
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
malware
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: malware
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-04-2015
Ran by Macek at 2015-04-22 17:57:27 Run:1
Running from C:\Users\Macek\Desktop
Loaded Profiles: Macek (Available profiles: Macek)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1754621796-775849813-1408084889-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - No Name - {D5D47440-0750-463D-BAEF-A47D02414806} - No File
Toolbar: HKU\S-1-5-21-1754621796-775849813-1408084889-1000 -> No Name - {D5D47440-0750-463D-BAEF-A47D02414806} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Extension: FireXPathpierretholencecom - C:\Users\Macek\AppData\Roaming\Mozilla\Firefox\Profiles\wxtjif1g.default\Extensions\FireXPath@pierre.tholence.com [2015-04-19]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2015-04-21]
CHR Extension: (kjepeiijmflchkjgfjpopeimafiognkc) - C:\Users\Macek\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjepeiijmflchkjgfjpopeimafiognkc [2015-04-19]
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - No Path Or update_url value
CHR HKLM-x32\...\Chrome\Extension: [pmcmflmkceipgecmhoddphflfndnfbbe] - C:\Users\Macek\AppData\Local\Temp\tbch.crx [Not Found]
S4 aswSP; No ImagePath
S3 StarOpen; No ImagePath
S3 cpuz128; \??\C:\Users\Macek\AppData\Local\Temp\cpuz_x64.sys [X]
2015-04-22 17:17 - 2015-04-22 17:17 - 00112640 _____ (forum.viry.cz) C:\Users\Macek\Desktop\FRSTLauncher.exe
2015-04-22 17:16 - 2015-04-22 17:16 - 00112640 _____ (forum.viry.cz) C:\Users\Macek\Downloads\FRSTLauncher.exe
2015-04-21 22:02 - 2015-04-21 22:03 - 00001666 _____ () C:\Users\Macek\Desktop\Rkill.txt
2015-04-21 22:02 - 2015-04-21 22:02 - 01063160 _____ (Bleeping Computer, LLC) C:\Users\Macek\Desktop\rkill64.exe
2015-04-21 21:59 - 2015-04-21 21:59 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\Macek\Desktop\rkill.exe
2015-04-21 13:30 - 2015-04-21 13:45 - 00000000 ____D () C:\rsit
2015-04-21 13:30 - 2015-04-21 13:45 - 00000000 ____D () C:\Program Files\trend micro
2015-04-21 13:29 - 2015-04-21 13:29 - 01222144 _____ () C:\Users\Macek\Desktop\RSITx64.exe
2015-04-21 13:06 - 2015-04-21 13:06 - 00388608 _____ (Trend Micro Inc.) C:\Users\Macek\Desktop\hijackthis.exe
2015-04-20 16:07 - 2015-04-21 17:53 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-04-20 16:07 - 2015-04-21 17:51 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-04-20 16:07 - 2015-04-20 16:07 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2015-04-14 18:10 - 2015-04-21 22:15 - 00000000 ____D () C:\Program Files (x86)\ead1d464-3c89-4c86-80ea-78f66b58bffd
2015-04-14 18:10 - 2015-04-21 22:15 - 00000000 ____D () C:\Program Files (x86)\69dc8177-a574-4dff-8461-b3267b078dcf
2015-04-14 18:08 - 2015-04-14 18:08 - 00000000 ____D () C:\Users\Macek\AppData\Roaming\cpuminer
2015-04-08 15:47 - 2015-04-08 15:47 - 00000423 _____ () C:\Windows\system32\cpuminer-conf.json
2015-04-21 21:41 - 2014-09-08 15:50 - 00000000 ____D () C:\AdwCleaner
2010-07-16 15:58 - 2010-07-16 15:58 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
Task: {5661E551-FA66-45E2-BC15-AAAA3609FFB2} - System32\Tasks\{5B5FD09E-B744-4EE3-A9AA-E972D6A1ACBD} => pcalua.exe -a "D:\Instalačky\dvd shrink\DVDShrink32015.exe" -d "D:\Instalačky\dvd shrink"
Task: {EC3022EF-7375-4C2B-A1F0-1C92DD563AFE} - System32\Tasks\{D9A43107-2FE6-4076-85DD-C58F6A1C6DE7} => pcalua.exe -a C:\Users\Macek\Desktop\Adaware_Installer.exe -d C:\Users\Macek\Desktop
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\TEMP:66BB1E73
Folder: C:\Users\Default
Folder: C:\Windows\OemDrv
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-1754621796-775849813-1408084889-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{D5D47440-0750-463D-BAEF-A47D02414806} => value deleted successfully.
HKCR\Wow6432Node\CLSID\{D5D47440-0750-463D-BAEF-A47D02414806} => Key not found.
HKU\S-1-5-21-1754621796-775849813-1408084889-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D5D47440-0750-463D-BAEF-A47D02414806} => value deleted successfully.
HKCR\CLSID\{D5D47440-0750-463D-BAEF-A47D02414806} => Key not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
C:\Users\Macek\AppData\Roaming\Mozilla\Firefox\Profiles\wxtjif1g.default\Extensions\FireXPath@pierre.tholence.com => Moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} => Moved successfully.
C:\Users\Macek\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjepeiijmflchkjgfjpopeimafiognkc => Moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pmcmflmkceipgecmhoddphflfndnfbbe" => Key deleted successfully.
aswSP => Service deleted successfully.
StarOpen => Service deleted successfully.
cpuz128 => Service deleted successfully.
C:\Users\Macek\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Users\Macek\Downloads\FRSTLauncher.exe => Moved successfully.
C:\Users\Macek\Desktop\Rkill.txt => Moved successfully.
C:\Users\Macek\Desktop\rkill64.exe => Moved successfully.
C:\Users\Macek\Desktop\rkill.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Users\Macek\Desktop\RSITx64.exe => Moved successfully.
C:\Users\Macek\Desktop\hijackthis.exe => Moved successfully.
C:\Program Files (x86)\Spybot - Search & Destroy 2 => Moved successfully.
C:\ProgramData\Spybot - Search & Destroy => Moved successfully.
C:\Windows\System32\Tasks\Safer-Networking => Moved successfully.
C:\Program Files (x86)\ead1d464-3c89-4c86-80ea-78f66b58bffd => Moved successfully.
C:\Program Files (x86)\69dc8177-a574-4dff-8461-b3267b078dcf => Moved successfully.
C:\Users\Macek\AppData\Roaming\cpuminer => Moved successfully.
C:\Windows\system32\cpuminer-conf.json => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\ProgramData\ezsidmv.dat => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5661E551-FA66-45E2-BC15-AAAA3609FFB2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5661E551-FA66-45E2-BC15-AAAA3609FFB2}" => Key deleted successfully.
C:\Windows\System32\Tasks\{5B5FD09E-B744-4EE3-A9AA-E972D6A1ACBD} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5B5FD09E-B744-4EE3-A9AA-E972D6A1ACBD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EC3022EF-7375-4C2B-A1F0-1C92DD563AFE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC3022EF-7375-4C2B-A1F0-1C92DD563AFE}" => Key deleted successfully.
C:\Windows\System32\Tasks\{D9A43107-2FE6-4076-85DD-C58F6A1C6DE7} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D9A43107-2FE6-4076-85DD-C58F6A1C6DE7}" => Key deleted successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\ProgramData\TEMP => ":66BB1E73" ADS removed successfully.
========================= Folder: C:\Users\Default ========================
2009-07-14 04:34 - 2011-08-22 21:57 - 0524288 ___SH () C:\Users\Default\NTUSER.DAT
2009-07-14 17:09 - 2009-07-14 17:40 - 0001024 ____H () C:\Users\Default\NTUSER.DAT.LOG
2009-07-14 04:34 - 2015-04-21 22:06 - 0189440 ____H () C:\Users\Default\NTUSER.DAT.LOG1
2009-07-14 04:34 - 2009-07-14 04:34 - 0000000 ____H () C:\Users\Default\NTUSER.DAT.LOG2
2009-07-14 06:45 - 2009-07-14 06:45 - 0065536 ___SH () C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
2009-07-14 06:45 - 2009-07-14 06:45 - 0524288 ___SH () C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
2009-07-14 06:45 - 2009-07-14 06:45 - 0524288 ___SH () C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ___HD () C:\Users\Default\AppData
2009-07-14 05:20 - 2015-04-22 08:41 - 0000000 ____D () C:\Users\Default\AppData\Local
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\AppData\Local\Application Data
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\AppData\Local\Data aplikací
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\AppData\Local\History
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ____D () C:\Users\Default\AppData\Local\Microsoft
2010-10-30 11:38 - 2010-10-30 11:38 - 0000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ____D () C:\Users\Default\AppData\Local\Microsoft\Windows
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ____D () C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer
2009-07-14 05:20 - 2010-10-29 19:58 - 0000000 __SHD () C:\Users\Default\AppData\Local\Microsoft\Windows\History
2010-10-29 19:58 - 2010-10-29 19:58 - 0000145 ___SH () C:\Users\Default\AppData\Local\Microsoft\Windows\History\desktop.ini
2010-10-29 19:58 - 2010-10-29 19:58 - 0000000 __SHD () C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5
2010-10-29 19:58 - 2010-10-29 19:58 - 0000145 ___SH () C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
2010-10-29 19:58 - 2013-06-13 22:09 - 0016384 ___SH () C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2009-07-14 05:20 - 2015-04-21 22:15 - 0000000 __SHD () C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files
2010-10-29 19:58 - 2010-10-29 19:58 - 0000067 ___SH () C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
2015-04-22 08:41 - 2015-04-22 08:41 - 0000000 ____D () C:\Users\Default\AppData\Local\temp
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\AppData\Local\Temporary Internet Files
2009-07-14 05:20 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming
2009-12-09 13:12 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2009-12-09 13:12 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player
2009-12-09 13:12 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com
2009-12-09 13:12 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin
2009-12-09 13:12 - 2014-09-13 21:10 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller
2009-12-09 13:12 - 2009-11-11 03:14 - 0038208 _____ () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-09 13:12 - 2014-09-12 23:02 - 0002879 _____ () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\digest.s
2009-07-14 17:36 - 2009-07-14 17:36 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Media Center Programs
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ___SD () C:\Users\Default\AppData\Roaming\Microsoft
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer
2009-07-14 05:20 - 2013-01-16 16:28 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
2009-07-14 06:49 - 2009-07-14 06:49 - 0000146 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
2009-07-14 06:49 - 2009-07-14 06:49 - 0000290 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
2009-07-14 06:49 - 2009-07-14 06:49 - 0000272 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows
2009-07-14 05:20 - 2010-10-29 19:58 - 0000000 __SHD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies
2010-10-29 19:58 - 2013-06-13 22:09 - 0016384 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts
2009-07-14 05:20 - 2009-07-14 04:35 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
2009-07-14 05:20 - 2013-03-15 16:25 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent
2013-03-15 16:25 - 2013-03-15 16:25 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
2013-03-15 16:25 - 2013-03-15 16:25 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
2009-07-14 05:20 - 2014-01-14 21:13 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo
2009-07-14 04:36 - 2009-06-10 22:45 - 0000003 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Compressed (zipped) Folder.ZFSendToTarget
2009-07-14 04:34 - 2009-06-10 22:44 - 0000007 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Desktop (create shortcut).DeskLink
2009-07-14 04:36 - 2009-07-14 06:54 - 0000558 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
2009-07-14 06:54 - 2009-07-14 06:54 - 0001238 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk
2009-07-14 04:34 - 2009-06-10 22:44 - 0000004 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Mail Recipient.MAPIMail
2014-01-14 21:13 - 2014-01-14 21:13 - 0000978 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk
2009-12-09 13:10 - 2009-12-09 13:10 - 0002192 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TOSHIBA Disc Creator(Datový disk).lnk
2009-12-09 13:10 - 2009-12-09 13:10 - 0002194 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TOSHIBA Disc Creator(Obrázky na disk).lnk
2009-12-09 13:10 - 2009-12-09 13:10 - 0002192 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TOSHIBA Disc Creator(Zvukové CD).lnk
2009-07-14 05:20 - 2010-07-16 14:52 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu
2009-07-14 05:20 - 2009-12-09 13:10 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
2009-07-14 05:20 - 2009-07-14 06:54 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2009-07-14 06:54 - 2009-07-14 06:54 - 0001280 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk
2009-07-14 04:36 - 2009-07-14 06:54 - 0000678 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
2009-07-14 06:54 - 2009-07-14 06:54 - 0001304 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk
2009-07-14 06:49 - 2009-07-14 06:49 - 0000262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk
2009-07-14 06:49 - 2009-07-14 06:49 - 0001228 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk
2009-07-14 05:20 - 2009-07-14 06:54 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
2009-07-14 04:36 - 2009-07-14 06:54 - 0000704 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
2009-07-14 06:54 - 2009-07-14 06:54 - 0001358 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk
2009-07-14 06:54 - 2009-07-14 06:54 - 0001258 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk
2009-07-14 06:54 - 2009-07-14 06:54 - 0001262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
2009-07-14 06:54 - 2009-07-14 06:54 - 0001250 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
2009-07-14 05:20 - 2009-07-14 06:54 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
2009-07-14 06:49 - 2009-07-14 06:49 - 0000262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk
2009-07-14 06:49 - 2009-07-14 06:49 - 0000262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk
2009-07-14 04:36 - 2009-07-14 06:54 - 0000592 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
2009-07-14 06:54 - 2009-07-14 06:54 - 0001306 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk
2009-07-14 05:20 - 2009-07-14 06:49 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2009-07-14 04:36 - 2009-07-14 06:49 - 0000318 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
2009-07-14 06:49 - 2009-07-14 06:49 - 0000262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk
2009-12-09 13:10 - 2009-12-09 13:10 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2009-12-09 13:10 - 2009-12-09 13:10 - 0001254 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Application Data
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Data aplikací
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Desktop
2009-07-14 05:20 - 2010-07-16 14:52 - 0000000 ___RD () C:\Users\Default\Documents
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Documents\Filmy
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Documents\Hudba
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Documents\My Music
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Documents\My Pictures
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Documents\My Videos
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Documents\Obrázky
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Dokumenty
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Downloads
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Favorites
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Links
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Local Settings
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Music
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\My Documents
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Nabídka Start
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\NetHood
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Okolní síť
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Okolní tiskárny
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Pictures
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Poslední
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\PrintHood
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Recent
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ____D () C:\Users\Default\Saved Games
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\SendTo
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Soubory cookie
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Start Menu
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Šablony
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Templates
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Videos
====== End of Folder: ======
========================= Folder: C:\Windows\OemDrv ========================
2010-02-15 19:08 - 2010-02-15 19:08 - 0000000 ____D () C:\Windows\OemDrv\Shortcut
2010-02-15 19:08 - 2009-09-25 11:17 - 0002925 _____ () C:\Windows\OemDrv\Shortcut\del_shortcut.cmd
2010-02-15 19:08 - 2009-07-23 14:23 - 0000141 _____ () C:\Windows\OemDrv\Shortcut\tinst.cmd
2010-02-15 19:08 - 2008-04-22 07:34 - 0000321 _____ () C:\Windows\OemDrv\Shortcut\Tinst.ini
2010-02-15 19:08 - 2010-02-15 19:08 - 0000000 ____D () C:\Windows\OemDrv\Shortcut\Files
2010-02-15 19:08 - 2006-04-26 11:38 - 0001398 _____ () C:\Windows\OemDrv\Shortcut\Files\Media Center.lnk
2010-02-15 19:08 - 2005-09-14 11:38 - 0163840 _____ () C:\Windows\OemDrv\Shortcut\Files\TCpToSpecPath.exe
2010-02-15 19:08 - 2008-03-13 11:10 - 0217088 _____ () C:\Windows\OemDrv\Shortcut\Files\TDelSpecPath.exe
====== End of Folder: ======
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 251.2 MB temporary data.
The system needed a reboot.
==== End of Fixlog 17:57:45 ====
Ran by Macek at 2015-04-22 17:57:27 Run:1
Running from C:\Users\Macek\Desktop
Loaded Profiles: Macek (Available profiles: Macek)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1754621796-775849813-1408084889-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM-x32 - No Name - {D5D47440-0750-463D-BAEF-A47D02414806} - No File
Toolbar: HKU\S-1-5-21-1754621796-775849813-1408084889-1000 -> No Name - {D5D47440-0750-463D-BAEF-A47D02414806} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Extension: FireXPathpierretholencecom - C:\Users\Macek\AppData\Roaming\Mozilla\Firefox\Profiles\wxtjif1g.default\Extensions\FireXPath@pierre.tholence.com [2015-04-19]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2015-04-21]
CHR Extension: (kjepeiijmflchkjgfjpopeimafiognkc) - C:\Users\Macek\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjepeiijmflchkjgfjpopeimafiognkc [2015-04-19]
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - No Path Or update_url value
CHR HKLM-x32\...\Chrome\Extension: [pmcmflmkceipgecmhoddphflfndnfbbe] - C:\Users\Macek\AppData\Local\Temp\tbch.crx [Not Found]
S4 aswSP; No ImagePath
S3 StarOpen; No ImagePath
S3 cpuz128; \??\C:\Users\Macek\AppData\Local\Temp\cpuz_x64.sys [X]
2015-04-22 17:17 - 2015-04-22 17:17 - 00112640 _____ (forum.viry.cz) C:\Users\Macek\Desktop\FRSTLauncher.exe
2015-04-22 17:16 - 2015-04-22 17:16 - 00112640 _____ (forum.viry.cz) C:\Users\Macek\Downloads\FRSTLauncher.exe
2015-04-21 22:02 - 2015-04-21 22:03 - 00001666 _____ () C:\Users\Macek\Desktop\Rkill.txt
2015-04-21 22:02 - 2015-04-21 22:02 - 01063160 _____ (Bleeping Computer, LLC) C:\Users\Macek\Desktop\rkill64.exe
2015-04-21 21:59 - 2015-04-21 21:59 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\Macek\Desktop\rkill.exe
2015-04-21 13:30 - 2015-04-21 13:45 - 00000000 ____D () C:\rsit
2015-04-21 13:30 - 2015-04-21 13:45 - 00000000 ____D () C:\Program Files\trend micro
2015-04-21 13:29 - 2015-04-21 13:29 - 01222144 _____ () C:\Users\Macek\Desktop\RSITx64.exe
2015-04-21 13:06 - 2015-04-21 13:06 - 00388608 _____ (Trend Micro Inc.) C:\Users\Macek\Desktop\hijackthis.exe
2015-04-20 16:07 - 2015-04-21 17:53 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-04-20 16:07 - 2015-04-21 17:51 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-04-20 16:07 - 2015-04-20 16:07 - 00000000 ____D () C:\Windows\System32\Tasks\Safer-Networking
2015-04-14 18:10 - 2015-04-21 22:15 - 00000000 ____D () C:\Program Files (x86)\ead1d464-3c89-4c86-80ea-78f66b58bffd
2015-04-14 18:10 - 2015-04-21 22:15 - 00000000 ____D () C:\Program Files (x86)\69dc8177-a574-4dff-8461-b3267b078dcf
2015-04-14 18:08 - 2015-04-14 18:08 - 00000000 ____D () C:\Users\Macek\AppData\Roaming\cpuminer
2015-04-08 15:47 - 2015-04-08 15:47 - 00000423 _____ () C:\Windows\system32\cpuminer-conf.json
2015-04-21 21:41 - 2014-09-08 15:50 - 00000000 ____D () C:\AdwCleaner
2010-07-16 15:58 - 2010-07-16 15:58 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
Task: {5661E551-FA66-45E2-BC15-AAAA3609FFB2} - System32\Tasks\{5B5FD09E-B744-4EE3-A9AA-E972D6A1ACBD} => pcalua.exe -a "D:\Instalačky\dvd shrink\DVDShrink32015.exe" -d "D:\Instalačky\dvd shrink"
Task: {EC3022EF-7375-4C2B-A1F0-1C92DD563AFE} - System32\Tasks\{D9A43107-2FE6-4076-85DD-C58F6A1C6DE7} => pcalua.exe -a C:\Users\Macek\Desktop\Adaware_Installer.exe -d C:\Users\Macek\Desktop
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\TEMP:66BB1E73
Folder: C:\Users\Default
Folder: C:\Windows\OemDrv
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-1754621796-775849813-1408084889-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => value deleted successfully.
HKCR\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{D5D47440-0750-463D-BAEF-A47D02414806} => value deleted successfully.
HKCR\Wow6432Node\CLSID\{D5D47440-0750-463D-BAEF-A47D02414806} => Key not found.
HKU\S-1-5-21-1754621796-775849813-1408084889-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D5D47440-0750-463D-BAEF-A47D02414806} => value deleted successfully.
HKCR\CLSID\{D5D47440-0750-463D-BAEF-A47D02414806} => Key not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
C:\Users\Macek\AppData\Roaming\Mozilla\Firefox\Profiles\wxtjif1g.default\Extensions\FireXPath@pierre.tholence.com => Moved successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} => Moved successfully.
C:\Users\Macek\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjepeiijmflchkjgfjpopeimafiognkc => Moved successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pmcmflmkceipgecmhoddphflfndnfbbe" => Key deleted successfully.
aswSP => Service deleted successfully.
StarOpen => Service deleted successfully.
cpuz128 => Service deleted successfully.
C:\Users\Macek\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Users\Macek\Downloads\FRSTLauncher.exe => Moved successfully.
C:\Users\Macek\Desktop\Rkill.txt => Moved successfully.
C:\Users\Macek\Desktop\rkill64.exe => Moved successfully.
C:\Users\Macek\Desktop\rkill.exe => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Users\Macek\Desktop\RSITx64.exe => Moved successfully.
C:\Users\Macek\Desktop\hijackthis.exe => Moved successfully.
C:\Program Files (x86)\Spybot - Search & Destroy 2 => Moved successfully.
C:\ProgramData\Spybot - Search & Destroy => Moved successfully.
C:\Windows\System32\Tasks\Safer-Networking => Moved successfully.
C:\Program Files (x86)\ead1d464-3c89-4c86-80ea-78f66b58bffd => Moved successfully.
C:\Program Files (x86)\69dc8177-a574-4dff-8461-b3267b078dcf => Moved successfully.
C:\Users\Macek\AppData\Roaming\cpuminer => Moved successfully.
C:\Windows\system32\cpuminer-conf.json => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\ProgramData\ezsidmv.dat => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5661E551-FA66-45E2-BC15-AAAA3609FFB2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5661E551-FA66-45E2-BC15-AAAA3609FFB2}" => Key deleted successfully.
C:\Windows\System32\Tasks\{5B5FD09E-B744-4EE3-A9AA-E972D6A1ACBD} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5B5FD09E-B744-4EE3-A9AA-E972D6A1ACBD}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EC3022EF-7375-4C2B-A1F0-1C92DD563AFE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC3022EF-7375-4C2B-A1F0-1C92DD563AFE}" => Key deleted successfully.
C:\Windows\System32\Tasks\{D9A43107-2FE6-4076-85DD-C58F6A1C6DE7} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D9A43107-2FE6-4076-85DD-C58F6A1C6DE7}" => Key deleted successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\ProgramData\TEMP => ":66BB1E73" ADS removed successfully.
========================= Folder: C:\Users\Default ========================
2009-07-14 04:34 - 2011-08-22 21:57 - 0524288 ___SH () C:\Users\Default\NTUSER.DAT
2009-07-14 17:09 - 2009-07-14 17:40 - 0001024 ____H () C:\Users\Default\NTUSER.DAT.LOG
2009-07-14 04:34 - 2015-04-21 22:06 - 0189440 ____H () C:\Users\Default\NTUSER.DAT.LOG1
2009-07-14 04:34 - 2009-07-14 04:34 - 0000000 ____H () C:\Users\Default\NTUSER.DAT.LOG2
2009-07-14 06:45 - 2009-07-14 06:45 - 0065536 ___SH () C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
2009-07-14 06:45 - 2009-07-14 06:45 - 0524288 ___SH () C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
2009-07-14 06:45 - 2009-07-14 06:45 - 0524288 ___SH () C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ___HD () C:\Users\Default\AppData
2009-07-14 05:20 - 2015-04-22 08:41 - 0000000 ____D () C:\Users\Default\AppData\Local
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\AppData\Local\Application Data
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\AppData\Local\Data aplikací
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\AppData\Local\History
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ____D () C:\Users\Default\AppData\Local\Microsoft
2010-10-30 11:38 - 2010-10-30 11:38 - 0000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ____D () C:\Users\Default\AppData\Local\Microsoft\Windows
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ____D () C:\Users\Default\AppData\Local\Microsoft\Windows\GameExplorer
2009-07-14 05:20 - 2010-10-29 19:58 - 0000000 __SHD () C:\Users\Default\AppData\Local\Microsoft\Windows\History
2010-10-29 19:58 - 2010-10-29 19:58 - 0000145 ___SH () C:\Users\Default\AppData\Local\Microsoft\Windows\History\desktop.ini
2010-10-29 19:58 - 2010-10-29 19:58 - 0000000 __SHD () C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5
2010-10-29 19:58 - 2010-10-29 19:58 - 0000145 ___SH () C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
2010-10-29 19:58 - 2013-06-13 22:09 - 0016384 ___SH () C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2009-07-14 05:20 - 2015-04-21 22:15 - 0000000 __SHD () C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files
2010-10-29 19:58 - 2010-10-29 19:58 - 0000067 ___SH () C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
2015-04-22 08:41 - 2015-04-22 08:41 - 0000000 ____D () C:\Users\Default\AppData\Local\temp
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\AppData\Local\Temporary Internet Files
2009-07-14 05:20 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming
2009-12-09 13:12 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia
2009-12-09 13:12 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player
2009-12-09 13:12 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com
2009-12-09 13:12 - 2009-12-09 13:12 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin
2009-12-09 13:12 - 2014-09-13 21:10 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller
2009-12-09 13:12 - 2009-11-11 03:14 - 0038208 _____ () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-09 13:12 - 2014-09-12 23:02 - 0002879 _____ () C:\Users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\digest.s
2009-07-14 17:36 - 2009-07-14 17:36 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Media Center Programs
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ___SD () C:\Users\Default\AppData\Roaming\Microsoft
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer
2009-07-14 05:20 - 2013-01-16 16:28 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
2009-07-14 06:49 - 2009-07-14 06:49 - 0000146 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
2009-07-14 06:49 - 2009-07-14 06:49 - 0000290 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
2009-07-14 06:49 - 2009-07-14 06:49 - 0000272 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
2009-07-14 05:20 - 2009-07-14 05:20 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows
2009-07-14 05:20 - 2010-10-29 19:58 - 0000000 __SHD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies
2010-10-29 19:58 - 2013-06-13 22:09 - 0016384 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts
2009-07-14 05:20 - 2009-07-14 04:35 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
2009-07-14 05:20 - 2013-03-15 16:25 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent
2013-03-15 16:25 - 2013-03-15 16:25 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
2013-03-15 16:25 - 2013-03-15 16:25 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
2009-07-14 05:20 - 2014-01-14 21:13 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo
2009-07-14 04:36 - 2009-06-10 22:45 - 0000003 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Compressed (zipped) Folder.ZFSendToTarget
2009-07-14 04:34 - 2009-06-10 22:44 - 0000007 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Desktop (create shortcut).DeskLink
2009-07-14 04:36 - 2009-07-14 06:54 - 0000558 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
2009-07-14 06:54 - 2009-07-14 06:54 - 0001238 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk
2009-07-14 04:34 - 2009-06-10 22:44 - 0000004 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Mail Recipient.MAPIMail
2014-01-14 21:13 - 2014-01-14 21:13 - 0000978 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk
2009-12-09 13:10 - 2009-12-09 13:10 - 0002192 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TOSHIBA Disc Creator(Datový disk).lnk
2009-12-09 13:10 - 2009-12-09 13:10 - 0002194 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TOSHIBA Disc Creator(Obrázky na disk).lnk
2009-12-09 13:10 - 2009-12-09 13:10 - 0002192 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TOSHIBA Disc Creator(Zvukové CD).lnk
2009-07-14 05:20 - 2010-07-16 14:52 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu
2009-07-14 05:20 - 2009-12-09 13:10 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
2009-07-14 05:20 - 2009-07-14 06:54 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2009-07-14 06:54 - 2009-07-14 06:54 - 0001280 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk
2009-07-14 04:36 - 2009-07-14 06:54 - 0000678 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
2009-07-14 06:54 - 2009-07-14 06:54 - 0001304 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk
2009-07-14 06:49 - 2009-07-14 06:49 - 0000262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk
2009-07-14 06:49 - 2009-07-14 06:49 - 0001228 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk
2009-07-14 05:20 - 2009-07-14 06:54 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
2009-07-14 04:36 - 2009-07-14 06:54 - 0000704 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
2009-07-14 06:54 - 2009-07-14 06:54 - 0001358 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk
2009-07-14 06:54 - 2009-07-14 06:54 - 0001258 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk
2009-07-14 06:54 - 2009-07-14 06:54 - 0001262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
2009-07-14 06:54 - 2009-07-14 06:54 - 0001250 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
2009-07-14 05:20 - 2009-07-14 06:54 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
2009-07-14 06:49 - 2009-07-14 06:49 - 0000262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk
2009-07-14 06:49 - 2009-07-14 06:49 - 0000262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk
2009-07-14 04:36 - 2009-07-14 06:54 - 0000592 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
2009-07-14 06:54 - 2009-07-14 06:54 - 0001306 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk
2009-07-14 05:20 - 2009-07-14 06:49 - 0000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2009-07-14 04:36 - 2009-07-14 06:49 - 0000318 ___SH () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
2009-07-14 06:49 - 2009-07-14 06:49 - 0000262 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk
2009-12-09 13:10 - 2009-12-09 13:10 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2009-12-09 13:10 - 2009-12-09 13:10 - 0001254 _____ () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Application Data
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Data aplikací
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Desktop
2009-07-14 05:20 - 2010-07-16 14:52 - 0000000 ___RD () C:\Users\Default\Documents
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Documents\Filmy
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Documents\Hudba
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Documents\My Music
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Documents\My Pictures
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Documents\My Videos
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Documents\Obrázky
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Dokumenty
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Downloads
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Favorites
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Links
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Local Settings
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Music
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\My Documents
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Nabídka Start
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\NetHood
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Okolní síť
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Okolní tiskárny
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Pictures
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Poslední
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\PrintHood
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Recent
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ____D () C:\Users\Default\Saved Games
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\SendTo
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Soubory cookie
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Start Menu
2010-07-16 14:52 - 2010-07-16 14:52 - 0000000 _SHDL () C:\Users\Default\Šablony
2009-07-14 07:08 - 2009-07-14 07:08 - 0000000 _SHDL () C:\Users\Default\Templates
2009-07-14 05:20 - 2009-07-14 04:34 - 0000000 ___RD () C:\Users\Default\Videos
====== End of Folder: ======
========================= Folder: C:\Windows\OemDrv ========================
2010-02-15 19:08 - 2010-02-15 19:08 - 0000000 ____D () C:\Windows\OemDrv\Shortcut
2010-02-15 19:08 - 2009-09-25 11:17 - 0002925 _____ () C:\Windows\OemDrv\Shortcut\del_shortcut.cmd
2010-02-15 19:08 - 2009-07-23 14:23 - 0000141 _____ () C:\Windows\OemDrv\Shortcut\tinst.cmd
2010-02-15 19:08 - 2008-04-22 07:34 - 0000321 _____ () C:\Windows\OemDrv\Shortcut\Tinst.ini
2010-02-15 19:08 - 2010-02-15 19:08 - 0000000 ____D () C:\Windows\OemDrv\Shortcut\Files
2010-02-15 19:08 - 2006-04-26 11:38 - 0001398 _____ () C:\Windows\OemDrv\Shortcut\Files\Media Center.lnk
2010-02-15 19:08 - 2005-09-14 11:38 - 0163840 _____ () C:\Windows\OemDrv\Shortcut\Files\TCpToSpecPath.exe
2010-02-15 19:08 - 2008-03-13 11:10 - 0217088 _____ () C:\Windows\OemDrv\Shortcut\Files\TDelSpecPath.exe
====== End of Folder: ======
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 251.2 MB temporary data.
The system needed a reboot.
==== End of Fixlog 17:57:45 ====
Re: malware
- C:\Windows\OemDrv\Shortcut\Files\TCpToSpecPath.exe
- C:\Windows\OemDrv\Shortcut\Files\TDelSpecPath.exe
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: malware
Pocitac, respektive prohlizece uz se chovaji normalne (bez vyskakovani dalsich oken)
Akorát, když kouknu do správce úloh a nemám nic zaplé,využití procesoru je 0% a paměť mám na 2GB pořád.
Odkazy z virustotal.com
https://www.virustotal.com/cs/file/4c88 ... 429719354/
https://www.virustotal.com/cs/file/3a21 ... 429719466/
Akorát, když kouknu do správce úloh a nemám nic zaplé,využití procesoru je 0% a paměť mám na 2GB pořád.
Odkazy z virustotal.com
https://www.virustotal.com/cs/file/4c88 ... 429719354/
https://www.virustotal.com/cs/file/3a21 ... 429719466/
Re: malware
Pamet je od toho, aby se vyuzivala. Jake 3 procesy vyuzivaji RAM nejvic? Lze to vycist z klasickeho spravce uloh -> Ctrl + Shift + Esc -> karta Procesy.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: malware
První je firefox, když je zaplý 103 820kB
mbam.exe 38 232kB
dwm.exe 13468kB
mbam.exe 38 232kB
dwm.exe 13468kB
Re: malware
Toto je zcela v poradku. Kouknete znovu ve spravci uloh na kartu Vykon - vlevo dole jsou 2 polozky: Strankovano a Nestrankovano. Jake je vyuziti pameti techto polozek?
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: malware
Ok
, myslel jsem zda tam nemam jeste neco spatne...
Stránkováno 262
Nestránkováno 86
Stránkováno 262
Nestránkováno 86
Re: malware
I toto je zcela v poradku, takze jeste uklidime.
- Stahnete a spustte DelFix - https://toolslib.net/downloads/viewdownload/2-delfix/
- Oznacte jen moznost "Remove disinfection tools"
- kliknete na Run
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: malware
Dekuji Vam moc za pomoc a vyreseni problemu.

Re: malware
Nemate zac, rad jsem pomohl
Mejte se krasne a treba zase nekdy
Mejte se krasne a treba zase nekdy
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.


Přispějete na provoz fóra?