02-26 31346784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMail"="c:\program files\Seznam\Postak\Postak.exe" [2008-02-21 453936]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-04-07 5512912]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SJphone 1.65.lnk]
backup=c:\windows\pss\SJphone 1.65.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SJphone 1.65.lnk
.
[HKLM\~\startupfolder\C:^Users^Rodiče^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
path=c:\users\Rodiče\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScanRegistry]
C:\W [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StillImageMonitor]
C:\W [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2013-04-21 19:43 59720 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
2014-05-28 04:46 455512 ----a-w- c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2010-11-20 21:29 144384 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eyeBeam SIP Client]
2006-05-31 16:05 18550784 ----a-w- c:\program files\CounterPath\X-Lite\x-lite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_DFFE5E47E07B1E117C76A22C295BA5AC]
2015-04-13 21:55 812872 ----a-w- c:\users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleDriveSync]
2015-02-19 13:24 26232152 ----a-w- c:\program files\Google\Drive\googledrivesync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KONICA MINOLTA magicolor 2400W STD]
2005-07-23 11:52 184320 ----a-w- c:\windows\System32\MSTMON_S.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchList]
2007-03-21 12:41 145496 ----a-w- c:\program files\Pinnacle\Studio 11\LaunchList2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2008-08-21 01:18 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-11-02 08:38 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecSche]
2003-11-12 09:08 466944 ----a-w- c:\program files\TVR\RecSche.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-03-26 11:21 5369856 ----a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2010-11-20 21:29 1174016 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2009-07-14 01:14 65024 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2015-04-07 106912]
R2 gupdate1ca24ec3816786f;Služba Google Update (gupdate1ca24ec3816786f);c:\program files\Google\Update\GoogleUpdate.exe [2014-10-30 107912]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-01-02 315488]
R3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-04-07 3205216]
R3 AVHybrid;AVHybrid service;c:\windows\system32\DRIVERS\AVHybrid.sys [2005-04-29 999680]
R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [2011-10-10 20504]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-03-13 102912]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2008-11-25 47360]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-17 1343400]
R3 WMSVC;Služba webové správy;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 9728]
R3 xxxHpSAMD;xxxHpSAMD;c:\windows\system32\drivers\HpSAMD.sys [2009-07-14 67152]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2015-04-07 788272]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2015-04-07 427736]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2015-04-07 24144]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2015-04-07 73440]
S2 CSHelper;CopySafe Helper Service;c:\program files\Common Files\ArtistScope\CSHelper32.exe [2012-09-26 236536]
S2 HP DS Service;HP DS Service;c:\program files\HP\HPBDSService\HPBDSService.exe [2010-10-27 13824]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-27 145920]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-04-07 220240]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - aswFsBlk
*Deregistered* - aswTdi
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-06-16 12:38 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-04-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 17:57]
.
2015-04-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-11 20:14]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.papeweb.cz/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do Microsoft Excelu - c:\progra~1\MICROS~3\Office15\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Rodiče\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Rodiče\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do OneNotu - c:\progra~1\MICROS~3\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.10.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} - hxxps://maxibps.postovnisporitelna.cz/Comp/CSOBEnroll.dll
FF - ProfilePath - c:\users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search/?trackid=sp-006
FF - prefs.js: browser.search.selectedEngine - Google (avast)
FF - prefs.js: browser.startup.homepage - hxxp://www.papeweb.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search/?trackid=sp-006
.
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3912)
c:\program files\Zoner\Callisto 4\Program\fshex40.dll
c:\program files\Zoner\Callisto 4\Program\FShEx40Res.CZ
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lvhidsvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\tcpsvcs.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\GWX\GWXConfigManager.exe
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
c:\windows\TEMP\D1DF41D3-696D-401A-8B8C-0C09B75C1CF8\dismhost.exe
.
**************************************************************************
.
Celkový čas: 2015-04-20 21:31:18 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-04-20 19:31
ComboFix2.txt 2015-04-20 12:48
.
Před spuštěním: 8 114 995 200
Po spuštění: 7 953 715 200
.
- - End Of File - - 62CB36DF48099A97EDB156287F807538
A36C5E4F47E84449FF07ED3517B43A31
ComboFix 15-04-19.01 - Rodiče 20.04.2015 15:46:02.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3070.1634 [GMT 2:00]
Spuštěný z: C:\ComboFix.exe
Použité ovládací přepínače :: C:\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\Tasks\Google Software Updater.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-03-20 do 2015-04-20 )))))))))))))))))))))))))))))))
.
.
2015-04-20 19:04 . 2015-04-20 19:04 -------- d-----w- c:\users\NFSU\AppData\Local\temp
2015-04-20 19:04 . 2015-04-20 19:04 -------- d-----w- c:\users\Lenka\AppData\Local\temp
2015-04-20 19:04 . 2015-04-20 19:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-04-20 12:14 . 2015-04-20 19:11 -------- d-----w- c:\users\Rodiče\AppData\Local\temp
2015-04-19 21:17 . 2015-04-19 21:17 -------- d-----w- c:\programdata\Malwarebytes
2015-04-19 21:16 . 2015-04-19 23:29 -------- d-----w- c:\programdata\Malwarebytes' Anti-Malware (portable)
2015-04-19 21:16 . 2015-04-19 21:16 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-04-19 21:15 . 2015-04-19 21:15 92888 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-04-19 20:37 . 2015-04-19 23:30 -------- d-----w- C:\FRST
2015-04-15 12:02 . 2015-03-23 03:06 860160 ----a-w- c:\windows\system32\appraiser.dll
2015-04-15 12:02 . 2015-03-23 03:06 576000 ----a-w- c:\windows\system32\generaltel.dll
2015-04-15 12:02 . 2015-03-23 03:06 630784 ----a-w- c:\windows\system32\invagent.dll
2015-04-15 12:02 . 2015-03-23 03:06 331264 ----a-w- c:\windows\system32\devinv.dll
2015-04-15 12:02 . 2015-03-23 03:06 26112 ----a-w- c:\windows\system32\acmigration.dll
2015-04-15 12:02 . 2015-03-23 02:59 896000 ----a-w- c:\windows\system32\aeinv.dll
2015-04-15 12:02 . 2015-03-23 03:06 202752 ----a-w- c:\windows\system32\aepdu.dll
2015-04-15 12:02 . 2015-03-23 03:06 159744 ----a-w- c:\windows\system32\aepic.dll
2015-04-15 12:02 . 2015-03-04 04:16 249784 ----a-w- c:\windows\system32\clfs.sys
2015-04-15 12:02 . 2015-03-04 04:10 58880 ----a-w- c:\windows\system32\clfsw32.dll
2015-04-15 12:00 . 2015-03-25 03:00 3088384 ----a-w- c:\windows\system32\wucltux.dll
2015-04-15 12:00 . 2015-03-25 03:00 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
2015-04-15 12:00 . 2015-03-25 03:00 33792 ----a-w- c:\windows\system32\wuapp.exe
2015-04-15 12:00 . 2015-03-25 03:00 131584 ----a-w- c:\windows\system32\wuauclt.exe
2015-04-15 12:00 . 2015-03-25 03:00 92672 ----a-w- c:\windows\system32\wudriver.dll
2015-04-15 12:00 . 2015-03-25 03:00 566784 ----a-w- c:\windows\system32\wuapi.dll
2015-04-15 12:00 . 2015-03-25 03:00 35328 ----a-w- c:\windows\system32\wups2.dll
2015-04-15 12:00 . 2015-03-25 03:00 29696 ----a-w- c:\windows\system32\wups.dll
2015-04-15 12:00 . 2015-03-25 03:00 2020864 ----a-w- c:\windows\system32\wuaueng.dll
2015-04-15 12:00 . 2015-03-25 03:00 173056 ----a-w- c:\windows\system32\wuwebv.dll
2015-04-15 12:00 . 2015-03-25 03:00 50176 ----a-w- c:\windows\system32\WinSetupUI.dll
2015-04-15 11:59 . 2015-02-25 03:03 514560 ----a-w- c:\windows\system32\drivers\http.sys
2015-04-15 11:59 . 2015-03-10 03:08 1237504 ----a-w- c:\windows\system32\msxml3.dll
2015-04-15 11:59 . 2015-03-10 03:05 2048 ----a-w- c:\windows\system32\msxml3r.dll
2015-04-07 11:32 . 2015-04-07 11:31 291312 ----a-w- c:\windows\system32\aswBoot.exe
2015-04-07 11:31 . 2015-04-07 11:31 43112 ----a-w- c:\windows\avastSS.scr
2015-04-06 04:58 . 2015-04-06 04:58 -------- d-----w- c:\programdata\regid.1991-06.com.microsoft
2015-04-06 04:56 . 2015-04-06 04:59 -------- d-----w- c:\program files\Microsoft SQL Server
2015-04-06 04:48 . 2015-04-06 04:48 -------- d-----w- c:\program files\Microsoft Analysis Services
2015-04-04 20:44 . 2015-04-04 20:45 -------- d-s---w- c:\windows\system32\GWX
2015-04-02 13:26 . 2015-04-02 13:26 3039416 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\1029\MSOINTL.DLL
2015-03-31 08:22 . 2015-03-31 08:22 550064 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSOSQM.EXE
2015-03-31 08:22 . 2015-03-31 08:22 26825912 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSO.DLL
2015-03-31 08:22 . 2015-03-31 08:22 112452792 ----a-w- c:\program files\Common Files\Microsoft Shared\OFFICE15\MSORES.DLL
2015-03-23 17:18 . 2015-03-23 17:18 -------- d-----w- c:\users\Rodiče\Tracing
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-04-15 17:57 . 2012-04-03 06:33 778416 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-04-15 17:57 . 2011-06-13 16:03 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-04-07 11:32 . 2014-01-02 17:36 106912 ----a-w- c:\windows\system32\drivers\aswStm.sys
2015-04-07 11:32 . 2014-06-23 04:41 24144 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-04-07 11:32 . 2013-03-14 05:27 208024 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-04-07 11:32 . 2013-03-14 05:27 49904 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-04-07 11:32 . 2012-11-04 19:41 81728 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2015-04-07 11:32 . 2008-04-01 14:46 427736 ----a-w- c:\windows\system32\drivers\aswSP.sys
2015-04-07 11:32 . 2008-02-24 21:37 73440 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-04-07 11:30 . 2011-11-20 07:47 788272 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-03-17 04:57 . 2015-04-15 12:01 248832 ----a-w- c:\windows\system32\schannel.dll
2015-03-14 10:06 . 2015-04-17 11:30 9119072 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{01A76777-1CDB-47D9-80DC-D2948FAD243B}\mpengine.dll
2015-02-26 03:11 . 2015-03-11 06:09 2381312 ----a-w- c:\windows\system32\win32k.sys
2015-02-24 03:23 . 2009-10-03 15:14 246920 ------w- c:\windows\system32\MpSigStub.exe
2015-02-20 04:13 . 2015-03-11 06:08 26624 ----a-w- c:\windows\system32\lpk.dll
2015-02-20 04:13 . 2015-03-11 06:08 70656 ----a-w- c:\windows\system32\fontsub.dll
2015-02-20 04:13 . 2015-03-11 06:08 10240 ----a-w- c:\windows\system32\dciman32.dll
2015-02-20 04:13 . 2015-03-11 06:08 34304 ----a-w- c:\windows\system32\atmlib.dll
2015-02-20 03:09 . 2015-03-11 06:08 299008 ----a-w- c:\windows\system32\atmfd.dll
2015-02-17 13:29 . 2015-02-17 13:29 1247912 ----a-w- c:\windows\system32\FM20.DLL
2015-02-04 10:23 . 2015-02-04 10:23 875688 ----a-w- c:\windows\system32\msvcr120_clr0400.dll
2015-02-04 02:54 . 2015-03-11 06:08 417792 ----a-w- c:\windows\system32\WMPhoto.dll
2015-02-03 03:16 . 2015-03-11 06:08 78784 ----a-w- c:\windows\system32\drivers\mountmgr.sys
2015-02-03 03:12 . 2015-03-11 06:08 179200 ----a-w- c:\windows\system32\wintrust.dll
2015-02-03 03:12 . 2015-03-11 06:08 617984 ----a-w- c:\windows\system32\wmdrmsdk.dll
2015-02-03 03:12 . 2015-03-11 06:10 1230848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2015-02-03 03:12 . 2015-03-11 06:08 171520 ----a-w- c:\windows\system32\ubpm.dll
2015-02-03 03:12 . 2015-03-11 06:07 4096 ----a-w- c:\windows\system32\msdxm.ocx
2015-02-03 03:12 . 2015-03-11 06:07 4096 ----a-w- c:\windows\system32\dxmasf.dll
2015-02-03 03:12 . 2015-03-11 06:07 50176 ----a-w- c:\windows\system32\setbcdlocale.dll
2015-02-03 03:12 . 2015-03-11 06:08 1329664 ----a-w- c:\windows\system32\quartz.dll
2015-02-03 03:12 . 2015-03-11 06:08 519680 ----a-w- c:\windows\system32\qdvd.dll
2015-02-03 03:12 . 2015-03-11 06:08 442880 ----a-w- c:\windows\system32\AUDIOKSE.dll
2015-02-03 03:12 . 2015-03-11 06:08 157184 ----a-w- c:\windows\system32\pcasvc.dll
2015-02-03 03:12 . 2015-03-11 06:08 28160 ----a-w- c:\windows\system32\pcadm.dll
2015-02-03 03:12 . 2015-03-11 06:07 8192 ----a-w- c:\windows\system32\spwmp.dll
2015-02-03 03:12 . 2015-03-11 06:08 504320 ----a-w- c:\windows\system32\msscp.dll
2015-02-03 03:12 . 2015-03-11 06:08 265216 ----a-w- c:\windows\system32\msnetobj.dll
2015-02-03 03:12 . 2015-03-11 06:07 10752 ----a-w- c:\windows\system32\msmmsp.dll
2015-02-03 03:12 . 2015-03-11 06:08 3209728 ----a-w- c:\windows\system32\mf.dll
2015-02-03 03:12 . 2015-03-11 06:08 354816 ----a-w- c:\windows\system32\mfplat.dll
2015-02-03 03:12 . 2015-03-11 06:07 103424 ----a-w- c:\windows\system32\mfps.dll
2015-02-03 03:12 . 2015-03-11 06:08 489984 ----a-w- c:\windows\system32\evr.dll
2015-02-03 03:12 . 2015-03-11 06:07 275968 ----a-w- c:\windows\system32\EncDump.dll
2015-02-03 03:12 . 2015-03-11 06:08 988160 ----a-w- c:\windows\system32\drmv2clt.dll
2015-02-03 03:12 . 2015-03-11 06:08 406016 ----a-w- c:\windows\system32\drmmgrtn.dll
2015-02-03 03:12 . 2015-03-11 06:08 1174528 ----a-w- c:\windows\system32\crypt32.dll
2015-02-03 03:12 . 2015-03-11 06:08 1005056 ----a-w- c:\windows\system32\cryptui.dll
2015-02-03 03:12 . 2015-03-11 06:08 103936 ----a-w- c:\windows\system32\cryptnet.dll
2015-02-03 03:12 . 2015-03-11 06:08 143872 ----a-w- c:\windows\system32\cryptsvc.dll
2015-02-03 03:12 . 2015-03-11 06:07 81408 ----a-w- c:\windows\system32\cryptsp.dll
2015-02-03 03:12 . 2015-03-11 06:08 744960 ----a-w- c:\windows\system32\blackbox.dll
2015-02-03 03:12 . 2015-03-11 06:08 475136 ----a-w- c:\windows\system32\audiosrv.dll
2015-02-03 03:12 . 2015-03-11 06:08 374784 ----a-w- c:\windows\system32\AudioEng.dll
2015-02-03 03:12 . 2015-03-11 06:07 50688 ----a-w- c:\windows\system32\appidapi.dll
2015-02-03 03:12 . 2015-03-11 06:07 195584 ----a-w- c:\windows\system32\AudioSes.dll
2015-02-03 03:12 . 2015-03-11 06:07 27648 ----a-w- c:\windows\system32\appidsvc.dll
2015-02-03 03:11 . 2015-03-11 06:08 50176 ----a-w- c:\windows\system32\rrinstaller.exe
2015-02-03 03:11 . 2015-03-11 06:07 9728 ----a-w- c:\windows\system32\pcawrk.exe
2015-02-03 03:11 . 2015-03-11 06:07 8192 ----a-w- c:\windows\system32\pcalua.exe
2015-02-03 03:11 . 2015-03-11 06:07 23040 ----a-w- c:\windows\system32\mfpmp.exe
2015-02-03 03:11 . 2015-03-11 06:08 100864 ----a-w- c:\windows\system32\audiodg.exe
2015-02-03 03:11 . 2015-03-11 06:07 96768 ----a-w- c:\windows\system32\appidpolicyconverter.exe
2015-02-03 03:11 . 2015-03-11 06:07 16896 ----a-w- c:\windows\system32\appidcertstorecheck.exe
2015-02-03 03:11 . 2015-03-11 06:07 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2015-02-03 03:10 . 2015-03-11 06:07 8704 ----a-w- c:\windows\system32\pcaevts.dll
2015-02-03 03:09 . 2015-03-11 06:07 2048 ----a-w- c:\windows\system32\mferror.dll
2015-02-03 03:00 . 2015-03-11 06:08 593920 ----a-w- c:\windows\system32\drivers\PEAuth.sys
2015-02-03 02:26 . 2015-03-11 06:07 50176 ----a-w- c:\windows\system32\drivers\appid.sys
2015-01-30 23:56 . 2015-03-11 06:08 370488 ----a-w- c:\windows\system32\drivers\cng.sys
2015-01-28 06:46 . 2015-01-28 06:49 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-01-27 23:36 . 2015-02-11 06:56 1167520 ----a-w- c:\windows\system32\aitstatic.exe
2006-03-20 14:37 . 2008-02-24 21:47 5689344 ----a-w- c:\program files\mplayerc.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\opera\program\plugins\ssldivx.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2015-03-18 12:08 1729752 ----a-w- c:\progra~1\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-04-07 11:31 644608 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-02-19 13:24 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2015-02-26 31346784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMail"="c:\program files\Seznam\Postak\Postak.exe" [2008-02-21 453936]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-04-07 5512912]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SJphone 1.65.lnk]
backup=c:\windows\pss\SJphone 1.65.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SJphone 1.65.lnk
.
[HKLM\~\startupfolder\C:^Users^Rodiče^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
path=c:\users\Rodiče\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScanRegistry]
C:\W [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StillImageMonitor]
C:\W [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2013-04-21 19:43 59720 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
2014-05-28 04:46 455512 ----a-w- c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2010-11-20 21:29 144384 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eyeBeam SIP Client]
2006-05-31 16:05 18550784 ----a-w- c:\program files\CounterPath\X-Lite\x-lite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_DFFE5E47E07B1E117C76A22C295BA5AC]
2015-04-13 21:55 812872 ----a-w- c:\users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleDriveSync]
2015-02-19 13:24 26232152 ----a-w- c:\program files\Google\Drive\googledrivesync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KONICA MINOLTA magicolor 2400W STD]
2005-07-23 11:52 184320 ----a-w- c:\windows\System32\MSTMON_S.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchList]
2007-03-21 12:41 145496 ----a-w- c:\program files\Pinnacle\Studio 11\LaunchList2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2008-08-21 01:18 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-11-02 08:38 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecSche]
2003-11-12 09:08 466944 ----a-w- c:\program files\TVR\RecSche.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-03-26 11:21 5369856 ----a-w- c:\windows\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2010-11-20 21:29 1174016 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2009-07-14 01:14 65024 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2015-04-07 106912]
R2 gupdate1ca24ec3816786f;Služba Google Update (gupdate1ca24ec3816786f);c:\program files\Google\Update\GoogleUpdate.exe [2014-10-30 107912]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-01-02 315488]
R3 AvastVBoxSvc;AvastVBox COM Service;c:\program files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-04-07 3205216]
R3 AVHybrid;AVHybrid service;c:\windows\system32\DRIVERS\AVHybrid.sys [2005-04-29 999680]
R3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [2011-10-10 20504]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-03-13 102912]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2008-11-25 47360]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-17 1343400]
R3 WMSVC;Služba webové správy;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 9728]
R3 xxxHpSAMD;xxxHpSAMD;c:\windows\system32\drivers\HpSAMD.sys [2009-07-14 67152]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswKbd;aswKbd; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2015-04-07 788272]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2015-04-07 427736]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2015-04-07 24144]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2015-04-07 73440]
S2 CSHelper;CopySafe Helper Service;c:\program files\Common Files\ArtistScope\CSHelper32.exe [2012-09-26 236536]
S2 HP DS Service;HP DS Service;c:\program files\HP\HPBDSService\HPBDSService.exe [2010-10-27 13824]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-27 145920]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2014-09-12 4799760]
S2 VBoxAswDrv;VBoxAsw Support Driver;c:\program files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-04-07 220240]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - aswFsBlk
*Deregistered* - aswTdi
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-06-16 12:38 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-04-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 17:57]
.
2015-04-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-11 20:14]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.papeweb.cz/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do Microsoft Excelu - c:\progra~1\MICROS~3\Office15\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Rodiče\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\users\Rodiče\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&eslat do OneNotu - c:\progra~1\MICROS~3\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.10.1
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} - hxxps://maxibps.postovnisporitelna.cz/Comp/CSOBEnroll.dll
FF - ProfilePath - c:\users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\
FF - prefs.js: browser.search.defaulturl - hxxps://www.google.com/search/?trackid=sp-006
FF - prefs.js: browser.search.selectedEngine - Google (avast)
FF - prefs.js: browser.startup.homepage - hxxp://www.papeweb.cz
FF - prefs.js: keyword.URL - hxxps://www.google.com/search/?trackid=sp-006
.
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3912)
c:\program files\Zoner\Callisto 4\Program\fshex40.dll
c:\program files\Zoner\Callisto 4\Program\FShEx40Res.CZ
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\lvhidsvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\tcpsvcs.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\GWX\GWXConfigManager.exe
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
c:\windows\TEMP\D1DF41D3-696D-401A-8B8C-0C09B75C1CF8\dismhost.exe
.
**************************************************************************
.
Celkový čas: 2015-04-20 21:31:18 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-04-20 19:31
ComboFix2.txt 2015-04-20 12:48
.
Před spuštěním: 8 114 995 200
Po spuštění: 7 953 715 200
.
- - End Of File - - 62CB36DF48099A97EDB156287F807538
A36C5E4F47E84449FF07ED3517B43A31
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Dobrý den, proces (možná služba), co vytěžuje procesor je stále po restartu puštěná.
Posílám log FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by Rodiče (administrator) on CERNY on 21-04-2015 14:26:33
Running from C:\Users\Rodiče\Desktop
Loaded Profiles: Rodiče (Available profiles: Rodiče & Lenka & NFSU)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArtistScope Pty Ltd) C:\Program Files\Common Files\ArtistScope\CSHelper32.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(Hewlett-Packard Company) C:\Program Files\HP\HPBDSService\HPBDSService.exe
(HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Animation Technologies Inc.) C:\Windows\System32\lvhidsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Seznam.cz a.s.) C:\Program Files\Seznam\Postak\Postak.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\CompatTel\wicainventory.exe
(Google Inc.) C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SMail] => C:\Program Files\Seznam\Postak\Postak.exe [453936 2008-02-21] (Seznam.cz a.s.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-07] (Avast Software s.r.o.)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31346784 2015-02-26] (Skype Technologies S.A.)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\InprocServer32: [Default-pngfilt] <==== ATTENTION!
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-04-07] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.papeweb.cz/
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... DF&pc=AVBR
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {0EBFFFDA-ABB1-49B2-A89B-594D808AC84F} URL = http://download.seznam.cz/vyhledavani/o ... rceid=IE_5
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = http://www.crawler.com/search/dispatche ... tbid=60327
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://blekko.com/?source=c3348dd4&tbp= ... earchTerms}
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {41FF3879-BCB7-4B39-B274-FEE2EC2BB8F5} URL = http://www.google.cz/search?q={searchTe ... 1I7GPEA_cs
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = http://www.ask.com/web?o=15710&l=dis&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredimail.com/?search= ... m2_test_v2
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?p={searc ... r=chr-divx
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-07] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net ... plugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/ ... ontrol.cab
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} https://maxibps.postovnisporitelna.cz/C ... Enroll.dll
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.cz/OnlineScanner.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/In ... ct119b.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
FireFox:
========
FF ProfilePath: C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: hxxp://www.papeweb.cz
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2014-06-03] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @google.com/npPicasa2,version=2.0.0 -> C:\Program Files\Picasa2\npPicasa2.dll [2008-08-21] (Google, Inc.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Picasa2\npPicasa3.dll [2013-04-02] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 -> C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll [2011-10-03] (Google)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3533039139-1052968357-1368303399-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Rodiče\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin HKU\S-1-5-21-3533039139-1052968357-1368303399-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Rodiče\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-01-06] (Apple Inc.)
FF SearchPlugin: C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\searchplugins\google-avast.xml [2014-12-15]
FF Extension: No Name - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\artur.dubovoy@gmail.com [2015-04-10]
FF Extension: gTranslator - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\jyboy.yy@gmail.com [2014-01-03]
FF Extension: ColorZilla - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2014-01-03]
FF Extension: Firebug - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\firebug@software.joehewitt.com.xpi [2014-01-03]
FF Extension: Simple Timer - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\simpletimer@grbradt.org.xpi [2014-01-03]
FF Extension: Google Translator for Firefox - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\translator@zoli.bod.xpi [2014-05-11]
FF Extension: View in Office Online Viewer - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\viewinofficeapps@huhsiaotao.xpi [2014-01-03]
FF Extension: No Name - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi [2014-01-03]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-11-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
Chrome:
=======
CHR HomePage: Default -> hxxp://www.papeweb.cz/
CHR StartupUrls: Default -> "hxxp://www.papeweb.cz/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-07]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-11-22]
CHR Extension: (Avast Online Security) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-05-16]
CHR Extension: (Color Picker Tools) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijgamcmigplkkdkhfcjmpjojlklnkgop [2014-01-21]
CHR Extension: (Color Picker) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcmgligingjhdnhdhgepemlckgcgmgaj [2014-08-18]
CHR Extension: (Google Wallet) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-11-22]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-07]
CHR HKLM\...\Chrome\Extension: [ocphobfcfafpclibolpjdafgaffkaoci] - C:\Users\Rodiče\AppData\Local\GamePlayLabs Plugin\gplplugin.crx [2011-03-15]
CHR HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\RODIE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-03]
StartMenuInternet: Google Chrome - C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-07] (Avast Software s.r.o.)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-04-07] (Avast Software)
R2 CSHelper; C:\Program Files\Common Files\ArtistScope\CSHelper32.exe [236536 2012-09-26] (ArtistScope Pty Ltd)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-07-23] ()
S2 gupdate1ca24ec3816786f; C:\Program Files\Google\Update\GoogleUpdate.exe [107912 2014-10-30] (Google Inc.)
R2 HP DS Service; C:\Program Files\HP\HPBDSService\HPBDSService.exe [13824 2010-10-27] (Hewlett-Packard Company) [File not signed]
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-27] (HP) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-14] (Microsoft Corporation)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-06-16] (Hewlett-Packard Company) [File not signed]
R2 LvHidSvc; C:\Windows\system32\lvhidsvc.exe [32256 2003-10-31] (Animation Technologies Inc.) [File not signed]
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-07-23] ()
S2 PCLEPCI; C:\Windows\system32\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-04-07] ()
R1 aswKbd; C:\Windows\system32\Drivers\aswKbd.sys [20624 2012-10-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [73440 2015-04-07] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-04-07] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-04-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [788272 2015-04-07] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427736 2015-04-07] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-04-07] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208024 2015-04-07] ()
S3 AVHybrid; C:\Windows\System32\DRIVERS\AVHybrid.sys [999680 2005-04-29] ()
R1 CSDriver; C:\Program Files\Common Files\ArtistScope\CSDriver32.sys [38328 2012-09-26] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-09-23] (LogMeIn, Inc.)
S3 HPFXBULKLEDM; C:\Windows\System32\drivers\hppcbulkio.sys [20504 2011-10-10] (Hewlett Packard)
R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2007-01-04] (Pinnacle Systems GmbH)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [56572 2008-11-02] (PowerISO Computing, Inc.) [File not signed]
S3 tap0801; C:\Windows\System32\DRIVERS\tap0801.sys [26624 2006-10-01] (The OpenVPN Project) [File not signed]
R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2008-03-23] (Acronis)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-04-07] (Avast Software)
S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2014-06-03] (RealVNC Ltd.)
S3 xxxHpSAMD; C:\Windows\system32\drivers\HpSAMD.sys [67152 2009-07-14] (Hewlett-Packard Company)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\RODIE~1\AppData\Local\Temp\catchme.sys [X]
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 14:26 - 2015-04-21 14:29 - 00024438 _____ () C:\Users\Rodiče\Desktop\FRST.txt
2015-04-21 14:25 - 2015-04-21 14:25 - 01139200 _____ (Farbar) C:\Users\Rodiče\Desktop\FRST.exe
2015-04-20 21:31 - 2015-04-20 21:31 - 00025386 _____ () C:\ComboFix.txt
2015-04-20 15:38 - 2015-04-20 21:32 - 00000000 ____D () C:\ComboFix
2015-04-20 01:48 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-20 01:48 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-20 01:48 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-20 01:46 - 2015-04-20 21:32 - 00000000 ____D () C:\Qoobox
2015-04-20 01:44 - 2015-04-20 14:37 - 00000000 ____D () C:\Windows\erdnt
2015-04-20 01:42 - 2015-04-20 15:20 - 05619466 ____R (Swearware) C:\ComboFix.exe
2015-04-20 01:32 - 2015-04-20 11:00 - 00000924 _____ () C:\Windows\Tasks\Google Software Updater.job
2015-04-20 01:29 - 2015-04-20 21:06 - 00001446 _____ () C:\Windows\PFRO.log
2015-04-19 23:17 - 2015-04-19 23:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-19 23:16 - 2015-04-20 01:29 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-04-19 23:16 - 2015-04-19 23:16 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-19 23:15 - 2015-04-19 23:15 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-19 22:37 - 2015-04-21 14:27 - 00000000 ____D () C:\FRST
2015-04-19 09:21 - 2015-04-21 13:23 - 00229284 _____ () C:\Windows\setupact.log
2015-04-19 09:21 - 2015-04-19 09:21 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-15 14:02 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 14:02 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 14:02 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 14:02 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 14:01 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 14:01 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 14:01 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 14:01 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 14:01 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 14:01 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 14:01 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 14:01 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 14:01 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 14:01 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 14:01 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 14:01 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 14:01 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 14:01 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 14:01 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 14:01 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 14:01 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 14:01 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 14:01 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 14:01 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 14:01 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 14:01 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 14:01 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 14:01 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 14:01 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 14:01 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 14:01 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 14:01 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 14:01 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 14:01 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 14:01 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 14:01 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 14:01 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 14:01 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 14:01 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 14:01 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 14:01 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 14:01 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 14:01 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 14:01 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 14:01 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 14:01 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 14:01 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 14:00 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 14:00 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 13:59 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 13:59 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-15 13:59 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-10 21:34 - 2015-04-10 21:34 - 00000000 ____D () C:\Users\Rodiče\Documents\Vlastní šablony Office
2015-04-07 13:32 - 2015-04-07 13:31 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-04-07 13:31 - 2015-04-07 13:31 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-04-06 10:41 - 2015-04-06 10:41 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-06 07:02 - 2015-04-16 21:50 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-06 06:56 - 2015-04-06 06:59 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
2015-04-06 06:48 - 2015-04-06 06:48 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2015-04-05 21:01 - 2015-04-05 21:01 - 00001917 _____ () C:\Users\Public\Desktop\FileZilla Client.lnk
2015-04-05 21:00 - 2015-04-05 21:00 - 06196576 _____ (Tim Kosse) C:\Users\Rodiče\Downloads\FileZilla_3.10.3_win32-setup.exe
2015-04-04 22:44 - 2015-04-04 22:45 - 00000000 ___SD () C:\Windows\system32\GWX
2015-03-23 19:18 - 2015-03-23 19:18 - 00000000 ____D () C:\Users\Rodiče\Tracing
2015-03-22 09:50 - 2015-03-22 09:50 - 01079296 _____ (Uniblue Systems Limited ) C:\Users\Rodiče\Downloads\pcmechanicpm.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 14:25 - 2008-02-25 22:38 - 00000000 ____D () C:\Users\Rodiče\AppData\Roaming\Skype
2015-04-21 13:57 - 2012-04-03 08:33 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-21 13:45 - 2008-11-08 21:50 - 00000000 ____D () C:\Program Files\Opera
2015-04-21 13:33 - 2012-09-28 13:48 - 00018544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-21 13:33 - 2012-09-28 13:48 - 00018544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-21 13:29 - 2012-10-17 01:09 - 01616352 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 13:25 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\inetsrv
2015-04-21 13:23 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-20 22:51 - 2015-03-10 18:34 - 00007631 _____ () C:\Users\Rodiče\AppData\Local\Resmon.ResmonCfg
2015-04-20 21:12 - 2006-11-02 12:23 - 00000246 _____ () C:\Windows\system.ini
2015-04-20 14:48 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-20 01:30 - 2012-10-17 02:41 - 00000008 __RSH () C:\Users\Rodiče\ntuser.pol
2015-04-20 01:30 - 2012-10-16 23:46 - 00000000 ____D () C:\Users\Rodiče
2015-04-20 01:30 - 2012-09-28 15:29 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-04-20 01:20 - 2006-11-02 13:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-04-19 22:30 - 2008-03-15 23:42 - 00000000 ____D () C:\bakalari
2015-04-19 22:27 - 2008-03-15 23:59 - 00000000 ____D () C:\TEMP
2015-04-19 08:46 - 2012-10-17 02:41 - 00175208 _____ () C:\Users\Rodiče\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-18 21:55 - 2012-09-12 11:40 - 00000000 ___RD () C:\Users\Rodiče\Desktop\__ K TISKU __
2015-04-18 20:26 - 2011-04-18 13:43 - 00000000 ____D () C:\Users\Rodiče\Desktop\MÁMA
2015-04-18 20:01 - 2013-04-15 16:36 - 00000000 ___RD () C:\Users\Rodiče\Desktop\___pošta___
2015-04-18 10:01 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-17 16:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-17 13:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-04-16 21:49 - 2008-02-24 22:57 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-16 14:19 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-16 13:11 - 2014-12-11 09:26 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-16 13:11 - 2014-05-06 23:38 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-15 23:16 - 2006-11-02 12:23 - 00000382 _____ () C:\Windows\win.ini
2015-04-15 23:13 - 2013-08-16 22:29 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 22:52 - 2012-10-26 07:43 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 22:49 - 2010-11-20 23:01 - 01688714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-15 19:57 - 2012-04-03 08:33 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 19:57 - 2011-06-13 18:03 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-13 22:04 - 2013-07-10 20:49 - 00000000 ____D () C:\Users\Rodiče\AppData\Roaming\FileZilla
2015-04-13 19:12 - 2010-11-17 22:53 - 00000000 ____D () C:\Users\Rodiče\Desktop\ONDRA
2015-04-08 12:45 - 2012-04-25 22:29 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-07 13:32 - 2014-06-23 06:41 - 00024144 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-04-07 13:32 - 2014-01-02 19:36 - 00106912 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-04-07 13:32 - 2013-03-14 07:27 - 00208024 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-04-07 13:32 - 2013-03-14 07:27 - 00049904 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-04-07 13:32 - 2012-11-04 21:41 - 00081728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-04-07 13:32 - 2008-04-01 16:46 - 00427736 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-04-07 13:32 - 2008-02-24 23:37 - 00073440 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-04-07 13:30 - 2011-11-20 09:47 - 00788272 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-04-06 07:15 - 2009-07-14 06:33 - 00638088 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-06 07:10 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-04-06 07:08 - 2011-04-12 03:46 - 00000000 ____D () C:\Windows\ShellNew
2015-04-06 07:07 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-06 07:00 - 2008-02-24 22:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-04-06 06:59 - 2008-02-24 22:59 - 00000000 ____D () C:\Program Files\Microsoft.NET
2015-04-06 06:56 - 2008-02-24 22:57 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-04-05 21:01 - 2013-07-10 20:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-04-05 21:01 - 2013-07-10 20:49 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2015-04-04 21:34 - 2009-05-03 18:59 - 00647680 ___SH () C:\Users\Rodiče\Desktop\Thumbs.db
2015-03-31 15:47 - 2014-08-21 19:31 - 00000000 ____D () C:\Users\Rodiče\AppData\Local\Adobe
2015-03-29 22:35 - 2010-09-20 20:12 - 00000000 ____D () C:\Users\Rodiče\Desktop\LENKA
2015-03-23 19:18 - 2014-09-29 07:28 - 00000000 ___RD () C:\Program Files\Skype
2015-03-23 19:18 - 2008-02-25 22:37 - 00000000 ____D () C:\ProgramData\Skype
==================== Files in the root of some directories =======
2008-02-24 23:47 - 2006-03-20 16:37 - 5689344 _____ (Gabest) C:\Program Files\mplayerc.exe
2008-03-23 16:40 - 2008-03-23 16:42 - 0000140 _____ () C:\Users\Rodiče\AppData\Roaming\burnaware.ini
2012-04-17 22:15 - 2012-05-21 15:58 - 0000128 _____ () C:\Users\Rodiče\AppData\Roaming\Earthquakes Meter_Settings.ini
2008-11-25 21:18 - 2008-11-25 22:34 - 0087608 _____ () C:\Users\Rodiče\AppData\Roaming\inst.exe
2008-11-25 21:18 - 2008-11-25 22:34 - 0007887 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.cat
2008-11-25 21:18 - 2008-11-25 22:34 - 0001144 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.inf
2008-11-25 21:19 - 2008-11-25 22:34 - 0000033 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.log
2008-11-25 21:18 - 2008-11-25 22:34 - 0047360 _____ (VSO Software) C:\Users\Rodiče\AppData\Roaming\pcouffin.sys
2011-11-13 07:50 - 2011-11-13 07:50 - 0000600 _____ () C:\Users\Rodiče\AppData\Roaming\winscp.rnd
2012-10-27 22:13 - 2014-12-29 00:19 - 0010240 _____ () C:\Users\Rodiče\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-10-25 21:13 - 2012-10-25 21:13 - 0000000 _____ () C:\Users\Rodiče\AppData\Local\PRAKTIK.INI
2015-03-06 14:39 - 2015-03-06 14:39 - 0000218 _____ () C:\Users\Rodiče\AppData\Local\recently-used.xbel
2015-03-10 18:34 - 2015-04-20 22:51 - 0007631 _____ () C:\Users\Rodiče\AppData\Local\Resmon.ResmonCfg
2012-10-25 14:01 - 2012-10-25 14:02 - 0000413 _____ () C:\ProgramData\hpzinstall.log
2012-10-17 11:14 - 2012-11-22 17:19 - 0000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2012-10-25 21:13 - 2012-10-25 21:13 - 0000000 _____ () C:\ProgramData\PRAKTIK.INI
2013-10-19 22:29 - 2013-10-25 22:33 - 0000024 _____ () C:\ProgramData\__FileUploader.log
Files to move or delete:
====================
C:\Users\NFSU\jagex_runescape_preferences.dat
C:\Users\NFSU\jagex_runescape_preferences2.dat
C:\Users\NFSU\jagex__preferences3.dat
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-14 16:24
==================== End Of Log ============================
Posílám log FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by Rodiče (administrator) on CERNY on 21-04-2015 14:26:33
Running from C:\Users\Rodiče\Desktop
Loaded Profiles: Rodiče (Available profiles: Rodiče & Lenka & NFSU)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArtistScope Pty Ltd) C:\Program Files\Common Files\ArtistScope\CSHelper32.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(Hewlett-Packard Company) C:\Program Files\HP\HPBDSService\HPBDSService.exe
(HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Animation Technologies Inc.) C:\Windows\System32\lvhidsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Seznam.cz a.s.) C:\Program Files\Seznam\Postak\Postak.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\CompatTel\wicainventory.exe
(Google Inc.) C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SMail] => C:\Program Files\Seznam\Postak\Postak.exe [453936 2008-02-21] (Seznam.cz a.s.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-07] (Avast Software s.r.o.)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31346784 2015-02-26] (Skype Technologies S.A.)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\InprocServer32: [Default-pngfilt] <==== ATTENTION!
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-04-07] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.papeweb.cz/
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... DF&pc=AVBR
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {0EBFFFDA-ABB1-49B2-A89B-594D808AC84F} URL = http://download.seznam.cz/vyhledavani/o ... rceid=IE_5
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = http://www.crawler.com/search/dispatche ... tbid=60327
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://blekko.com/?source=c3348dd4&tbp= ... earchTerms}
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {41FF3879-BCB7-4B39-B274-FEE2EC2BB8F5} URL = http://www.google.cz/search?q={searchTe ... 1I7GPEA_cs
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = http://www.ask.com/web?o=15710&l=dis&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredimail.com/?search= ... m2_test_v2
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?p={searc ... r=chr-divx
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-07] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net ... plugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/ ... ontrol.cab
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} https://maxibps.postovnisporitelna.cz/C ... Enroll.dll
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.cz/OnlineScanner.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/In ... ct119b.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
FireFox:
========
FF ProfilePath: C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: hxxp://www.papeweb.cz
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2014-06-03] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @google.com/npPicasa2,version=2.0.0 -> C:\Program Files\Picasa2\npPicasa2.dll [2008-08-21] (Google, Inc.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Picasa2\npPicasa3.dll [2013-04-02] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 -> C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll [2011-10-03] (Google)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3533039139-1052968357-1368303399-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Rodiče\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin HKU\S-1-5-21-3533039139-1052968357-1368303399-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Rodiče\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-01-06] (Apple Inc.)
FF SearchPlugin: C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\searchplugins\google-avast.xml [2014-12-15]
FF Extension: No Name - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\artur.dubovoy@gmail.com [2015-04-10]
FF Extension: gTranslator - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\jyboy.yy@gmail.com [2014-01-03]
FF Extension: ColorZilla - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2014-01-03]
FF Extension: Firebug - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\firebug@software.joehewitt.com.xpi [2014-01-03]
FF Extension: Simple Timer - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\simpletimer@grbradt.org.xpi [2014-01-03]
FF Extension: Google Translator for Firefox - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\translator@zoli.bod.xpi [2014-05-11]
FF Extension: View in Office Online Viewer - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\viewinofficeapps@huhsiaotao.xpi [2014-01-03]
FF Extension: No Name - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi [2014-01-03]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-11-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
Chrome:
=======
CHR HomePage: Default -> hxxp://www.papeweb.cz/
CHR StartupUrls: Default -> "hxxp://www.papeweb.cz/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-07]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-11-22]
CHR Extension: (Avast Online Security) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-05-16]
CHR Extension: (Color Picker Tools) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijgamcmigplkkdkhfcjmpjojlklnkgop [2014-01-21]
CHR Extension: (Color Picker) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcmgligingjhdnhdhgepemlckgcgmgaj [2014-08-18]
CHR Extension: (Google Wallet) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-11-22]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-07]
CHR HKLM\...\Chrome\Extension: [ocphobfcfafpclibolpjdafgaffkaoci] - C:\Users\Rodiče\AppData\Local\GamePlayLabs Plugin\gplplugin.crx [2011-03-15]
CHR HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\RODIE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-03]
StartMenuInternet: Google Chrome - C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-07] (Avast Software s.r.o.)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-04-07] (Avast Software)
R2 CSHelper; C:\Program Files\Common Files\ArtistScope\CSHelper32.exe [236536 2012-09-26] (ArtistScope Pty Ltd)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-07-23] ()
S2 gupdate1ca24ec3816786f; C:\Program Files\Google\Update\GoogleUpdate.exe [107912 2014-10-30] (Google Inc.)
R2 HP DS Service; C:\Program Files\HP\HPBDSService\HPBDSService.exe [13824 2010-10-27] (Hewlett-Packard Company) [File not signed]
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-27] (HP) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-14] (Microsoft Corporation)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-06-16] (Hewlett-Packard Company) [File not signed]
R2 LvHidSvc; C:\Windows\system32\lvhidsvc.exe [32256 2003-10-31] (Animation Technologies Inc.) [File not signed]
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-07-23] ()
S2 PCLEPCI; C:\Windows\system32\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-04-07] ()
R1 aswKbd; C:\Windows\system32\Drivers\aswKbd.sys [20624 2012-10-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [73440 2015-04-07] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-04-07] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-04-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [788272 2015-04-07] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427736 2015-04-07] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-04-07] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208024 2015-04-07] ()
S3 AVHybrid; C:\Windows\System32\DRIVERS\AVHybrid.sys [999680 2005-04-29] ()
R1 CSDriver; C:\Program Files\Common Files\ArtistScope\CSDriver32.sys [38328 2012-09-26] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-09-23] (LogMeIn, Inc.)
S3 HPFXBULKLEDM; C:\Windows\System32\drivers\hppcbulkio.sys [20504 2011-10-10] (Hewlett Packard)
R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2007-01-04] (Pinnacle Systems GmbH)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [56572 2008-11-02] (PowerISO Computing, Inc.) [File not signed]
S3 tap0801; C:\Windows\System32\DRIVERS\tap0801.sys [26624 2006-10-01] (The OpenVPN Project) [File not signed]
R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2008-03-23] (Acronis)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-04-07] (Avast Software)
S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2014-06-03] (RealVNC Ltd.)
S3 xxxHpSAMD; C:\Windows\system32\drivers\HpSAMD.sys [67152 2009-07-14] (Hewlett-Packard Company)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\RODIE~1\AppData\Local\Temp\catchme.sys [X]
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 14:26 - 2015-04-21 14:29 - 00024438 _____ () C:\Users\Rodiče\Desktop\FRST.txt
2015-04-21 14:25 - 2015-04-21 14:25 - 01139200 _____ (Farbar) C:\Users\Rodiče\Desktop\FRST.exe
2015-04-20 21:31 - 2015-04-20 21:31 - 00025386 _____ () C:\ComboFix.txt
2015-04-20 15:38 - 2015-04-20 21:32 - 00000000 ____D () C:\ComboFix
2015-04-20 01:48 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-20 01:48 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-20 01:48 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-20 01:46 - 2015-04-20 21:32 - 00000000 ____D () C:\Qoobox
2015-04-20 01:44 - 2015-04-20 14:37 - 00000000 ____D () C:\Windows\erdnt
2015-04-20 01:42 - 2015-04-20 15:20 - 05619466 ____R (Swearware) C:\ComboFix.exe
2015-04-20 01:32 - 2015-04-20 11:00 - 00000924 _____ () C:\Windows\Tasks\Google Software Updater.job
2015-04-20 01:29 - 2015-04-20 21:06 - 00001446 _____ () C:\Windows\PFRO.log
2015-04-19 23:17 - 2015-04-19 23:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-19 23:16 - 2015-04-20 01:29 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-04-19 23:16 - 2015-04-19 23:16 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-19 23:15 - 2015-04-19 23:15 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-19 22:37 - 2015-04-21 14:27 - 00000000 ____D () C:\FRST
2015-04-19 09:21 - 2015-04-21 13:23 - 00229284 _____ () C:\Windows\setupact.log
2015-04-19 09:21 - 2015-04-19 09:21 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-15 14:02 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 14:02 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 14:02 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 14:02 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 14:01 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 14:01 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 14:01 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 14:01 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 14:01 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 14:01 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 14:01 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 14:01 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 14:01 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 14:01 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 14:01 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 14:01 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 14:01 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 14:01 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 14:01 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 14:01 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 14:01 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 14:01 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 14:01 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 14:01 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 14:01 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 14:01 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 14:01 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 14:01 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 14:01 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 14:01 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 14:01 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 14:01 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 14:01 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 14:01 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 14:01 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 14:01 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 14:01 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 14:01 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 14:01 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 14:01 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 14:01 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 14:01 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 14:01 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 14:01 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 14:01 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 14:01 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 14:01 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 14:00 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 14:00 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 13:59 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 13:59 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-15 13:59 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-10 21:34 - 2015-04-10 21:34 - 00000000 ____D () C:\Users\Rodiče\Documents\Vlastní šablony Office
2015-04-07 13:32 - 2015-04-07 13:31 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-04-07 13:31 - 2015-04-07 13:31 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-04-06 10:41 - 2015-04-06 10:41 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-06 07:02 - 2015-04-16 21:50 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-06 06:56 - 2015-04-06 06:59 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
2015-04-06 06:48 - 2015-04-06 06:48 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2015-04-05 21:01 - 2015-04-05 21:01 - 00001917 _____ () C:\Users\Public\Desktop\FileZilla Client.lnk
2015-04-05 21:00 - 2015-04-05 21:00 - 06196576 _____ (Tim Kosse) C:\Users\Rodiče\Downloads\FileZilla_3.10.3_win32-setup.exe
2015-04-04 22:44 - 2015-04-04 22:45 - 00000000 ___SD () C:\Windows\system32\GWX
2015-03-23 19:18 - 2015-03-23 19:18 - 00000000 ____D () C:\Users\Rodiče\Tracing
2015-03-22 09:50 - 2015-03-22 09:50 - 01079296 _____ (Uniblue Systems Limited ) C:\Users\Rodiče\Downloads\pcmechanicpm.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 14:25 - 2008-02-25 22:38 - 00000000 ____D () C:\Users\Rodiče\AppData\Roaming\Skype
2015-04-21 13:57 - 2012-04-03 08:33 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-21 13:45 - 2008-11-08 21:50 - 00000000 ____D () C:\Program Files\Opera
2015-04-21 13:33 - 2012-09-28 13:48 - 00018544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-21 13:33 - 2012-09-28 13:48 - 00018544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-21 13:29 - 2012-10-17 01:09 - 01616352 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 13:25 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\inetsrv
2015-04-21 13:23 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-20 22:51 - 2015-03-10 18:34 - 00007631 _____ () C:\Users\Rodiče\AppData\Local\Resmon.ResmonCfg
2015-04-20 21:12 - 2006-11-02 12:23 - 00000246 _____ () C:\Windows\system.ini
2015-04-20 14:48 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-20 01:30 - 2012-10-17 02:41 - 00000008 __RSH () C:\Users\Rodiče\ntuser.pol
2015-04-20 01:30 - 2012-10-16 23:46 - 00000000 ____D () C:\Users\Rodiče
2015-04-20 01:30 - 2012-09-28 15:29 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-04-20 01:20 - 2006-11-02 13:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-04-19 22:30 - 2008-03-15 23:42 - 00000000 ____D () C:\bakalari
2015-04-19 22:27 - 2008-03-15 23:59 - 00000000 ____D () C:\TEMP
2015-04-19 08:46 - 2012-10-17 02:41 - 00175208 _____ () C:\Users\Rodiče\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-18 21:55 - 2012-09-12 11:40 - 00000000 ___RD () C:\Users\Rodiče\Desktop\__ K TISKU __
2015-04-18 20:26 - 2011-04-18 13:43 - 00000000 ____D () C:\Users\Rodiče\Desktop\MÁMA
2015-04-18 20:01 - 2013-04-15 16:36 - 00000000 ___RD () C:\Users\Rodiče\Desktop\___pošta___
2015-04-18 10:01 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-17 16:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-17 13:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-04-16 21:49 - 2008-02-24 22:57 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-16 14:19 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-16 13:11 - 2014-12-11 09:26 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-16 13:11 - 2014-05-06 23:38 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-15 23:16 - 2006-11-02 12:23 - 00000382 _____ () C:\Windows\win.ini
2015-04-15 23:13 - 2013-08-16 22:29 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 22:52 - 2012-10-26 07:43 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 22:49 - 2010-11-20 23:01 - 01688714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-15 19:57 - 2012-04-03 08:33 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 19:57 - 2011-06-13 18:03 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-13 22:04 - 2013-07-10 20:49 - 00000000 ____D () C:\Users\Rodiče\AppData\Roaming\FileZilla
2015-04-13 19:12 - 2010-11-17 22:53 - 00000000 ____D () C:\Users\Rodiče\Desktop\ONDRA
2015-04-08 12:45 - 2012-04-25 22:29 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-07 13:32 - 2014-06-23 06:41 - 00024144 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-04-07 13:32 - 2014-01-02 19:36 - 00106912 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-04-07 13:32 - 2013-03-14 07:27 - 00208024 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-04-07 13:32 - 2013-03-14 07:27 - 00049904 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-04-07 13:32 - 2012-11-04 21:41 - 00081728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-04-07 13:32 - 2008-04-01 16:46 - 00427736 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-04-07 13:32 - 2008-02-24 23:37 - 00073440 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-04-07 13:30 - 2011-11-20 09:47 - 00788272 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-04-06 07:15 - 2009-07-14 06:33 - 00638088 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-06 07:10 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-04-06 07:08 - 2011-04-12 03:46 - 00000000 ____D () C:\Windows\ShellNew
2015-04-06 07:07 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-06 07:00 - 2008-02-24 22:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-04-06 06:59 - 2008-02-24 22:59 - 00000000 ____D () C:\Program Files\Microsoft.NET
2015-04-06 06:56 - 2008-02-24 22:57 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-04-05 21:01 - 2013-07-10 20:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-04-05 21:01 - 2013-07-10 20:49 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2015-04-04 21:34 - 2009-05-03 18:59 - 00647680 ___SH () C:\Users\Rodiče\Desktop\Thumbs.db
2015-03-31 15:47 - 2014-08-21 19:31 - 00000000 ____D () C:\Users\Rodiče\AppData\Local\Adobe
2015-03-29 22:35 - 2010-09-20 20:12 - 00000000 ____D () C:\Users\Rodiče\Desktop\LENKA
2015-03-23 19:18 - 2014-09-29 07:28 - 00000000 ___RD () C:\Program Files\Skype
2015-03-23 19:18 - 2008-02-25 22:37 - 00000000 ____D () C:\ProgramData\Skype
==================== Files in the root of some directories =======
2008-02-24 23:47 - 2006-03-20 16:37 - 5689344 _____ (Gabest) C:\Program Files\mplayerc.exe
2008-03-23 16:40 - 2008-03-23 16:42 - 0000140 _____ () C:\Users\Rodiče\AppData\Roaming\burnaware.ini
2012-04-17 22:15 - 2012-05-21 15:58 - 0000128 _____ () C:\Users\Rodiče\AppData\Roaming\Earthquakes Meter_Settings.ini
2008-11-25 21:18 - 2008-11-25 22:34 - 0087608 _____ () C:\Users\Rodiče\AppData\Roaming\inst.exe
2008-11-25 21:18 - 2008-11-25 22:34 - 0007887 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.cat
2008-11-25 21:18 - 2008-11-25 22:34 - 0001144 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.inf
2008-11-25 21:19 - 2008-11-25 22:34 - 0000033 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.log
2008-11-25 21:18 - 2008-11-25 22:34 - 0047360 _____ (VSO Software) C:\Users\Rodiče\AppData\Roaming\pcouffin.sys
2011-11-13 07:50 - 2011-11-13 07:50 - 0000600 _____ () C:\Users\Rodiče\AppData\Roaming\winscp.rnd
2012-10-27 22:13 - 2014-12-29 00:19 - 0010240 _____ () C:\Users\Rodiče\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-10-25 21:13 - 2012-10-25 21:13 - 0000000 _____ () C:\Users\Rodiče\AppData\Local\PRAKTIK.INI
2015-03-06 14:39 - 2015-03-06 14:39 - 0000218 _____ () C:\Users\Rodiče\AppData\Local\recently-used.xbel
2015-03-10 18:34 - 2015-04-20 22:51 - 0007631 _____ () C:\Users\Rodiče\AppData\Local\Resmon.ResmonCfg
2012-10-25 14:01 - 2012-10-25 14:02 - 0000413 _____ () C:\ProgramData\hpzinstall.log
2012-10-17 11:14 - 2012-11-22 17:19 - 0000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2012-10-25 21:13 - 2012-10-25 21:13 - 0000000 _____ () C:\ProgramData\PRAKTIK.INI
2013-10-19 22:29 - 2013-10-25 22:33 - 0000024 _____ () C:\ProgramData\__FileUploader.log
Files to move or delete:
====================
C:\Users\NFSU\jagex_runescape_preferences.dat
C:\Users\NFSU\jagex_runescape_preferences2.dat
C:\Users\NFSU\jagex__preferences3.dat
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-14 16:24
==================== End Of Log ============================
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Připojuji log Addition:
- Přílohy
-
- Addition.zip
- (18.5 KiB) Staženo 63 x
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu bude na plose ulozen fixlog, jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: CreateRestorePoint: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\InprocServer32: [Default-pngfilt] <==== ATTENTION! HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = http://www.crawler.com/search/dispatche ... tp=bs&qkw={searchTerms}&tbid=60327 SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://blekko.com/?source=c3348dd4&tbp=rbox&q={searchTerms} SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = http://www.ask.com/web?o=15710&l=dis&q={searchTerms} SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredimail.com/?search={searchTerms}&loc=search_box_im2_test_v2 SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?p={searchTerms}&fr=chr-divx BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006 FF Keyword.URL: https://www.google.com/search/?trackid=sp-006 Task: {4AC4E5D5-EEAA-40E0-AC3D-02FEDB358A50} - System32\Tasks\{2EA0833A-7CFA-4608-B7BA-99B743430703} => pcalua.exe -a C:\Users\Rodiče\Downloads\ColorArchiver2.2.0_Setup.exe -d C:\Users\Rodiče\Downloads Task: {7B845966-FEF0-43AA-9DF2-F7AD498BC795} - System32\Tasks\{DDD94263-A9A5-45C4-B75F-E3A2D1EA714B} => pcalua.exe -a D:\Setup.exe -d D:\ Task: {DC549EFA-A767-4FC0-AE06-0FD381F7EF4A} - System32\Tasks\{8DB6D166-81E9-401C-9230-9FE6FF49404F} => pcalua.exe -a F:\Setup.exe -d F:\ Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
link:
https://www.virustotal.com/cs/file/4299 ... 429627337/
fixlog:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 20-04-2015
Ran by Rodiče at 2015-04-21 16:46:48 Run:2
Running from C:\Users\Rodiče\Desktop
Loaded Profiles: Rodiče (Available profiles: Rodiče & Lenka & NFSU)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\InprocServer32: [Default-pngfilt] <==== ATTENTION!
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = http://www.crawler.com/search/dispatche ... tp=bs&qkw={searchTerms}&tbid=60327
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://blekko.com/?source=c3348dd4&tbp= ... earchTerms}
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = http://www.ask.com/web?o=15710&l=dis&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredimail.com/?search= ... m2_test_v2
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?p={searc ... r=chr-divx
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
Task: {4AC4E5D5-EEAA-40E0-AC3D-02FEDB358A50} - System32\Tasks\{2EA0833A-7CFA-4608-B7BA-99B743430703} => pcalua.exe -a C:\Users\Rodiče\Downloads\ColorArchiver2.2.0_Setup.exe -d C:\Users\Rodiče\Downloads
Task: {7B845966-FEF0-43AA-9DF2-F7AD498BC795} - System32\Tasks\{DDD94263-A9A5-45C4-B75F-E3A2D1EA714B} => pcalua.exe -a D:\Setup.exe -d D:\
Task: {DC549EFA-A767-4FC0-AE06-0FD381F7EF4A} - System32\Tasks\{8DB6D166-81E9-401C-9230-9FE6FF49404F} => pcalua.exe -a F:\Setup.exe -d F:\
Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
End
*****************
Processes closed successfully.
Restore point was successfully created.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Classes\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}" => Key deleted successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" => Key deleted successfully.
HKCR\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} => Key not found.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}" => Key deleted successfully.
HKCR\CLSID\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => Key not found.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}" => Key deleted successfully.
HKCR\CLSID\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27} => Key not found.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}" => Key deleted successfully.
HKCR\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key not found.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}" => Key deleted successfully.
HKCR\CLSID\{DECA3892-BA8F-44b8-A993-A466AD694AE4} => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}" => Key deleted successfully.
HKCR\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key not found.
Firefox DefaultSearchUrl deleted successfully.
Firefox Keyword.URL deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4AC4E5D5-EEAA-40E0-AC3D-02FEDB358A50}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AC4E5D5-EEAA-40E0-AC3D-02FEDB358A50}" => Key deleted successfully.
C:\Windows\System32\Tasks\{2EA0833A-7CFA-4608-B7BA-99B743430703} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2EA0833A-7CFA-4608-B7BA-99B743430703}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7B845966-FEF0-43AA-9DF2-F7AD498BC795}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B845966-FEF0-43AA-9DF2-F7AD498BC795}" => Key deleted successfully.
C:\Windows\System32\Tasks\{DDD94263-A9A5-45C4-B75F-E3A2D1EA714B} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DDD94263-A9A5-45C4-B75F-E3A2D1EA714B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DC549EFA-A767-4FC0-AE06-0FD381F7EF4A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DC549EFA-A767-4FC0-AE06-0FD381F7EF4A}" => Key deleted successfully.
C:\Windows\System32\Tasks\{8DB6D166-81E9-401C-9230-9FE6FF49404F} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8DB6D166-81E9-401C-9230-9FE6FF49404F}" => Key deleted successfully.
C:\Windows\Tasks\Google Software Updater.job => Moved successfully.
The system needed a reboot.
==== End of Fixlog 16:47:46 ====
Proces je opět spuštěný.
https://www.virustotal.com/cs/file/4299 ... 429627337/
fixlog:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 20-04-2015
Ran by Rodiče at 2015-04-21 16:46:48 Run:2
Running from C:\Users\Rodiče\Desktop
Loaded Profiles: Rodiče (Available profiles: Rodiče & Lenka & NFSU)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\InprocServer32: [Default-pngfilt] <==== ATTENTION!
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} URL = http://www.crawler.com/search/dispatche ... tp=bs&qkw={searchTerms}&tbid=60327
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = http://blekko.com/?source=c3348dd4&tbp= ... earchTerms}
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {B7B664DF-3AF9-4C8E-8148-F42BB7831D27} URL = http://www.ask.com/web?o=15710&l=dis&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = http://mystart.incredimail.com/?search= ... m2_test_v2
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?p={searc ... r=chr-divx
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
Task: {4AC4E5D5-EEAA-40E0-AC3D-02FEDB358A50} - System32\Tasks\{2EA0833A-7CFA-4608-B7BA-99B743430703} => pcalua.exe -a C:\Users\Rodiče\Downloads\ColorArchiver2.2.0_Setup.exe -d C:\Users\Rodiče\Downloads
Task: {7B845966-FEF0-43AA-9DF2-F7AD498BC795} - System32\Tasks\{DDD94263-A9A5-45C4-B75F-E3A2D1EA714B} => pcalua.exe -a D:\Setup.exe -d D:\
Task: {DC549EFA-A767-4FC0-AE06-0FD381F7EF4A} - System32\Tasks\{8DB6D166-81E9-401C-9230-9FE6FF49404F} => pcalua.exe -a F:\Setup.exe -d F:\
Task: C:\Windows\Tasks\Google Software Updater.job => C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
End
*****************
Processes closed successfully.
Restore point was successfully created.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Classes\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}" => Key deleted successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" => Key deleted successfully.
HKCR\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} => Key not found.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}" => Key deleted successfully.
HKCR\CLSID\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} => Key not found.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27}" => Key deleted successfully.
HKCR\CLSID\{B7B664DF-3AF9-4C8E-8148-F42BB7831D27} => Key not found.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}" => Key deleted successfully.
HKCR\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A} => Key not found.
"HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}" => Key deleted successfully.
HKCR\CLSID\{DECA3892-BA8F-44b8-A993-A466AD694AE4} => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}" => Key deleted successfully.
HKCR\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => Key not found.
Firefox DefaultSearchUrl deleted successfully.
Firefox Keyword.URL deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4AC4E5D5-EEAA-40E0-AC3D-02FEDB358A50}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AC4E5D5-EEAA-40E0-AC3D-02FEDB358A50}" => Key deleted successfully.
C:\Windows\System32\Tasks\{2EA0833A-7CFA-4608-B7BA-99B743430703} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2EA0833A-7CFA-4608-B7BA-99B743430703}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7B845966-FEF0-43AA-9DF2-F7AD498BC795}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B845966-FEF0-43AA-9DF2-F7AD498BC795}" => Key deleted successfully.
C:\Windows\System32\Tasks\{DDD94263-A9A5-45C4-B75F-E3A2D1EA714B} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DDD94263-A9A5-45C4-B75F-E3A2D1EA714B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DC549EFA-A767-4FC0-AE06-0FD381F7EF4A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DC549EFA-A767-4FC0-AE06-0FD381F7EF4A}" => Key deleted successfully.
C:\Windows\System32\Tasks\{8DB6D166-81E9-401C-9230-9FE6FF49404F} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8DB6D166-81E9-401C-9230-9FE6FF49404F}" => Key deleted successfully.
C:\Windows\Tasks\Google Software Updater.job => Moved successfully.
The system needed a reboot.
==== End of Fixlog 16:47:46 ====
Proces je opět spuštěný.
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Po stazeni http://www.xuetr.com/download/PCHunter_free.zip
(rezervni odkaz http://www.epoolsoft.com/pchunter/PCHunter_free.zip ),
rozbaleni, spusteni spravne verze dle operacniho systemu 32b vs 64b, prejdi do zalozky Examination, v ni zaskrkej vsechny volby, dej generovat, po skonceni generovani klik na exportovat - textak do raru a vloz do prispevku (neb bude dlouhy a nevesel by se).
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
posílám log
- Přílohy
-
- 21042015_1744.zip
- (146.65 KiB) Staženo 63 x
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Resenim se nabizi jednoduse zakazat sluzbu, aby se spoustela pri spusteni PC. Pokud se Vam chce, otestujte na virustotal jeste nasledujici knihovny, ktere jsou navazane na dany proces:
Dejte pak jeste novy log z FRST.
- C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\system32\kernel32.dll
C:\Windows\system32\KERNELBASE.dll
C:\Windows\system32\ADVAPI32.dll
C:\Windows\system32\msvcrt.dll
C:\Windows\SYSTEM32\sechost.dll
C:\Windows\system32\RPCRT4.dll
C:\Windows\system32\USER32.dll
C:\Windows\system32\GDI32.dll
C:\Windows\system32\LPK.dll
C:\Windows\system32\USP10.dll
C:\Windows\system32\HID.DLL
C:\Windows\system32\SETUPAPI.dll
C:\Windows\system32\CFGMGR32.dll
C:\Windows\system32\OLEAUT32.dll
C:\Windows\system32\ole32.dll
C:\Windows\system32\DEVOBJ.dll
C:\Windows\system32\IMM32.DLL
C:\Windows\system32\MSCTF.dll
C:\Windows\system32\WINTRUST.dll
C:\Windows\system32\CRYPT32.dll
C:\Windows\system32\MSASN1.dll
Dejte pak jeste novy log z FRST.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Proces lvhidsvc.exe vytěžuje procesor, prosím o pomoc o
Knihovny jsem prošel, byly čisté.
Log RFST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by Rodiče (administrator) on CERNY on 21-04-2015 21:54:15
Running from C:\Users\Rodiče\Desktop
Loaded Profiles: Rodiče (Available profiles: Rodiče & Lenka & NFSU)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArtistScope Pty Ltd) C:\Program Files\Common Files\ArtistScope\CSHelper32.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(Hewlett-Packard Company) C:\Program Files\HP\HPBDSService\HPBDSService.exe
(HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Animation Technologies Inc.) C:\Windows\System32\lvhidsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Seznam.cz a.s.) C:\Program Files\Seznam\Postak\Postak.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Skype Technologies S.A.) C:\Windows\Temp\SKY3B89.tmp
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Opera Software) C:\Program Files\Opera\launcher.exe
() C:\Program Files\Opera\28.0.1750.51\opera_autoupdate.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SMail] => C:\Program Files\Seznam\Postak\Postak.exe [453936 2008-02-21] (Seznam.cz a.s.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-07] (Avast Software s.r.o.)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31346784 2015-02-26] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-04-07] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.papeweb.cz/
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... DF&pc=AVBR
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {0EBFFFDA-ABB1-49B2-A89B-594D808AC84F} URL = http://download.seznam.cz/vyhledavani/o ... rceid=IE_5
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {41FF3879-BCB7-4B39-B274-FEE2EC2BB8F5} URL = http://www.google.cz/search?q={searchTe ... 1I7GPEA_cs
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-07] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net ... plugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/ ... ontrol.cab
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} https://maxibps.postovnisporitelna.cz/C ... Enroll.dll
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.cz/OnlineScanner.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/In ... ct119b.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
FireFox:
========
FF ProfilePath: C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606
FF DefaultSearchEngine: Google (avast)
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: hxxp://www.papeweb.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2014-06-03] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @google.com/npPicasa2,version=2.0.0 -> C:\Program Files\Picasa2\npPicasa2.dll [2008-08-21] (Google, Inc.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Picasa2\npPicasa3.dll [2013-04-02] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 -> C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll [2011-10-03] (Google)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3533039139-1052968357-1368303399-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Rodiče\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin HKU\S-1-5-21-3533039139-1052968357-1368303399-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Rodiče\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-01-06] (Apple Inc.)
FF SearchPlugin: C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\searchplugins\google-avast.xml [2014-12-15]
FF Extension: No Name - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\artur.dubovoy@gmail.com [2015-04-10]
FF Extension: gTranslator - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\jyboy.yy@gmail.com [2014-01-03]
FF Extension: ColorZilla - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2014-01-03]
FF Extension: Firebug - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\firebug@software.joehewitt.com.xpi [2014-01-03]
FF Extension: Simple Timer - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\simpletimer@grbradt.org.xpi [2014-01-03]
FF Extension: Google Translator for Firefox - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\translator@zoli.bod.xpi [2014-05-11]
FF Extension: View in Office Online Viewer - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\viewinofficeapps@huhsiaotao.xpi [2014-01-03]
FF Extension: No Name - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi [2014-01-03]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-11-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
Chrome:
=======
CHR HomePage: Default -> hxxp://www.papeweb.cz/
CHR StartupUrls: Default -> "hxxp://www.papeweb.cz/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-07]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-11-22]
CHR Extension: (Bookmark Manager) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-21]
CHR Extension: (Avast Online Security) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-05-16]
CHR Extension: (Color Picker Tools) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijgamcmigplkkdkhfcjmpjojlklnkgop [2014-01-21]
CHR Extension: (Color Picker) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcmgligingjhdnhdhgepemlckgcgmgaj [2014-08-18]
CHR Extension: (Google Wallet) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-11-22]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-07]
CHR HKLM\...\Chrome\Extension: [ocphobfcfafpclibolpjdafgaffkaoci] - C:\Users\Rodiče\AppData\Local\GamePlayLabs Plugin\gplplugin.crx [2011-03-15]
CHR HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\RODIE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-03]
StartMenuInternet: Google Chrome - C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-07] (Avast Software s.r.o.)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-04-07] (Avast Software)
R2 CSHelper; C:\Program Files\Common Files\ArtistScope\CSHelper32.exe [236536 2012-09-26] (ArtistScope Pty Ltd)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-07-23] ()
S2 gupdate1ca24ec3816786f; C:\Program Files\Google\Update\GoogleUpdate.exe [107912 2014-10-30] (Google Inc.)
R2 HP DS Service; C:\Program Files\HP\HPBDSService\HPBDSService.exe [13824 2010-10-27] (Hewlett-Packard Company) [File not signed]
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-27] (HP) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-14] (Microsoft Corporation)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-06-16] (Hewlett-Packard Company) [File not signed]
R2 LvHidSvc; C:\Windows\system32\lvhidsvc.exe [32256 2003-10-31] (Animation Technologies Inc.) [File not signed]
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-07-23] ()
S2 PCLEPCI; C:\Windows\system32\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-04-07] ()
R1 aswKbd; C:\Windows\system32\Drivers\aswKbd.sys [20624 2012-10-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [73440 2015-04-07] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-04-07] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-04-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [788272 2015-04-07] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427736 2015-04-07] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-04-07] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208024 2015-04-07] ()
S3 AVHybrid; C:\Windows\System32\DRIVERS\AVHybrid.sys [999680 2005-04-29] ()
R1 CSDriver; C:\Program Files\Common Files\ArtistScope\CSDriver32.sys [38328 2012-09-26] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-09-23] (LogMeIn, Inc.)
S3 HPFXBULKLEDM; C:\Windows\System32\drivers\hppcbulkio.sys [20504 2011-10-10] (Hewlett Packard)
R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2007-01-04] (Pinnacle Systems GmbH)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [56572 2008-11-02] (PowerISO Computing, Inc.) [File not signed]
S3 tap0801; C:\Windows\System32\DRIVERS\tap0801.sys [26624 2006-10-01] (The OpenVPN Project) [File not signed]
R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2008-03-23] (Acronis)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-04-07] (Avast Software)
S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2014-06-03] (RealVNC Ltd.)
S3 xxxHpSAMD; C:\Windows\system32\drivers\HpSAMD.sys [67152 2009-07-14] (Hewlett-Packard Company)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\RODIE~1\AppData\Local\Temp\catchme.sys [X]
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 17:15 - 2015-04-21 17:15 - 00000000 ____D () C:\Users\Rodiče\Desktop\PCHunter_free
2015-04-21 17:14 - 2015-04-21 17:15 - 06739485 _____ () C:\Users\Rodiče\Desktop\PCHunter_free.zip
2015-04-21 16:52 - 2015-04-21 21:47 - 00000924 _____ () C:\Windows\Tasks\Google Software Updater.job
2015-04-21 16:10 - 2015-04-21 16:10 - 00018948 _____ () C:\Users\Rodiče\Desktop\Addition.zip
2015-04-21 14:40 - 2015-04-21 14:46 - 00076826 _____ () C:\Users\Rodiče\Desktop\Addition.txt
2015-04-21 14:26 - 2015-04-21 21:57 - 00022967 _____ () C:\Users\Rodiče\Desktop\FRST.txt
2015-04-21 14:25 - 2015-04-21 14:25 - 01139200 _____ (Farbar) C:\Users\Rodiče\Desktop\FRST.exe
2015-04-20 21:31 - 2015-04-20 21:31 - 00025386 _____ () C:\ComboFix.txt
2015-04-20 15:38 - 2015-04-20 21:32 - 00000000 ____D () C:\ComboFix
2015-04-20 01:48 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-20 01:48 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-20 01:48 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-20 01:46 - 2015-04-20 21:32 - 00000000 ____D () C:\Qoobox
2015-04-20 01:44 - 2015-04-20 14:37 - 00000000 ____D () C:\Windows\erdnt
2015-04-20 01:42 - 2015-04-20 15:20 - 05619466 ____R (Swearware) C:\ComboFix.exe
2015-04-20 01:29 - 2015-04-20 21:06 - 00001446 _____ () C:\Windows\PFRO.log
2015-04-19 23:17 - 2015-04-19 23:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-19 23:16 - 2015-04-20 01:29 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-04-19 23:16 - 2015-04-19 23:16 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-19 23:15 - 2015-04-19 23:15 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-19 22:37 - 2015-04-21 21:54 - 00000000 ____D () C:\FRST
2015-04-19 09:21 - 2015-04-21 21:47 - 00280236 _____ () C:\Windows\setupact.log
2015-04-19 09:21 - 2015-04-19 09:21 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-15 14:02 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 14:02 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 14:02 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 14:02 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 14:01 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 14:01 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 14:01 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 14:01 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 14:01 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 14:01 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 14:01 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 14:01 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 14:01 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 14:01 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 14:01 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 14:01 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 14:01 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 14:01 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 14:01 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 14:01 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 14:01 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 14:01 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 14:01 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 14:01 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 14:01 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 14:01 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 14:01 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 14:01 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 14:01 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 14:01 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 14:01 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 14:01 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 14:01 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 14:01 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 14:01 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 14:01 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 14:01 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 14:01 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 14:01 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 14:01 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 14:01 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 14:01 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 14:01 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 14:01 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 14:01 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 14:01 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 14:01 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 14:00 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 14:00 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 13:59 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 13:59 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-15 13:59 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-10 21:34 - 2015-04-10 21:34 - 00000000 ____D () C:\Users\Rodiče\Documents\Vlastní šablony Office
2015-04-07 13:32 - 2015-04-07 13:31 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-04-07 13:31 - 2015-04-07 13:31 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-04-06 10:41 - 2015-04-06 10:41 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-06 07:02 - 2015-04-16 21:50 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-06 06:56 - 2015-04-06 06:59 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
2015-04-06 06:48 - 2015-04-06 06:48 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2015-04-05 21:01 - 2015-04-05 21:01 - 00001917 _____ () C:\Users\Public\Desktop\FileZilla Client.lnk
2015-04-05 21:00 - 2015-04-05 21:00 - 06196576 _____ (Tim Kosse) C:\Users\Rodiče\Downloads\FileZilla_3.10.3_win32-setup.exe
2015-04-04 22:44 - 2015-04-04 22:45 - 00000000 ___SD () C:\Windows\system32\GWX
2015-03-23 19:18 - 2015-03-23 19:18 - 00000000 ____D () C:\Users\Rodiče\Tracing
2015-03-22 09:50 - 2015-03-22 09:50 - 01079296 _____ (Uniblue Systems Limited ) C:\Users\Rodiče\Downloads\pcmechanicpm.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 21:57 - 2012-04-03 08:33 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-21 21:55 - 2008-02-25 22:38 - 00000000 ____D () C:\Users\Rodiče\AppData\Roaming\Skype
2015-04-21 21:54 - 2012-10-17 01:09 - 01675468 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 21:54 - 2008-02-25 22:37 - 00000000 ____D () C:\ProgramData\Skype
2015-04-21 21:50 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\inetsrv
2015-04-21 21:47 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-21 20:59 - 2015-03-10 18:34 - 00007631 _____ () C:\Users\Rodiče\AppData\Local\Resmon.ResmonCfg
2015-04-21 20:57 - 2011-11-03 18:37 - 00000000 ____D () C:\Users\Rodiče\Desktop\+STAŽENÉ+
2015-04-21 18:45 - 2009-05-03 18:59 - 00647680 ___SH () C:\Users\Rodiče\Desktop\Thumbs.db
2015-04-21 18:42 - 2013-10-19 18:48 - 00000349 _____ () C:\Users\Public\Documents\PCLECHAL.INI
2015-04-21 16:59 - 2012-09-28 13:48 - 00018544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-21 16:59 - 2012-09-28 13:48 - 00018544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-21 13:45 - 2008-11-08 21:50 - 00000000 ____D () C:\Program Files\Opera
2015-04-20 21:12 - 2006-11-02 12:23 - 00000246 _____ () C:\Windows\system.ini
2015-04-20 14:48 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-20 01:30 - 2012-10-17 02:41 - 00000008 __RSH () C:\Users\Rodiče\ntuser.pol
2015-04-20 01:30 - 2012-10-16 23:46 - 00000000 ____D () C:\Users\Rodiče
2015-04-20 01:30 - 2012-09-28 15:29 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-04-20 01:20 - 2006-11-02 13:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-04-19 22:30 - 2008-03-15 23:42 - 00000000 ____D () C:\bakalari
2015-04-19 22:27 - 2008-03-15 23:59 - 00000000 ____D () C:\TEMP
2015-04-19 08:46 - 2012-10-17 02:41 - 00175208 _____ () C:\Users\Rodiče\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-18 21:55 - 2012-09-12 11:40 - 00000000 ___RD () C:\Users\Rodiče\Desktop\__ K TISKU __
2015-04-18 20:26 - 2011-04-18 13:43 - 00000000 ____D () C:\Users\Rodiče\Desktop\MÁMA
2015-04-18 20:01 - 2013-04-15 16:36 - 00000000 ___RD () C:\Users\Rodiče\Desktop\___pošta___
2015-04-18 10:01 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-17 16:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-17 13:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-04-16 21:49 - 2008-02-24 22:57 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-16 14:19 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-16 13:11 - 2014-12-11 09:26 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-16 13:11 - 2014-05-06 23:38 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-15 23:16 - 2006-11-02 12:23 - 00000382 _____ () C:\Windows\win.ini
2015-04-15 23:13 - 2013-08-16 22:29 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 22:52 - 2012-10-26 07:43 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 22:49 - 2010-11-20 23:01 - 01688714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-15 19:57 - 2012-04-03 08:33 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 19:57 - 2011-06-13 18:03 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-13 22:04 - 2013-07-10 20:49 - 00000000 ____D () C:\Users\Rodiče\AppData\Roaming\FileZilla
2015-04-13 19:12 - 2010-11-17 22:53 - 00000000 ____D () C:\Users\Rodiče\Desktop\ONDRA
2015-04-08 12:45 - 2012-04-25 22:29 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-07 13:32 - 2014-06-23 06:41 - 00024144 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-04-07 13:32 - 2014-01-02 19:36 - 00106912 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-04-07 13:32 - 2013-03-14 07:27 - 00208024 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-04-07 13:32 - 2013-03-14 07:27 - 00049904 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-04-07 13:32 - 2012-11-04 21:41 - 00081728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-04-07 13:32 - 2008-04-01 16:46 - 00427736 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-04-07 13:32 - 2008-02-24 23:37 - 00073440 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-04-07 13:30 - 2011-11-20 09:47 - 00788272 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-04-06 07:15 - 2009-07-14 06:33 - 00638088 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-06 07:10 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-04-06 07:08 - 2011-04-12 03:46 - 00000000 ____D () C:\Windows\ShellNew
2015-04-06 07:07 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-06 07:00 - 2008-02-24 22:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-04-06 06:59 - 2008-02-24 22:59 - 00000000 ____D () C:\Program Files\Microsoft.NET
2015-04-06 06:56 - 2008-02-24 22:57 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-04-05 21:01 - 2013-07-10 20:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-04-05 21:01 - 2013-07-10 20:49 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2015-03-31 15:47 - 2014-08-21 19:31 - 00000000 ____D () C:\Users\Rodiče\AppData\Local\Adobe
2015-03-29 22:35 - 2010-09-20 20:12 - 00000000 ____D () C:\Users\Rodiče\Desktop\LENKA
2015-03-23 19:18 - 2014-09-29 07:28 - 00000000 ___RD () C:\Program Files\Skype
==================== Files in the root of some directories =======
2008-02-24 23:47 - 2006-03-20 16:37 - 5689344 _____ (Gabest) C:\Program Files\mplayerc.exe
2008-03-23 16:40 - 2008-03-23 16:42 - 0000140 _____ () C:\Users\Rodiče\AppData\Roaming\burnaware.ini
2012-04-17 22:15 - 2012-05-21 15:58 - 0000128 _____ () C:\Users\Rodiče\AppData\Roaming\Earthquakes Meter_Settings.ini
2008-11-25 21:18 - 2008-11-25 22:34 - 0087608 _____ () C:\Users\Rodiče\AppData\Roaming\inst.exe
2008-11-25 21:18 - 2008-11-25 22:34 - 0007887 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.cat
2008-11-25 21:18 - 2008-11-25 22:34 - 0001144 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.inf
2008-11-25 21:19 - 2008-11-25 22:34 - 0000033 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.log
2008-11-25 21:18 - 2008-11-25 22:34 - 0047360 _____ (VSO Software) C:\Users\Rodiče\AppData\Roaming\pcouffin.sys
2011-11-13 07:50 - 2011-11-13 07:50 - 0000600 _____ () C:\Users\Rodiče\AppData\Roaming\winscp.rnd
2012-10-27 22:13 - 2014-12-29 00:19 - 0010240 _____ () C:\Users\Rodiče\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-10-25 21:13 - 2012-10-25 21:13 - 0000000 _____ () C:\Users\Rodiče\AppData\Local\PRAKTIK.INI
2015-03-06 14:39 - 2015-03-06 14:39 - 0000218 _____ () C:\Users\Rodiče\AppData\Local\recently-used.xbel
2015-03-10 18:34 - 2015-04-21 20:59 - 0007631 _____ () C:\Users\Rodiče\AppData\Local\Resmon.ResmonCfg
2012-10-25 14:01 - 2012-10-25 14:02 - 0000413 _____ () C:\ProgramData\hpzinstall.log
2012-10-17 11:14 - 2012-11-22 17:19 - 0000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2012-10-25 21:13 - 2012-10-25 21:13 - 0000000 _____ () C:\ProgramData\PRAKTIK.INI
2013-10-19 22:29 - 2013-10-25 22:33 - 0000024 _____ () C:\ProgramData\__FileUploader.log
Files to move or delete:
====================
C:\Users\NFSU\jagex_runescape_preferences.dat
C:\Users\NFSU\jagex_runescape_preferences2.dat
C:\Users\NFSU\jagex__preferences3.dat
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-14 16:24
==================== End Of Log ============================
Log RFST:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-04-2015
Ran by Rodiče (administrator) on CERNY on 21-04-2015 21:54:15
Running from C:\Users\Rodiče\Desktop
Loaded Profiles: Rodiče (Available profiles: Rodiče & Lenka & NFSU)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArtistScope Pty Ltd) C:\Program Files\Common Files\ArtistScope\CSHelper32.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(Hewlett-Packard Company) C:\Program Files\HP\HPBDSService\HPBDSService.exe
(HP) C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Animation Technologies Inc.) C:\Windows\System32\lvhidsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Seznam.cz a.s.) C:\Program Files\Seznam\Postak\Postak.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Skype Technologies S.A.) C:\Windows\Temp\SKY3B89.tmp
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Opera Software) C:\Program Files\Opera\launcher.exe
() C:\Program Files\Opera\28.0.1750.51\opera_autoupdate.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SMail] => C:\Program Files\Seznam\Postak\Postak.exe [453936 2008-02-21] (Seznam.cz a.s.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5512912 2015-04-07] (Avast Software s.r.o.)
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [31346784 2015-02-26] (Skype Technologies S.A.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-04-07] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.papeweb.cz/
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?q={searchTer ... DF&pc=AVBR
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {0EBFFFDA-ABB1-49B2-A89B-594D808AC84F} URL = http://download.seznam.cz/vyhledavani/o ... rceid=IE_5
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {41FF3879-BCB7-4B39-B274-FEE2EC2BB8F5} URL = http://www.google.cz/search?q={searchTe ... 1I7GPEA_cs
SearchScopes: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://www.icq.com/search/results.php?q ... &ch_id=osd
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO: Search Helper -> {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} -> C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-28] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-07] (Avast Software s.r.o.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-18] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-28] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKU\S-1-5-21-3533039139-1052968357-1368303399-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-03] (Google Inc.)
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net ... plugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/ ... ontrol.cab
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} https://maxibps.postovnisporitelna.cz/C ... Enroll.dll
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.cz/OnlineScanner.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/In ... ct119b.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
FireFox:
========
FF ProfilePath: C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606
FF DefaultSearchEngine: Google (avast)
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: hxxp://www.papeweb.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2014-06-03] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @google.com/npPicasa2,version=2.0.0 -> C:\Program Files\Picasa2\npPicasa2.dll [2008-08-21] (Google, Inc.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Picasa2\npPicasa3.dll [2013-04-02] (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-28] (Oracle Corporation)
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.3 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @pack.google.com/Google Updater;version=14 -> C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll [2011-10-03] (Google)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3533039139-1052968357-1368303399-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Rodiče\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin HKU\S-1-5-21-3533039139-1052968357-1368303399-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Rodiče\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-01-06] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-01-06] (Apple Inc.)
FF SearchPlugin: C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\searchplugins\google-avast.xml [2014-12-15]
FF Extension: No Name - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\artur.dubovoy@gmail.com [2015-04-10]
FF Extension: gTranslator - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\jyboy.yy@gmail.com [2014-01-03]
FF Extension: ColorZilla - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326} [2014-01-03]
FF Extension: Firebug - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\firebug@software.joehewitt.com.xpi [2014-01-03]
FF Extension: Simple Timer - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\simpletimer@grbradt.org.xpi [2014-01-03]
FF Extension: Google Translator for Firefox - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\translator@zoli.bod.xpi [2014-05-11]
FF Extension: View in Office Online Viewer - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\viewinofficeapps@huhsiaotao.xpi [2014-01-03]
FF Extension: No Name - C:\Users\Rodiče\AppData\Roaming\Mozilla\Firefox\Profiles\94z9eu4z.default-1388757279606\Extensions\{5A170DD3-63CA-4c58-93B7-DE9FF536C2FF}.xpi [2014-01-03]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: No Name - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-11-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF HKLM\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
Chrome:
=======
CHR HomePage: Default -> hxxp://www.papeweb.cz/
CHR StartupUrls: Default -> "hxxp://www.papeweb.cz/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-05-07]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-11-22]
CHR Extension: (Bookmark Manager) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-21]
CHR Extension: (Avast Online Security) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2013-05-16]
CHR Extension: (Color Picker Tools) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijgamcmigplkkdkhfcjmpjojlklnkgop [2014-01-21]
CHR Extension: (Color Picker) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcmgligingjhdnhdhgepemlckgcgmgaj [2014-08-18]
CHR Extension: (Google Wallet) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Rodiče\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-11-22]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-07]
CHR HKLM\...\Chrome\Extension: [ocphobfcfafpclibolpjdafgaffkaoci] - C:\Users\Rodiče\AppData\Local\GamePlayLabs Plugin\gplplugin.crx [2011-03-15]
CHR HKU\S-1-5-21-3533039139-1052968357-1368303399-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\RODIE~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-05-03]
StartMenuInternet: Google Chrome - C:\Users\Rodiče\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-07] (Avast Software s.r.o.)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3205216 2015-04-07] (Avast Software)
R2 CSHelper; C:\Program Files\Common Files\ArtistScope\CSHelper32.exe [236536 2012-09-26] (ArtistScope Pty Ltd)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-07-23] ()
S2 gupdate1ca24ec3816786f; C:\Program Files\Google\Update\GoogleUpdate.exe [107912 2014-10-30] (Google Inc.)
R2 HP DS Service; C:\Program Files\HP\HPBDSService\HPBDSService.exe [13824 2010-10-27] (Hewlett-Packard Company) [File not signed]
R2 HP LaserJet Service; C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe [145920 2010-10-27] (HP) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-14] (Microsoft Corporation)
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2010-06-16] (Hewlett-Packard Company) [File not signed]
R2 LvHidSvc; C:\Windows\system32\lvhidsvc.exe [32256 2003-10-31] (Animation Technologies Inc.) [File not signed]
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-07-23] ()
S2 PCLEPCI; C:\Windows\system32\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24144 2015-04-07] ()
R1 aswKbd; C:\Windows\system32\Drivers\aswKbd.sys [20624 2012-10-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [73440 2015-04-07] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-04-07] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49904 2015-04-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [788272 2015-04-07] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427736 2015-04-07] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [106912 2015-04-07] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208024 2015-04-07] ()
S3 AVHybrid; C:\Windows\System32\DRIVERS\AVHybrid.sys [999680 2005-04-29] ()
R1 CSDriver; C:\Program Files\Common Files\ArtistScope\CSDriver32.sys [38328 2012-09-26] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-09-23] (LogMeIn, Inc.)
S3 HPFXBULKLEDM; C:\Windows\System32\drivers\hppcbulkio.sys [20504 2011-10-10] (Hewlett Packard)
R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2007-01-04] (Pinnacle Systems GmbH)
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [56572 2008-11-02] (PowerISO Computing, Inc.) [File not signed]
S3 tap0801; C:\Windows\System32\DRIVERS\tap0801.sys [26624 2006-10-01] (The OpenVPN Project) [File not signed]
R2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44384 2008-03-23] (Acronis)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220240 2015-04-07] (Avast Software)
S3 vncmirror; C:\Windows\System32\DRIVERS\vncmirror.sys [4608 2014-06-03] (RealVNC Ltd.)
S3 xxxHpSAMD; C:\Windows\system32\drivers\HpSAMD.sys [67152 2009-07-14] (Hewlett-Packard Company)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\RODIE~1\AppData\Local\Temp\catchme.sys [X]
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [42856 2009-06-10] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 17:15 - 2015-04-21 17:15 - 00000000 ____D () C:\Users\Rodiče\Desktop\PCHunter_free
2015-04-21 17:14 - 2015-04-21 17:15 - 06739485 _____ () C:\Users\Rodiče\Desktop\PCHunter_free.zip
2015-04-21 16:52 - 2015-04-21 21:47 - 00000924 _____ () C:\Windows\Tasks\Google Software Updater.job
2015-04-21 16:10 - 2015-04-21 16:10 - 00018948 _____ () C:\Users\Rodiče\Desktop\Addition.zip
2015-04-21 14:40 - 2015-04-21 14:46 - 00076826 _____ () C:\Users\Rodiče\Desktop\Addition.txt
2015-04-21 14:26 - 2015-04-21 21:57 - 00022967 _____ () C:\Users\Rodiče\Desktop\FRST.txt
2015-04-21 14:25 - 2015-04-21 14:25 - 01139200 _____ (Farbar) C:\Users\Rodiče\Desktop\FRST.exe
2015-04-20 21:31 - 2015-04-20 21:31 - 00025386 _____ () C:\ComboFix.txt
2015-04-20 15:38 - 2015-04-20 21:32 - 00000000 ____D () C:\ComboFix
2015-04-20 01:48 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-20 01:48 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-20 01:48 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-20 01:48 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-20 01:46 - 2015-04-20 21:32 - 00000000 ____D () C:\Qoobox
2015-04-20 01:44 - 2015-04-20 14:37 - 00000000 ____D () C:\Windows\erdnt
2015-04-20 01:42 - 2015-04-20 15:20 - 05619466 ____R (Swearware) C:\ComboFix.exe
2015-04-20 01:29 - 2015-04-20 21:06 - 00001446 _____ () C:\Windows\PFRO.log
2015-04-19 23:17 - 2015-04-19 23:17 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-19 23:16 - 2015-04-20 01:29 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-04-19 23:16 - 2015-04-19 23:16 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-19 23:15 - 2015-04-19 23:15 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-19 22:37 - 2015-04-21 21:54 - 00000000 ____D () C:\FRST
2015-04-19 09:21 - 2015-04-21 21:47 - 00280236 _____ () C:\Windows\setupact.log
2015-04-19 09:21 - 2015-04-19 09:21 - 00000000 _____ () C:\Windows\setuperr.log
2015-04-15 14:02 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-04-15 14:02 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-04-15 14:02 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-04-15 14:02 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-04-15 14:02 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-04-15 14:01 - 2015-04-02 01:49 - 00342704 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-04-15 14:01 - 2015-03-17 07:01 - 03976632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-04-15 14:01 - 2015-03-17 07:01 - 03920824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-04-15 14:01 - 2015-03-17 07:01 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-04-15 14:01 - 2015-03-17 07:01 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-04-15 14:01 - 2015-03-17 06:59 - 01306112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-04-15 14:01 - 2015-03-17 06:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-04-15 14:01 - 2015-03-17 06:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-04-15 14:01 - 2015-03-17 06:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-04-15 14:01 - 2015-03-17 06:56 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-04-15 14:01 - 2015-03-17 06:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-04-15 14:01 - 2015-03-17 06:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-04-15 14:01 - 2015-03-17 06:50 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-04-15 14:01 - 2015-03-17 06:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-04-15 14:01 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-04-15 14:01 - 2015-03-13 05:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-04-15 14:01 - 2015-03-13 05:42 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-04-15 14:01 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-04-15 14:01 - 2015-03-13 05:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-04-15 14:01 - 2015-03-13 05:27 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-04-15 14:01 - 2015-03-13 05:27 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-04-15 14:01 - 2015-03-13 05:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-04-15 14:01 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-04-15 14:01 - 2015-03-13 05:20 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-04-15 14:01 - 2015-03-13 05:20 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-04-15 14:01 - 2015-03-13 05:17 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-04-15 14:01 - 2015-03-13 05:16 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-04-15 14:01 - 2015-03-13 05:16 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-04-15 14:01 - 2015-03-13 05:15 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-04-15 14:01 - 2015-03-13 05:09 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-04-15 14:01 - 2015-03-13 05:06 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-04-15 14:01 - 2015-03-13 05:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-04-15 14:01 - 2015-03-13 04:57 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-04-15 14:01 - 2015-03-13 04:56 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-04-15 14:01 - 2015-03-13 04:54 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-04-15 14:01 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-04-15 14:01 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-04-15 14:01 - 2015-03-13 04:43 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-04-15 14:01 - 2015-03-13 04:43 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-04-15 14:01 - 2015-03-13 04:42 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-04-15 14:01 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-04-15 14:01 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-04-15 14:01 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-04-15 14:01 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-04-15 14:01 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-04-15 14:00 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-04-15 14:00 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-04-15 14:00 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-04-15 13:59 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-04-15 13:59 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-04-15 13:59 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-04-10 21:34 - 2015-04-10 21:34 - 00000000 ____D () C:\Users\Rodiče\Documents\Vlastní šablony Office
2015-04-07 13:32 - 2015-04-07 13:31 - 00291312 _____ (Avast Software s.r.o.) C:\Windows\system32\aswBoot.exe
2015-04-07 13:31 - 2015-04-07 13:31 - 00043112 _____ (Avast Software s.r.o.) C:\Windows\avastSS.scr
2015-04-06 10:41 - 2015-04-06 10:41 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-06 07:02 - 2015-04-16 21:50 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-06 06:56 - 2015-04-06 06:59 - 00000000 ____D () C:\Program Files\Microsoft SQL Server
2015-04-06 06:48 - 2015-04-06 06:48 - 00000000 ____D () C:\Program Files\Microsoft Analysis Services
2015-04-05 21:01 - 2015-04-05 21:01 - 00001917 _____ () C:\Users\Public\Desktop\FileZilla Client.lnk
2015-04-05 21:00 - 2015-04-05 21:00 - 06196576 _____ (Tim Kosse) C:\Users\Rodiče\Downloads\FileZilla_3.10.3_win32-setup.exe
2015-04-04 22:44 - 2015-04-04 22:45 - 00000000 ___SD () C:\Windows\system32\GWX
2015-03-23 19:18 - 2015-03-23 19:18 - 00000000 ____D () C:\Users\Rodiče\Tracing
2015-03-22 09:50 - 2015-03-22 09:50 - 01079296 _____ (Uniblue Systems Limited ) C:\Users\Rodiče\Downloads\pcmechanicpm.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-21 21:57 - 2012-04-03 08:33 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-21 21:55 - 2008-02-25 22:38 - 00000000 ____D () C:\Users\Rodiče\AppData\Roaming\Skype
2015-04-21 21:54 - 2012-10-17 01:09 - 01675468 _____ () C:\Windows\WindowsUpdate.log
2015-04-21 21:54 - 2008-02-25 22:37 - 00000000 ____D () C:\ProgramData\Skype
2015-04-21 21:50 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\inetsrv
2015-04-21 21:47 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-21 20:59 - 2015-03-10 18:34 - 00007631 _____ () C:\Users\Rodiče\AppData\Local\Resmon.ResmonCfg
2015-04-21 20:57 - 2011-11-03 18:37 - 00000000 ____D () C:\Users\Rodiče\Desktop\+STAŽENÉ+
2015-04-21 18:45 - 2009-05-03 18:59 - 00647680 ___SH () C:\Users\Rodiče\Desktop\Thumbs.db
2015-04-21 18:42 - 2013-10-19 18:48 - 00000349 _____ () C:\Users\Public\Documents\PCLECHAL.INI
2015-04-21 16:59 - 2012-09-28 13:48 - 00018544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-21 16:59 - 2012-09-28 13:48 - 00018544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-21 13:45 - 2008-11-08 21:50 - 00000000 ____D () C:\Program Files\Opera
2015-04-20 21:12 - 2006-11-02 12:23 - 00000246 _____ () C:\Windows\system.ini
2015-04-20 14:48 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-20 01:30 - 2012-10-17 02:41 - 00000008 __RSH () C:\Users\Rodiče\ntuser.pol
2015-04-20 01:30 - 2012-10-16 23:46 - 00000000 ____D () C:\Users\Rodiče
2015-04-20 01:30 - 2012-09-28 15:29 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-04-20 01:20 - 2006-11-02 13:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-04-19 22:30 - 2008-03-15 23:42 - 00000000 ____D () C:\bakalari
2015-04-19 22:27 - 2008-03-15 23:59 - 00000000 ____D () C:\TEMP
2015-04-19 08:46 - 2012-10-17 02:41 - 00175208 _____ () C:\Users\Rodiče\AppData\Local\GDIPFONTCACHEV1.DAT
2015-04-18 21:55 - 2012-09-12 11:40 - 00000000 ___RD () C:\Users\Rodiče\Desktop\__ K TISKU __
2015-04-18 20:26 - 2011-04-18 13:43 - 00000000 ____D () C:\Users\Rodiče\Desktop\MÁMA
2015-04-18 20:01 - 2013-04-15 16:36 - 00000000 ___RD () C:\Users\Rodiče\Desktop\___pošta___
2015-04-18 10:01 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-04-17 16:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2015-04-17 13:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2015-04-16 21:49 - 2008-02-24 22:57 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-16 14:19 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-04-16 13:11 - 2014-12-11 09:26 - 00000000 ____D () C:\Windows\system32\appraiser
2015-04-16 13:11 - 2014-05-06 23:38 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-04-15 23:16 - 2006-11-02 12:23 - 00000382 _____ () C:\Windows\win.ini
2015-04-15 23:13 - 2013-08-16 22:29 - 00000000 ____D () C:\Windows\system32\MRT
2015-04-15 22:52 - 2012-10-26 07:43 - 125832184 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-04-15 22:49 - 2010-11-20 23:01 - 01688714 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-15 19:57 - 2012-04-03 08:33 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-15 19:57 - 2011-06-13 18:03 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-13 22:04 - 2013-07-10 20:49 - 00000000 ____D () C:\Users\Rodiče\AppData\Roaming\FileZilla
2015-04-13 19:12 - 2010-11-17 22:53 - 00000000 ____D () C:\Users\Rodiče\Desktop\ONDRA
2015-04-08 12:45 - 2012-04-25 22:29 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-07 13:32 - 2014-06-23 06:41 - 00024144 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-04-07 13:32 - 2014-01-02 19:36 - 00106912 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswStm.sys
2015-04-07 13:32 - 2013-03-14 07:27 - 00208024 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-04-07 13:32 - 2013-03-14 07:27 - 00049904 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-04-07 13:32 - 2012-11-04 21:41 - 00081728 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswRdr2.sys
2015-04-07 13:32 - 2008-04-01 16:46 - 00427736 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSP.sys
2015-04-07 13:32 - 2008-02-24 23:37 - 00073440 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-04-07 13:30 - 2011-11-20 09:47 - 00788272 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswSnx.sys
2015-04-06 07:15 - 2009-07-14 06:33 - 00638088 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-04-06 07:10 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-04-06 07:08 - 2011-04-12 03:46 - 00000000 ____D () C:\Windows\ShellNew
2015-04-06 07:07 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-04-06 07:00 - 2008-02-24 22:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2015-04-06 06:59 - 2008-02-24 22:59 - 00000000 ____D () C:\Program Files\Microsoft.NET
2015-04-06 06:56 - 2008-02-24 22:57 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-04-05 21:01 - 2013-07-10 20:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2015-04-05 21:01 - 2013-07-10 20:49 - 00000000 ____D () C:\Program Files\FileZilla FTP Client
2015-03-31 15:47 - 2014-08-21 19:31 - 00000000 ____D () C:\Users\Rodiče\AppData\Local\Adobe
2015-03-29 22:35 - 2010-09-20 20:12 - 00000000 ____D () C:\Users\Rodiče\Desktop\LENKA
2015-03-23 19:18 - 2014-09-29 07:28 - 00000000 ___RD () C:\Program Files\Skype
==================== Files in the root of some directories =======
2008-02-24 23:47 - 2006-03-20 16:37 - 5689344 _____ (Gabest) C:\Program Files\mplayerc.exe
2008-03-23 16:40 - 2008-03-23 16:42 - 0000140 _____ () C:\Users\Rodiče\AppData\Roaming\burnaware.ini
2012-04-17 22:15 - 2012-05-21 15:58 - 0000128 _____ () C:\Users\Rodiče\AppData\Roaming\Earthquakes Meter_Settings.ini
2008-11-25 21:18 - 2008-11-25 22:34 - 0087608 _____ () C:\Users\Rodiče\AppData\Roaming\inst.exe
2008-11-25 21:18 - 2008-11-25 22:34 - 0007887 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.cat
2008-11-25 21:18 - 2008-11-25 22:34 - 0001144 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.inf
2008-11-25 21:19 - 2008-11-25 22:34 - 0000033 _____ () C:\Users\Rodiče\AppData\Roaming\pcouffin.log
2008-11-25 21:18 - 2008-11-25 22:34 - 0047360 _____ (VSO Software) C:\Users\Rodiče\AppData\Roaming\pcouffin.sys
2011-11-13 07:50 - 2011-11-13 07:50 - 0000600 _____ () C:\Users\Rodiče\AppData\Roaming\winscp.rnd
2012-10-27 22:13 - 2014-12-29 00:19 - 0010240 _____ () C:\Users\Rodiče\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-10-25 21:13 - 2012-10-25 21:13 - 0000000 _____ () C:\Users\Rodiče\AppData\Local\PRAKTIK.INI
2015-03-06 14:39 - 2015-03-06 14:39 - 0000218 _____ () C:\Users\Rodiče\AppData\Local\recently-used.xbel
2015-03-10 18:34 - 2015-04-21 20:59 - 0007631 _____ () C:\Users\Rodiče\AppData\Local\Resmon.ResmonCfg
2012-10-25 14:01 - 2012-10-25 14:02 - 0000413 _____ () C:\ProgramData\hpzinstall.log
2012-10-17 11:14 - 2012-11-22 17:19 - 0000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2012-10-25 21:13 - 2012-10-25 21:13 - 0000000 _____ () C:\ProgramData\PRAKTIK.INI
2013-10-19 22:29 - 2013-10-25 22:33 - 0000024 _____ () C:\ProgramData\__FileUploader.log
Files to move or delete:
====================
C:\Users\NFSU\jagex_runescape_preferences.dat
C:\Users\NFSU\jagex_runescape_preferences2.dat
C:\Users\NFSU\jagex__preferences3.dat
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-14 16:24
==================== End Of Log ============================


Přispějete na provoz fóra?