Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Prosím o kontrolu logu

#1 Příspěvek od darkane »

Prosím o kontrolu logu, někdy mi připadá notebook pomalejší, HDD často na 100%
Děkuji

Logfile of random's system information tool 1.10 (written by random/random)
Run by darkane at 2015-05-15 20:06:22
Microsoft Windows 8.1
System drive C: has 218 GB (45%) free of 486 GB
Total RAM: 8081 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:06:26, on 15. 5. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\darkane.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://yamdex.net/?searchid=1&l10n=ru&f ... earchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://yamdex.net/?searchid=1&l10n=ru&f ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://yamdex.net/?searchid=1&l10n=ru&f ... 354d&text=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://yamdex.net/?searchid=1&l10n=ru&f ... 354d&text=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [Super-Charger] C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EPSONE57E5F (Epson Stylus SX430)] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE /FU "C:\Users\DARKA_~1\AppData\Local\Temp\E_S5E8.tmp" /EF "HKCU"
O4 - Startup: default-3d.lnk = C:\ProgramData\{2c47840c-bb9b-f60c-2c47-7840cbb91032}\default-3d.exe
O4 - Global Startup: SRS PC Sound.lnk = C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK32.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Od&eslat do OneNotu - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - DefaultPrefix: http://yamdex.net/?searchid=1&l10n=ru&f ... 354d&text=
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: AvastVBox COM Service (AvastVBoxSvc) - Avast Software - C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Micro Star SCM - Micro-Star International Co., Ltd. - C:\Program Files (x86)\System Control Manager\MSIService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11789 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
dashost.exe {710d0387-b3c1-4ea2-81cd56e219e28e33}
"C:\Program Files (x86)\System Control Manager\MSIService.exe"
"C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-76ecb0c1-75f0-4ea0-b03b-a5610ab89c7f -SystemEventPortName:HostProcess-d12fc59d-fb12-4e71-a750-bb765987e202 -IoCancelEventPortName:HostProcess-3bcd99db-5f1b-4647-8380-aaac258acacc -NonStateChangingEventPortName:HostProcess-56ef0d53-070e-4a85-a422-e193d5ed4791 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:56effbce-a868-40f2-ba99-b60e644c549d -DeviceGroupId:WpdFsGroup
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-81862b58-0deb-44ad-ba3b-f0232f87f809 -SystemEventPortName:HostProcess-42a10c21-dc45-4f6c-b3d1-ccfa8d1ab302 -IoCancelEventPortName:HostProcess-78074651-4ac4-4187-9469-206d47887be9 -NonStateChangingEventPortName:HostProcess-3fdce3d8-13f0-4379-acad-bf55f33d2d51 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:c547528f-b513-4e52-a64d-114ed63e3155 -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe"
ngservice.exe pipeserver
C:\WINDOWS\Explorer.EXE
taskhostex.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe"
igfxEM.exe
igfxHK.exe
"C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE" /FU "C:\Users\DARKA_~1\AppData\Local\Temp\E_S5E8.tmp" /EF "HKCU"
"C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe"
"C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"

"C:\Program Files\CCleaner\CCleaner64.exe" /monitor
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe11_ Global\UsGthrCtrlFltPipeMssGthrPipe11 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 584 588 596 65536 592
"C:\Users\darka_000\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.25.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3503.0728]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 17.0.0.169 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default\searchplugins\
zbocz.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-22 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-21 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-22 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-21 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2012-11-28 2859344]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-11-28 13192848]
"BTMTrayAgent"=C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [2012-08-27 11577216]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-10-01 448912]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]
"Radio Manager"=C:\Program Files (x86)\SCM\Radio Manager.exe [2012-09-13 403848]
"SCM"=C:\Program Files (x86)\SCM\SCM.exe [2012-09-13 399776]
"Služba Acronis Scheduler2"=C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2014-05-30 383992]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-04-08 8202008]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
"EPSONE57E5F (Epson Stylus SX430)"=C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [2011-01-20 232448]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2012-09-13 56128]
"Super-Charger"=C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [2012-05-23 502328]
"RemoteControl10"=C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2012-03-29 91432]
"MGSysCtrl"=C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe [2009-11-06 2244608]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-05-12 5515496]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
SRS PC Sound.lnk - C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK32.EXE

C:\Users\darka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
default-3d.lnk - C:\ProgramData\{2c47840c-bb9b-f60c-2c47-7840cbb91032}\default-3d.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll,C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SoftwareSASGeneration"=1
"ConsentPromptBehaviorAdmin"=0
"PromptOnSecureDesktop"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-05-15 18:43:44 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2015-05-15 15:34:41 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-15 15:34:41 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-15 15:18:21 ----SHD---- C:\Config.Msi
2015-05-13 13:01:02 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2015-05-13 13:01:02 ----A---- C:\WINDOWS\system32\dwmcore.dll
2015-05-13 13:01:01 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2015-05-13 13:01:00 ----A---- C:\WINDOWS\system32\drivers\bthhfenum.sys
2015-05-13 13:00:41 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2015-05-13 13:00:41 ----A---- C:\WINDOWS\system32\schannel.dll
2015-05-13 13:00:38 ----A---- C:\WINDOWS\system32\drivers\ahcache.sys
2015-05-13 13:00:37 ----A---- C:\WINDOWS\system32\SystemSettingsDatabase.dll
2015-05-13 13:00:37 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2015-05-13 13:00:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2015-05-13 13:00:36 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2015-05-13 13:00:36 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2015-05-13 13:00:36 ----A---- C:\WINDOWS\system32\SRH.dll
2015-05-13 13:00:35 ----A---- C:\WINDOWS\system32\dbgeng.dll
2015-05-13 13:00:34 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2015-05-13 13:00:33 ----A---- C:\WINDOWS\SYSWOW64\dbghelp.dll
2015-05-13 13:00:33 ----A---- C:\WINDOWS\system32\dbghelp.dll
2015-05-13 13:00:32 ----A---- C:\WINDOWS\SYSWOW64\PhotoMetadataHandler.dll
2015-05-13 13:00:32 ----A---- C:\WINDOWS\system32\services.exe
2015-05-13 13:00:32 ----A---- C:\WINDOWS\system32\PhotoMetadataHandler.dll
2015-05-13 13:00:32 ----A---- C:\WINDOWS\system32\DWrite.dll
2015-05-13 13:00:32 ----A---- C:\WINDOWS\system32\drivers\udfs.sys
2015-05-13 13:00:31 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2015-05-13 13:00:31 ----A---- C:\WINDOWS\system32\win32k.sys
2015-05-13 13:00:31 ----A---- C:\WINDOWS\system32\FntCache.dll
2015-05-13 13:00:30 ----A---- C:\WINDOWS\system32\UtcResources.dll
2015-05-13 13:00:30 ----A---- C:\WINDOWS\system32\diagtrack.dll
2015-05-13 13:00:29 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2015-05-13 13:00:29 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-05-13 13:00:29 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2015-05-13 13:00:29 ----A---- C:\WINDOWS\system32\certcli.dll
2015-05-13 13:00:27 ----A---- C:\WINDOWS\SYSWOW64\sdbinst.exe
2015-05-13 13:00:27 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2015-05-13 13:00:27 ----A---- C:\WINDOWS\system32\sdbinst.exe
2015-05-13 13:00:26 ----A---- C:\WINDOWS\SYSWOW64\wpdshext.dll
2015-05-13 13:00:26 ----A---- C:\WINDOWS\system32\wpdshext.dll
2015-05-13 13:00:26 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2015-05-13 13:00:26 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2015-05-13 13:00:24 ----A---- C:\WINDOWS\system32\dpapisrv.dll
2015-05-13 13:00:19 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-05-13 13:00:17 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-05-13 13:00:15 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-05-13 13:00:14 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-05-13 13:00:13 ----A---- C:\WINDOWS\system32\jscript9.dll
2015-05-13 13:00:12 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2015-05-13 13:00:12 ----A---- C:\WINDOWS\system32\wininet.dll
2015-05-13 13:00:11 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-05-13 13:00:11 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-05-13 13:00:11 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-05-13 13:00:11 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-05-13 13:00:11 ----A---- C:\WINDOWS\system32\jscript.dll
2015-05-13 13:00:11 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-05-13 13:00:10 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2015-05-13 13:00:10 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-05-13 13:00:10 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-05-13 13:00:10 ----A---- C:\WINDOWS\system32\vbscript.dll
2015-05-13 13:00:10 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\system32\webcheck.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\system32\mshtmled.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\system32\inseng.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\system32\inetcomm.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\system32\ieui.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\system32\iepeers.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-05-13 13:00:09 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-05-13 13:00:09 ----A---- C:\WINDOWS\system32\dxtrans.dll
2015-05-13 13:00:08 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2015-05-13 13:00:08 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2015-05-13 13:00:08 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2015-05-10 12:28:04 ----D---- C:\Program Files (x86)\ASIOProxy
2015-04-22 09:59:43 ----A---- C:\WINDOWS\system32\aswBoot.exe
2015-04-22 09:59:32 ----A---- C:\WINDOWS\avastSS.scr
2015-04-16 18:23:59 ----D---- C:\WINDOWS\SYSWOW64\GroupPolicy
2015-04-16 18:23:59 ----A---- C:\log.txt
2015-04-16 18:23:50 ----H---- C:\iехplоrе.bаt.exe
2015-04-16 18:23:50 ----H---- C:\iexplore.bat
2015-04-16 18:23:08 ----H---- C:\firеfох.bаt.exe
2015-04-16 18:23:08 ----H---- C:\firefox.bat

======List of files/folders modified in the last 1 month======

2015-05-15 20:06:24 ----D---- C:\Program Files\trend micro
2015-05-15 20:02:44 ----D---- C:\WINDOWS\Prefetch
2015-05-15 20:02:00 ----D---- C:\WINDOWS\system32\sru
2015-05-15 20:00:40 ----RSD---- C:\WINDOWS\assembly
2015-05-15 19:59:39 ----D---- C:\WINDOWS\Temp
2015-05-15 19:59:31 ----D---- C:\WINDOWS\Microsoft.NET
2015-05-15 19:30:29 ----D---- C:\Users\darka_000\AppData\Roaming\DAEMON Tools Lite
2015-05-15 19:30:13 ----D---- C:\WINDOWS\Inf
2015-05-15 19:30:11 ----D---- C:\WINDOWS\SoftwareDistribution
2015-05-15 19:30:11 ----D---- C:\WINDOWS\Minidump
2015-05-15 19:30:11 ----D---- C:\WINDOWS\debug
2015-05-15 19:30:11 ----D---- C:\Windows
2015-05-15 19:28:22 ----D---- C:\Program Files\CCleaner
2015-05-15 18:47:10 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2015-05-15 18:44:35 ----D---- C:\WINDOWS\system32\config
2015-05-15 18:43:49 ----D---- C:\WINDOWS\WinSxS
2015-05-15 18:43:44 ----D---- C:\WINDOWS\SysWOW64
2015-05-15 18:42:12 ----D---- C:\Program Files\Microsoft Silverlight
2015-05-15 18:42:12 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2015-05-15 18:42:11 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-15 17:16:22 ----RD---- C:\WINDOWS\System32
2015-05-15 17:16:22 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2015-05-15 17:16:22 ----D---- C:\WINDOWS\system32\drivers
2015-05-15 17:16:21 ----RSD---- C:\WINDOWS\Fonts
2015-05-15 17:16:21 ----D---- C:\WINDOWS\system32\AdvancedInstallers
2015-05-15 17:16:20 ----D---- C:\WINDOWS\apppatch
2015-05-15 17:16:19 ----D---- C:\Program Files\Internet Explorer
2015-05-15 17:16:19 ----D---- C:\Program Files (x86)\Internet Explorer
2015-05-15 17:16:17 ----D---- C:\WINDOWS\system32\DriverStore
2015-05-15 15:59:29 ----HD---- C:\Program Files\WindowsApps
2015-05-15 15:42:12 ----SHD---- C:\WINDOWS\Installer
2015-05-15 15:42:05 ----D---- C:\ProgramData\Microsoft Help
2015-05-15 15:41:51 ----D---- C:\WINDOWS\CbsTemp
2015-05-15 15:31:56 ----D---- C:\WINDOWS\system32\MRT
2015-05-15 15:25:48 ----A---- C:\WINDOWS\system32\MRT.exe
2015-05-15 15:12:12 ----D---- C:\Program Files\Windows Journal
2015-05-15 14:50:50 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-15 14:44:11 ----SHD---- C:\System Volume Information
2015-05-14 09:04:57 ----D---- C:\WINDOWS\AppReadiness
2015-05-13 12:59:16 ----D---- C:\WINDOWS\system32\catroot2
2015-05-10 12:28:04 ----RD---- C:\Program Files (x86)
2015-05-10 12:05:44 ----D---- C:\Users\darka_000\AppData\Roaming\vlc
2015-05-06 16:20:27 ----D---- C:\WINDOWS\system32\NDF
2015-04-30 07:51:10 ----D---- C:\Users\darka_000\AppData\Roaming\Mp3tag
2015-04-24 15:40:51 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-04-22 10:13:31 ----HD---- C:\ProgramData
2015-04-22 10:00:02 ----D---- C:\WINDOWS\system32\Tasks
2015-04-18 10:50:53 ----D---- C:\WINDOWS\rescache
2015-04-16 20:09:00 ----D---- C:\WINDOWS\Tasks
2015-04-16 18:23:43 ----D---- C:\Program Files (x86)\Google
2015-04-16 13:04:12 ----HD---- C:\WINDOWS\system32\GroupPolicy

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2015-04-22 65736]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2015-04-22 272248]
R0 fltsrv;Acronis Storage Filter Management; C:\WINDOWS\system32\DRIVERS\fltsrv.sys [2015-02-18 118560]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-02 647736]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2013-09-05 30496]
R0 PxHlpa64;PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2015-02-18 276256]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2015-04-22 93528]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2015-04-22 1047320]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2015-04-22 442264]
R1 dtsoftbus01;@oem19.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2015-01-19 283200]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2014-04-30 71680]
R2 aswHwid;avast! HardwareID; C:\WINDOWS\system32\drivers\aswHwid.sys [2015-04-22 29168]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2015-04-22 89944]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2015-04-22 137288]
R2 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [2015-04-22 273824]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-10-29 81920]
R3 btmhsf;btmhsf; C:\WINDOWS\system32\DRIVERS\btmhsf.sys [2012-08-29 857472]
R3 ETD;@oem7.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2012-11-28 295760]
R3 iBtFltCoex;iBtFltCoex; C:\WINDOWS\system32\DRIVERS\iBtFltCoex.sys [2012-08-06 68136]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2014-10-01 3828152]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2012-11-28 4142864]
R3 IntcDAud;@oem25.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2012-11-28 342528]
R3 iwdbus;@oem34.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2014-08-01 27032]
R3 MEIx64;@oem27.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-11-28 62784]
R3 NETwNe64;@netwew00.inf,___ %NIC_Service_DispName_WIN8_64%;___ Intel(R) Wireless WiFi Link 5000 Series – ovladač adaptéru pro 64bitový systém Windows 8; C:\WINDOWS\system32\DRIVERS\NETwew00.sys [2013-07-08 3344352]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [2010-01-18 14136]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2013-09-05 11273504]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-06-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2014-04-30 38912]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2014-10-29 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-09-24 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2014-09-24 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2014-10-29 1198080]
S3 dg_ssudbus;@oem20.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 intaud_WaveExtensible;@oem33.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2014-08-01 38296]
S3 ipadtst;ipadtst; \??\C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [2011-12-12 17936]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 RSUSBSTOR;@oem4.inf,%RSUSBSTOR.SvcDesc%;RtsUStor.Sys Realtek USB Card Reader; C:\WINDOWS\System32\Drivers\RtsUStor.sys [2012-11-28 252048]
S3 ssudmdm;@oem21.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 ssudserd;@oem22.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudserd.sys [2014-01-22 206080]
S3 usb_rndisx;@netrndis.inf,%usb_rndis.Service.DispName%;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2013-08-22 20992]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2014-05-30 943136]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-04-22 343336]
R2 Bluetooth Device Monitor;Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [2012-08-27 1112000]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [2012-09-06 1124288]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-09-02 14904]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\WINDOWS\system32\igfxCUIService.exe [2014-10-01 319376]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-06-20 634632]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-11-28 165760]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-11-28 276864]
R2 Micro Star SCM;Micro Star SCM; C:\Program Files (x86)\System Control Manager\MSIService.exe [2009-07-09 160768]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [2012-05-23 142904]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2013-08-30 920864]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2012-11-28 201360]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-11-28 364416]
R3 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [2015-04-22 4034896]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-09-05 1364256]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15 268464]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2014-10-01 281488]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19 107912]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-04-24 148080]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Po spusteni probehne stazeni databaze
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#3 Příspěvek od darkane »

také zdravím :)
zde je nový log

# AdwCleaner v4.204 - Log vytvořen 15/05/2015 v 20:41:48
# Aktualizováno 12/05/2015 by Xplode
# Databáze : 2015-05-12.2 [Server]
# Operační system : Windows 8.1 (x64)
# Uživatelské jméno : darkane - DARKANE
# Spuštěno z : C:\Users\darka_000\Desktop\adwcleaner_4.204.exe
# Nastavení : Čištění

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ProgramData\{2c47840c-bb9b-f60c-2c47-7840cbb91032}
Složka Smazáno : C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Složka Smazáno : C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Složka Smazáno : C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Složka Smazáno : C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Složka Smazáno : C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Soubor Smazáno : C:\Program Files\Common Files\System\SysMenu.dll
Soubor Smazáno : C:\Program Files\Common Files\System\SysMenu64.dll

***** [ Naplánované úlohy ] *****


***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki
Klíč Smazáno : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3C}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3D}
Klíč Smazáno : HKCU\Software\IM
Klíč Smazáno : HKU\.DEFAULT\Software\Goobzo

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17416

Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Search_URL]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]

-\\ Mozilla Firefox v37.0.2 (x86 cs)


-\\ Google Chrome v42.0.2311.152

[C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://www.ask.com/web?q={searchTerms}
[C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://search.aol.com/aol/search?q={searchTerms}

*************************

AdwCleaner[R0].txt - [3099 bytů] - [03/02/2015 20:34:30]
AdwCleaner[R1].txt - [3710 bytů] - [15/05/2015 20:39:42]
AdwCleaner[S0].txt - [3219 bytů] - [03/02/2015 20:37:30]
AdwCleaner[S1].txt - [2925 bytů] - [15/05/2015 20:41:48]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2983 bytů] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#4 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#5 Příspěvek od darkane »

Zoek si na práci nechal záležet. Makal přes hodinu.
Zde je jeho log


Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by darkane on p  15. 05. 2015 at 21:01:16,28.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\darka_000\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

15. 5. 2015 21:02:59 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Seznam.cz deleted successfully
C:\PROGRA~3\EZ CD Audio Converter deleted successfully
C:\Users\darka_000\AppData\Roaming\Vso deleted successfully
C:\Users\darka_000\AppData\Local\Axialis deleted successfully
C:\Users\darka_000\AppData\Local\CrashDumps deleted successfully
C:\Users\darka_000\AppData\Local\MigWiz deleted successfully
C:\Users\darka_000\AppData\Local\Unity deleted successfully
C:\Users\Guest\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{132D15C7-7A5A-44CF-B7AA-33BEBBA3C0B} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{134E625A-C8DB-43A0-8BF4-98D1FB431FAF} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1D1C15D2-A622-4178-8435-FE9412D4463A} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD892EE-289A-4F93-879D-48BC7F22FDEE} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{253B4B63-157C-4140-9143-701D404E72FA} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{27AC3345-F2D1-424D-B85A-B0B45386026} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2814B0B9-3881-4833-B8E8-4479C0113C36} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{28B43F12-963A-4971-A47D-E9DB91617011} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2EAA0A37-B1FC-4C29-A9A3-45E240DC2E39} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2FAE5DA5-D4BE-46F5-8821-7DA1A392890} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3039ABE8-54B3-4CA2-A4E0-5CCB9CD68F5E} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3075C849-B9DE-4E93-B7F7-2FB2717DD78E} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{371C169E-DCB3-468F-847C-A7CCB86DD63} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3E179EE3-A404-4773-9166-3445B834AAE5} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3F40BE0B-3616-408A-8627-1F80F68A6C15} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{40083835-744C-4AAE-A58A-9D693AE345A} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{43237ABF-E257-4582-8D1F-617CE3D9B85B} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{45C8DAA1-1FA3-4201-B5C4-F0A688C99F1E} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5A0C914E-62A6-4FBD-B2DE-FC4FC3318AA1} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5B37CA00-9DFE-46D5-B422-E56766578678} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5C5A688B-59A3-47E0-A11D-4C246FE288B1} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6B26CBA1-B6A8-41D9-8A70-F0AAA7662AE2} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6D2661B6-7065-4111-B1CC-B0FAB9A9DC1D} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{709AF13D-12EB-40BD-AD83-C25A1BF4EB6E} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{71BE9D50-E298-4B77-9C92-A6E438FEC3AC} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7212D516-D92E-4FEA-8D50-E864CB956BA} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{72317A25-2C3A-4028-9BFE-AF1512201DB8} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{72801EF5-ABFA-4DBD-87B1-8C99A04D2DD0} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{75482A7D-D7FB-4209-949C-7F7A873AB4F1} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7DB90A68-23D1-4C40-8E98-6DBB9F5019A} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{88681A98-F96-4102-9AFA-B5DD742E694B} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8868EADA-6594-4592-AAFF-28E5FC25C7C7} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8EB4D2B7-3998-42CF-8ECF-F68A43DA274C} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{92240F65-CA04-4589-B717-DDB9FB7B46DE} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A1A60938-6334-4025-AA65-3ACF6BBB6F2} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A3718083-F722-4641-A185-F3732DDB29E3} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC40718E-B6C3-42A9-AD44-348E2B8CAF5} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AE03D4A9-17E9-4DA4-9B42-E3BD533A7691} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AEC72CF0-FCCE-49A0-B5DF-2B312CA3B422} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B0D7F094-1BB3-4869-B4C0-CCEE1AF393C1} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2E90B27-38CF-4084-A8B4-84A22347B64} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BC252890-873D-4521-AD4E-EAB47FCE5B0} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BC6EAA72-B694-4A13-9AE2-924D34FC3B2A} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF855DCB-4267-4D92-899E-80EBBC583166} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BFB06399-DAC3-4E9B-8E16-117A95539A68} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C040382D-2D64-4A3C-9D4F-D229D64F9782} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C50A08C4-2EBB-4128-B9E2-128C738E183F} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C820B5E9-CD00-48FD-B98C-2629E3DC555} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C8C1EAD6-80EF-48D1-9F1E-FFE3DF9722E9} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA4563E6-8131-42F2-AAF0-3B41F45349A9} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DFE32364-EEAC-4FFE-9E6C-25DE2BB9FC1} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E5152E26-1E41-4DBF-9063-3E3CE9B18454} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EA533399-ABC0-4121-87EC-D55336D01776} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EB86A890-216-4ED8-ADD-BE709DB44DE} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EC20DE07-20EC-4F96-9A37-D24715A9EC9F} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFAB9052-9960-4B55-9A59-82AC4DD7CAC} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFCA0003-C120-48F3-9916-366BB9EA33E1} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F1642AA1-A9E8-4CC1-9B1C-2B673F744CF9} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F339CF5F-E66A-498A-A867-E1EF9DEEADA} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{1D355335-BE86-4418-AC98-2436CC3D6D74} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611901163} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611341129} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611911129} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611901159} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611171152} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611331113} deleted successfully
HKEY_USERS\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Internet Explorer\URLSearchHooks\{0633EE93-D776-472f-A0FF-E1416B8B2E3D} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\DARKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\DARKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\fla9otca.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/");

Added to C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\fla9otca.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\DARKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default

user.js not found
---- Lines Box Rock removed from prefs.js ----
user_pref("extensions.Box Rock.aul", "1417642821980");
user_pref("extensions.Box Rock.irl", true);
user_pref("extensions.Box Rock.is", "EF22DDCZ");
user_pref("extensions.Box Rock.ug", "5C557DF9-E6D6-47BC-8F16-86175EC1176D");
---- Lines Dolphin Deals removed from prefs.js ----
user_pref("extensions.Dolphin Deals.asul", "1418311002740");
user_pref("extensions.Dolphin Deals.aul", "1418310992306");
user_pref("extensions.Dolphin Deals.irl", true);
user_pref("extensions.Dolphin Deals.is", "amp1lmcz");
user_pref("extensions.Dolphin Deals.ug", "92325897-E584-43DC-B8F2-31DDD08E770C");
---- Lines SourceApp removed from prefs.js ----
user_pref("extensions.SourceApp.aul", "1421701104935");
user_pref("extensions.SourceApp.irl", true);
user_pref("extensions.SourceApp.is", "smp1cz");
user_pref("extensions.SourceApp.ug", "8D188151-EFB1-4EE0-9055-03C56F40F82A");
---- Lines extensions.WlWWNzFzeZpghaiM removed from prefs.js ----
user_pref("extensions.WlWWNzFzeZpghaiM.epoch", "1422984442");
user_pref("extensions.WlWWNzFzeZpghaiM.url", "http://superiend.info/sync2/?q=hfZ9oflK ... 6rTg9rihIC
---- FireFox user.js and prefs.js backups ----

prefs_201515.05._2153_.backup

ProfilePath: C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\fla9otca.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_201515.05._2153_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Seznam.cz not found
C:\Users\darka_000\Desktop\WinX_YouTube_Downloader – zástupce.lnk not found
C:\fir?f??.b?t.exe deleted
C:\i??pl?r?.b?t.exe deleted
C:\Users\darka_000\AppData\Roaming\{37E99E86-D615-4B08-937F-F8F935C455F3}_ANZHUANG deleted
C:\Users\darka_000\AppData\Local\Installer deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\Public\Documents\GOOBZO deleted
C:\Users\Public\Documents\ShopperPro deleted
C:\Users\Public\Documents\YTAHelper deleted
C:\WINDOWS\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Adm deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\WINDOWS\Syswow64\GroupPolicy\Adm deleted
C:\WINDOWS\Syswow64\GroupPolicy\Machine deleted
C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\fla9otca.default\extensions\staged deleted
C:\Users\darka_000\Desktop\4K Video Downloader.lnk deleted
C:\Users\darka_000\Desktop\MRDownloader.exe deleted
"C:\Users\darka_000\AppData\Roaming\HKU" deleted
"C:\Users\darka_000\AppData\Roaming\ICBWRJZE" deleted
"C:\Users\darka_000\AppData\Roaming\KGPKVLD" deleted
"C:\Users\darka_000\AppData\Roaming\QHMDS" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\DARKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\fla9otca.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [22. 04. 2015 09:59]

==== Firefox Extensions ======================

ProfilePath: C:\Users\DARKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default
- Easy Youtube Video Downloader Express - %ProfilePath%\extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default
9AE02005247DA91AB1743F5208DBEF76 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash
09B4E13D25623D879D35286E2D29FF13 - C:\Users\darka_000\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
EBFA34C48C2B514A471B9B32892FBD63 - C:\Users\darka_000\AppData\Local\Roblox\Versions\version-d2af929835a34f18\NPRobloxProxy.dll - Roblox Launcher Plugin
B5758C2FF943681E3FABB3B0DDE3DEF9 - C:\Users\darka_000\AppData\Local\Roblox\Versions\version-d2af929835a34f18\NPRobloxProxy64.dll - Roblox Launcher Plugin


==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\Guest\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

Google Chrome Version: 42.0.2311.152



==== Chromium Startpages ======================

C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "https://www.seznam.cz/",


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"CustomizeSearch"="http://www.google.com"
"SearchAssistant"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"CustomizeSearch"="http://www.google.com"
"SearchAssistant"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chcust.htm"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{A3BC4107-6A74-4AFB-B7F3-156D79424B64} Bing Url="http://www.bing.com/search?q={searchTer ... &pc=MAMIJS;"

==== Reset Google Chrome ======================

C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\darka_000\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\darka_000\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\darka_000\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\darka_000\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\darka_000\AppData\Local\Mozilla\Firefox\Profiles\9yz2pq69.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=29 folders=20 6385756 bytes)

==== Empty Temp Folders ======================

C:\Users\darka_000\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\DARKA_~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on p  15. 05. 2015 at 22:05:49,46 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#6 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#7 Příspěvek od darkane »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2015 02
Ran by darkane (administrator) on DARKANE on 15-05-2015 22:36:20
Running from C:\Users\darka_000\Desktop
Loaded Profiles: darkane (Available profiles: UpdatusUser & darkane & Guest)
Platform: Windows 8.1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\System Control Manager\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2859344 2012-11-28] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-11-28] (Realtek Semiconductor)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [403848 2012-09-13] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [399776 2012-09-13] (MSI)
HKLM\...\Run: [Slu~ba Acronis Scheduler2] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [383992 2014-05-30] (Acronis)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-02] (Intel Corporation)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [502328 2012-05-23] (MSI)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [MGSysCtrl] => C:\Program Files (x86)\System Control Manager\MGSysCtrl.exe [2244608 2009-11-06] (Micro-Star International Co., Ltd.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-12] (Avast Software s.r.o.)
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8202008 2015-04-08] (Piriform Ltd)
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [EPSONE57E5F (Epson Stylus SX430)] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [232448 2011-01-20] (SEIKO EPSON CORPORATION)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation)
AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SRS PC Sound.lnk [2012-11-29]
ShortcutTarget: SRS PC Sound.lnk -> C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe (SRS Labs, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk [2012-11-29]
ShortcutTarget: WinZip Quick Pick.lnk -> C:\Program Files\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)
Startup: C:\Users\darka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\default-3d.lnk [2015-02-02]
ShortcutTarget: default-3d.lnk -> C:\ProgramData\{2c47840c-bb9b-f60c-2c47-7840cbb91032}\default-3d.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-04-22] (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
URLSearchHook: [S-1-5-21-2802680610-4246973846-2910803817-1002] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2802680610-4246973846-2910803817-1002 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-22] (Avast Software s.r.o.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-21] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-22] (Avast Software s.r.o.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-21] (Oracle Corporation)
DefaultPrefix-x32: => http://yamdex.net/?searchid=1&l10n=ru&f ... 354d&text= <==== ATTENTION

FireFox:
========
FF ProfilePath: C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default
FF Homepage: https://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-11-28] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-11-28] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-21] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-28] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-03-14] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin HKU\S-1-5-21-2802680610-4246973846-2910803817-1002: @nsroblox.roblox.com/launcher -> C:\Users\darka_000\AppData\Local\Roblox\Versions\version-d2af929835a34f18\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-2802680610-4246973846-2910803817-1002: @nsroblox.roblox.com/launcher64 -> C:\Users\darka_000\AppData\Local\Roblox\Versions\version-d2af929835a34f18\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-2802680610-4246973846-2910803817-1002: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\darka_000\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF SearchPlugin: C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default\searchplugins\zbocz.xml [2015-03-07]
FF Extension: Easy Youtube Video Downloader Express - C:\Users\darka_000\AppData\Roaming\Mozilla\Firefox\Profiles\9yz2pq69.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2014-12-05]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-01-09]

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-19]
CHR Extension: (YouTube) - C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-19]
CHR Extension: (Google Search) - C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-19]
CHR Extension: (Chrono Download Manager) - C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\mciiogijehkdemklbdcbfkefimifhecn [2015-04-07]
CHR Extension: (Gmail) - C:\Users\darka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-19]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-22] (Avast Software s.r.o.)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4034896 2015-04-22] (Avast Software)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [1429504 2015-03-05] (Microsoft Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-11-28] (Intel Corporation)
R2 Micro Star SCM; C:\Program Files (x86)\System Control Manager\MSIService.exe [160768 2009-07-09] (Micro-Star International Co., Ltd.) [File not signed]
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [142904 2012-05-23] (MSI)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-11-28] (Realtek Semiconductor)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-22] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-04-22] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-22] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-22] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-22] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-04-22] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-04-22] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-04-22] ()
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [857472 2012-08-29] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2015-01-19] (DT Soft Ltd)
S3 ipadtst; C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [17936 2011-12-12] (Windows (R) Win 7 DDK provider)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [14136 2010-01-18] (MSI)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-04-22] (Avast Software)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-15 22:36 - 2015-05-15 22:36 - 00017627 _____ () C:\Users\darka_000\Desktop\FRST.txt
2015-05-15 22:35 - 2015-05-15 22:36 - 00000000 ____D () C:\FRST
2015-05-15 22:35 - 2015-05-15 22:35 - 02106368 _____ (Farbar) C:\Users\darka_000\Desktop\FRST64.exe
2015-05-15 22:04 - 2015-05-15 22:04 - 00000330 _____ () C:\WINDOWS\PFRO.log
2015-05-15 22:02 - 2015-05-15 21:01 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2015-05-15 21:02 - 2015-05-15 22:05 - 00026191 _____ () C:\zoek-results.log
2015-05-15 21:01 - 2015-05-15 21:54 - 00000000 ____D () C:\zoek_backup
2015-05-15 21:00 - 2015-05-15 21:00 - 01308672 _____ () C:\Users\darka_000\Desktop\zoek.exe
2015-05-15 20:43 - 2015-05-15 22:04 - 00000154 _____ () C:\WINDOWS\setupact.log
2015-05-15 20:43 - 2015-05-15 20:43 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-05-15 20:38 - 2015-05-15 20:38 - 02209792 _____ () C:\Users\darka_000\Desktop\adwcleaner_4.204.exe
2015-05-15 20:11 - 2015-05-15 22:19 - 00109095 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-15 20:05 - 2015-05-15 20:05 - 01222144 _____ () C:\Users\darka_000\Desktop\RSITx64.exe
2015-05-15 18:43 - 2015-05-05 19:59 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-05-15 18:43 - 2015-05-05 19:59 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-05-15 15:34 - 2015-04-30 22:35 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-15 15:34 - 2015-04-30 22:35 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-05-14 12:59 - 2015-05-14 13:02 - 00000000 ____D () C:\Users\darka_000\Downloads\1991- Queen - Greatest Hits II (JP SACD 2013 Universal International • UIGY-9533)
2015-05-14 12:56 - 2015-05-14 13:02 - 00000000 ____D () C:\Users\darka_000\Downloads\1981- Queen - Greatest Hits (JP SACD 2013 Universal International • UIGY-9532)
2015-05-13 13:01 - 2015-04-10 02:34 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-05-13 13:01 - 2015-04-10 02:11 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-05-13 13:01 - 2015-03-17 19:26 - 00467776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-05-13 13:01 - 2015-03-09 04:02 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-05-13 13:00 - 2015-05-01 01:05 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-05-13 13:00 - 2015-05-01 00:48 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-05-13 13:00 - 2015-04-24 23:32 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-05-13 13:00 - 2015-04-21 19:14 - 24971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-05-13 13:00 - 2015-04-21 18:50 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-05-13 13:00 - 2015-04-21 18:50 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-05-13 13:00 - 2015-04-21 18:49 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-05-13 13:00 - 2015-04-21 18:37 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-05-13 13:00 - 2015-04-21 18:35 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-05-13 13:00 - 2015-04-21 18:31 - 06025728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-05-13 13:00 - 2015-04-21 18:24 - 19691008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-05-13 13:00 - 2015-04-21 18:13 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
2015-05-13 13:00 - 2015-04-21 18:11 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-05-13 13:00 - 2015-04-21 18:09 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-05-13 13:00 - 2015-04-21 18:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-05-13 13:00 - 2015-04-21 18:07 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-05-13 13:00 - 2015-04-21 18:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-05-13 13:00 - 2015-04-21 18:04 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-05-13 13:00 - 2015-04-21 17:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-05-13 13:00 - 2015-04-21 17:58 - 00664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-05-13 13:00 - 2015-04-21 17:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-05-13 13:00 - 2015-04-21 17:49 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-05-13 13:00 - 2015-04-21 17:49 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-05-13 13:00 - 2015-04-21 17:49 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-05-13 13:00 - 2015-04-21 17:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-05-13 13:00 - 2015-04-21 17:40 - 14401536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-05-13 13:00 - 2015-04-21 17:38 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-05-13 13:00 - 2015-04-21 17:37 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-05-13 13:00 - 2015-04-21 17:36 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-05-13 13:00 - 2015-04-21 17:32 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-05-13 13:00 - 2015-04-21 17:31 - 04305920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-05-13 13:00 - 2015-04-21 17:28 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-05-13 13:00 - 2015-04-21 17:27 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-05-13 13:00 - 2015-04-21 17:26 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-05-13 13:00 - 2015-04-21 17:26 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-05-13 13:00 - 2015-04-21 17:25 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-05-13 13:00 - 2015-04-21 17:17 - 12828672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-05-13 13:00 - 2015-04-21 17:15 - 01547264 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-05-13 13:00 - 2015-04-21 17:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-05-13 13:00 - 2015-04-21 17:02 - 01882112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-05-13 13:00 - 2015-04-21 16:58 - 01310208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-05-13 13:00 - 2015-04-21 16:56 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-05-13 13:00 - 2015-04-14 00:48 - 04180480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-05-13 13:00 - 2015-04-10 03:00 - 01996800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-05-13 13:00 - 2015-04-10 02:50 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-05-13 13:00 - 2015-04-10 02:26 - 01560576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-05-13 13:00 - 2015-04-09 00:55 - 00410128 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2015-05-13 13:00 - 2015-04-03 02:35 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2015-05-13 13:00 - 2015-04-03 02:14 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2015-05-13 13:00 - 2015-04-02 00:22 - 02985984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2015-05-13 13:00 - 2015-04-02 00:20 - 04417536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2015-05-13 13:00 - 2015-04-01 05:45 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2015-05-13 13:00 - 2015-04-01 04:31 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2015-05-13 13:00 - 2015-03-30 07:47 - 00561928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-05-13 13:00 - 2015-03-27 05:27 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-05-13 13:00 - 2015-03-27 04:50 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-05-13 13:00 - 2015-03-27 04:48 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-05-13 13:00 - 2015-03-20 03:56 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-05-13 13:00 - 2015-03-13 06:03 - 00239424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-05-13 13:00 - 2015-03-13 06:03 - 00154432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2015-05-13 13:00 - 2015-03-13 04:02 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
2015-05-13 13:00 - 2015-03-13 03:11 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-05-13 13:00 - 2015-03-13 02:39 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-05-13 13:00 - 2015-03-13 02:29 - 00410017 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-05-13 13:00 - 2015-03-11 03:49 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe
2015-05-13 13:00 - 2015-03-11 03:09 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe
2015-05-13 13:00 - 2015-03-06 05:08 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2015-05-13 13:00 - 2015-03-06 04:47 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2015-05-13 13:00 - 2015-03-06 04:43 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2015-05-13 13:00 - 2015-03-05 01:09 - 01429504 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-05-13 13:00 - 2015-03-04 03:32 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2015-05-13 13:00 - 2015-03-04 03:12 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2015-05-13 13:00 - 2015-02-18 01:19 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2015-05-13 13:00 - 2015-01-30 02:53 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-05-13 13:00 - 2014-11-14 08:58 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsDatabase.dll
2015-05-10 12:28 - 2015-05-10 12:28 - 00000000 ____D () C:\Program Files (x86)\ASIOProxy
2015-05-10 12:16 - 2015-05-14 10:42 - 00000000 ____D () C:\Users\darka_000\Desktop\foo_input_sacd-0.7.8
2015-05-10 11:52 - 2015-05-14 10:46 - 00000000 ____D () C:\Users\darka_000\Downloads\1975- Queen - A Night At The Opera SACD
2015-05-10 11:51 - 2015-05-14 10:46 - 00000000 ____D () C:\Users\darka_000\Downloads\1975 - Queen - A Night At The Opera flac
2015-05-08 11:47 - 2015-05-08 14:15 - 00000000 ____D () C:\Users\darka_000\Desktop\d240h
2015-05-07 21:04 - 2015-05-08 21:15 - 1979078656 _____ () C:\Users\darka_000\Downloads\Whiplash-(2014)-CZ-Hudební--Drama.avi
2015-04-29 22:40 - 2015-04-29 22:42 - 00000000 ____D () C:\Users\darka_000\Downloads\1982- The Best Of Whitesnake (FR 1990 Underdog Records • 97. 892)
2015-04-22 09:59 - 2015-04-22 09:59 - 00364472 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\aswBoot.exe
2015-04-22 09:59 - 2015-04-22 09:59 - 00043112 _____ (Avast Software s.r.o.) C:\WINDOWS\avastSS.scr
2015-04-16 20:18 - 2015-04-16 20:18 - 00001738 _____ () C:\Users\darka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\firefox – zástupce.lnk
2015-04-16 20:15 - 2015-04-16 20:15 - 00001522 _____ () C:\Users\darka_000\Desktop\Firefox.lnk
2015-04-16 18:23 - 2015-05-15 21:54 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy
2015-04-16 18:23 - 2015-04-16 18:24 - 00000109 ____H () C:\iexplore.bat
2015-04-16 18:23 - 2015-04-16 18:24 - 00000108 ____H () C:\firefox.bat
2015-04-16 15:10 - 2015-04-16 15:12 - 00000197 _____ () C:\WINDOWS\system32\2015-04-16-13-10-28.082-AvastVBoxSVC.exe-3888.log
2015-04-16 15:08 - 2015-05-15 22:04 - 00000008 __RSH () C:\Users\darka_000\ntuser.pol
2015-04-16 08:28 - 2015-04-16 08:28 - 00000197 _____ () C:\WINDOWS\system32\2015-04-16-06-28-32.088-AvastVBoxSVC.exe-2768.log
2015-04-15 15:01 - 2015-03-23 23:59 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-04-15 15:01 - 2015-03-23 23:59 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-04-15 15:01 - 2015-03-23 23:59 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2015-04-15 15:01 - 2015-03-23 23:58 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-04-15 15:01 - 2015-03-23 23:45 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2015-04-15 15:01 - 2015-03-23 00:45 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-04-15 15:01 - 2015-03-23 00:09 - 01111552 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-04-15 15:01 - 2015-03-23 00:09 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-04-15 15:01 - 2015-03-23 00:09 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-04-15 15:01 - 2015-03-23 00:09 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-04-15 15:01 - 2015-03-23 00:09 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-04-15 15:01 - 2015-03-23 00:09 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-04-15 15:01 - 2015-03-20 06:12 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2015-04-15 15:01 - 2015-03-20 06:10 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-04-15 15:01 - 2015-03-20 06:10 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-04-15 15:01 - 2015-03-20 05:17 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe
2015-04-15 15:01 - 2015-03-20 04:41 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe
2015-04-15 15:01 - 2015-03-20 04:40 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-04-15 15:01 - 2015-03-20 04:16 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-04-15 15:01 - 2015-03-14 10:54 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-04-15 15:01 - 2015-03-14 10:20 - 01385256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-04-15 15:01 - 2015-03-14 10:13 - 01124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2015-04-15 15:01 - 2015-03-14 03:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-04-15 15:01 - 2015-03-14 03:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-04-15 15:01 - 2015-03-14 03:51 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-04-15 15:01 - 2015-03-14 03:37 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-04-15 15:01 - 2015-03-14 03:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-04-15 15:01 - 2015-03-14 02:22 - 03678720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-04-15 15:01 - 2015-03-14 02:12 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-04-15 15:01 - 2015-03-14 02:12 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-04-15 15:01 - 2015-03-14 02:09 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-04-15 15:01 - 2015-03-14 02:08 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-04-15 15:01 - 2015-03-14 02:08 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-04-15 15:01 - 2015-03-14 02:06 - 02373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-04-15 15:01 - 2015-03-14 02:06 - 00891392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-04-15 15:01 - 2015-03-14 02:02 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-04-15 15:01 - 2015-03-14 02:02 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-04-15 15:01 - 2015-03-14 01:59 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-04-15 15:01 - 2015-03-14 01:59 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-04-15 15:01 - 2015-03-13 04:58 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2015-04-15 15:01 - 2015-03-13 04:37 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2015-04-15 15:01 - 2015-03-04 12:25 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2015-04-15 15:01 - 2015-03-04 05:04 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
2015-04-15 15:01 - 2015-03-04 04:19 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll
2015-04-15 15:01 - 2015-02-24 10:32 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2015-04-15 15:01 - 2015-02-21 01:49 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-05-15 22:20 - 2015-03-14 00:15 - 00000970 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-15 22:05 - 2015-03-14 00:15 - 00000966 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-15 22:04 - 2014-12-12 07:49 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2015-05-15 22:04 - 2014-11-25 19:18 - 00000000 ____D () C:\Users\darka_000
2015-05-15 22:04 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-15 22:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-15 21:57 - 2015-01-16 19:37 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2015-05-15 21:54 - 2012-07-26 10:12 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy
2015-05-15 21:45 - 2014-11-19 21:36 - 00000914 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-15 20:42 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-15 20:41 - 2015-02-03 20:34 - 00000000 ____D () C:\AdwCleaner
2015-05-15 20:41 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\System
2015-05-15 20:38 - 2014-12-04 09:15 - 02053632 ___SH () C:\Users\darka_000\Desktop\Thumbs.db
2015-05-15 20:25 - 2014-11-30 15:33 - 00003974 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A257EF5E-6C8E-4054-B281-CC22C7C170CC}
2015-05-15 20:06 - 2015-02-03 19:49 - 00000000 ____D () C:\rsit
2015-05-15 20:06 - 2015-02-03 19:49 - 00000000 ____D () C:\Program Files\trend micro
2015-05-15 19:56 - 2014-12-09 20:51 - 00172032 ___SH () C:\Users\darka_000\Downloads\Thumbs.db
2015-05-15 19:37 - 2014-11-19 14:32 - 00003600 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2802680610-4246973846-2910803817-1002
2015-05-15 19:30 - 2015-01-19 22:55 - 00000000 ____D () C:\Users\darka_000\AppData\Roaming\DAEMON Tools Lite
2015-05-15 19:30 - 2015-01-19 09:42 - 00000000 ____D () C:\WINDOWS\Minidump
2015-05-15 19:28 - 2015-01-09 09:02 - 00000844 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-05-15 19:28 - 2015-01-09 09:02 - 00000000 ____D () C:\Program Files\CCleaner
2015-05-15 18:42 - 2014-11-23 09:26 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-05-15 18:42 - 2014-11-23 09:26 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-05-15 18:42 - 2014-11-19 15:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-05-15 18:42 - 2013-08-22 16:44 - 05135872 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-05-15 17:16 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2015-05-15 17:16 - 2013-08-22 15:36 - 00000000 ____D () C:\WINDOWS\system32\AdvancedInstallers
2015-05-15 15:59 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-05-15 15:42 - 2014-11-19 22:04 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-05-15 15:41 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-05-15 15:31 - 2014-11-21 09:26 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-05-15 15:25 - 2014-11-21 09:26 - 140425016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-05-15 15:17 - 2014-11-23 09:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-15 15:12 - 2014-09-24 17:59 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-15 14:50 - 2014-09-24 18:23 - 01749406 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-05-15 14:50 - 2014-09-24 17:39 - 00740962 _____ () C:\WINDOWS\system32\perfh005.dat
2015-05-15 14:50 - 2014-09-24 17:39 - 00152146 _____ () C:\WINDOWS\system32\perfc005.dat
2015-05-14 10:34 - 2015-01-26 10:05 - 00000000 ____D () C:\Users\darka_000\Downloads\LP HD
2015-05-10 12:05 - 2014-11-28 11:59 - 00000000 ____D () C:\Users\darka_000\AppData\Roaming\vlc
2015-05-08 22:45 - 2014-12-12 15:34 - 00000000 ____D () C:\Users\darka_000\Desktop\MJ
2015-05-08 22:44 - 2014-12-26 21:54 - 00000132 _____ () C:\Users\darka_000\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2015-05-06 16:20 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-05-06 09:40 - 2014-11-19 15:07 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-04-30 15:04 - 2014-11-21 21:43 - 00000000 ____D () C:\Users\darka_000\Desktop\Ondra
2015-04-30 07:51 - 2014-11-19 21:32 - 00000000 ____D () C:\Users\darka_000\AppData\Roaming\Mp3tag
2015-04-29 19:23 - 2014-11-22 22:16 - 00000000 ____D () C:\Users\darka_000\Desktop\Dáda
2015-04-25 10:00 - 2014-12-06 00:19 - 00000000 ____D () C:\Users\darka_000\AppData\Local\Windows Live
2015-04-24 15:40 - 2014-11-19 15:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-04-22 09:59 - 2015-01-09 08:24 - 01047320 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-04-22 09:59 - 2015-01-09 08:24 - 00442264 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-04-22 09:59 - 2015-01-09 08:24 - 00272248 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-04-22 09:59 - 2015-01-09 08:24 - 00137288 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-04-22 09:59 - 2015-01-09 08:24 - 00093528 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-04-22 09:59 - 2015-01-09 08:24 - 00089944 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-04-22 09:59 - 2015-01-09 08:24 - 00065736 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-04-22 09:59 - 2015-01-09 08:24 - 00029168 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-04-20 11:11 - 2015-02-23 20:33 - 00000328 _____ () C:\Users\darka_000\Desktop\kul.txt
2015-04-18 10:50 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-04-16 18:23 - 2014-12-19 13:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-04-16 18:23 - 2014-12-19 13:08 - 00000000 ____D () C:\Program Files (x86)\Google
2015-04-16 18:23 - 2014-11-19 15:54 - 00001619 ____R () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Моzillа Firеfох.lnk
2015-04-16 18:23 - 2014-11-19 14:24 - 00001748 ____R () C:\Users\darka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Intеrnеt Ехplоrеr.lnk
2015-04-15 16:17 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppCompat
2015-04-15 15:45 - 2014-11-19 21:36 - 00003802 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-04-15 15:23 - 2012-07-26 07:26 - 00000269 _____ () C:\WINDOWS\win.ini
2015-04-15 15:21 - 2014-12-10 08:44 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-04-15 15:21 - 2014-09-24 21:02 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-04-15 15:00 - 2014-11-25 18:54 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll

==================== Files in the root of some directories =======

2014-12-26 21:54 - 2015-05-08 22:44 - 0000132 _____ () C:\Users\darka_000\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2015-01-17 14:16 - 2015-01-17 18:06 - 0001057 _____ () C:\Users\darka_000\AppData\Roaming\vso_ts_preview.xml
2014-12-17 22:18 - 2015-02-18 21:24 - 0009098 _____ () C:\Users\darka_000\AppData\Local\MRDownloader.err
2014-12-17 22:00 - 2015-04-13 17:05 - 0001112 _____ () C:\Users\darka_000\AppData\Local\MRDownloader.nast
2014-12-01 09:07 - 2015-01-13 20:09 - 0007604 _____ () C:\Users\darka_000\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-14 11:12

==================== End Of Log ============================

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#8 Příspěvek od darkane »

druhá část Additional

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-05-2015 02
Ran by darkane at 2015-05-15 22:37:33
Running from C:\Users\darka_000\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2802680610-4246973846-2910803817-500 - Administrator - Disabled)
darkane (S-1-5-21-2802680610-4246973846-2910803817-1002 - Administrator - Enabled) => C:\Users\darka_000
Guest (S-1-5-21-2802680610-4246973846-2910803817-501 - Limited - Disabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-2802680610-4246973846-2910803817-1004 - Limited - Enabled)
UpdatusUser (S-1-5-21-2802680610-4246973846-2910803817-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

„Windows Live Essentials“ (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
„Windows Live Mail“ (x32 Version: 16.4.3503.0728 - „Microsoft Corporation“) Hidden
„Windows Live Messenger“ (x32 Version: 16.4.3503.0728 - „Microsoft Corporation“) Hidden
4K Video Downloader 3.4 (HKLM-x32\...\4K Video Downloader_is1) (Version: 3.4.5.1525 - Open Media LLC)
Acronis Disk Director (HKLM-x32\...\{AE372858-B1BD-49EF-8308-648322846008}) (Version: 12.0.3223 - Acronis)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Audition CS6 (HKLM-x32\...\{30FD541D-3C9D-41C4-B240-A994EE4E0231}) (Version: 5.0 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
ASIO Proxy for foobar2000 (HKLM-x32\...\ASIOProxy) (Version: 0.7.2 - Maxim V.Anisiutkin)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.2.2218 - AVAST Software)
Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.1208.0301 - Micro-Star International Co., Ltd.)
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
BurnRecovery (HKLM-x32\...\{2892E1B7-E24D-4CCB-B8A7-B63D4B66F89F}) (Version: 4.0.1211.2101 - Micro-Star International Co., Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform)
ConvertXtoDVD 4.1.19.365 (HKLM-x32\...\{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1) (Version: 4.1.19.365 - )
CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4126.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0333 - Disc Soft Ltd)
Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EPSON SX430 Series Printer Uninstall (HKLM\...\EPSON SX430 Series) (Version: - SEIKO EPSON Corporation)
ETDWare PS/2-X64 11.13.0.2_WHQL (HKLM\...\Elantech) (Version: 11.13.0.2 - ELAN Microelectronic Corp.)
EZ CD Audio Converter (HKLM-x32\...\EZ CD Audio Converter) (Version: 2.4 - Poikosoft)
Fotoattēlu galerija (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Fotogaléria (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Fotogalerie (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Fotogalerii (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Fotogalerija (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Foto-galerija (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Fotogalleri (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Fotogalleriet (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Fotoğraf Galerisi (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Fotótár (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galeria de Fotografias (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galeria de Fotos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galeria fotografii (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galerie foto (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Galerija fotografija (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.152 - Google Inc.)
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1008 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1281 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3958 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{0728A184-F899-4356-B93D-8228674F0DEB}) (Version: 2.6.1209.0268 - Motorola Solutions, Inc.)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
KB9X Radio Switch Driver (HKLM\...\B16388B2E5D3CBA8F0EE88A8C5459BADAF4DE251) (Version: 1.0.7112.20593 - ENE TECHNOLOGY INC.)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Mozilla Firefox 37.0.2 (x86 cs) (HKLM-x32\...\Mozilla Firefox 37.0.2 (x86 cs)) (Version: 37.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.1.1 - Mozilla)
Mp3tag v2.69 (HKLM-x32\...\Mp3tag) (Version: v2.69 - Florian Heidenreich)
MSI Remind Manager (HKLM-x32\...\{7359585E-A828-4EFC-8177-7D1883DDA0B5}) (Version: 2.12.1003 - MSI)
NVIDIA Ovladače grafiky 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.02 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0604 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
Ovládací panel NVIDIA 327.02 (Version: 327.02 - NVIDIA Corporation) Hidden
PC Sound (HKLM\...\{3007FF9F-5B2C-41FF-8BFC-08BF25DB2681}) (Version: 1.12.2900 - SRS Labs, Inc.)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
Poczta usługi Windows Live (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Podstawowe programy Windows Live (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Pošta Windows Live (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Raccolta foto (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.2.612.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6728 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.30136 - Realtek Semiconductor Corp.)
ROBLOX Player for darkane (HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation)
ROBLOX Studio for darkane (HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version: - ROBLOX Corporation)
SAMSUNG Moblie USB Driver (HKLM\...\{8F110B6A-60A2-4542-BB19-AD6234E2969D}) (Version: 2.9.5.0916 - SAMSUNG Electronics Co., Ltd. )
SCM (HKLM\...\{FA8AB91A-0B41-4797-9015-9B3FBC7834CC}) (Version: 10.012.09132 - )
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Silverjuke 3.02 (HKLM-x32\...\Silverjuke) (Version: 3.02 - Bjoern Petersen Software Design and Development)
Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.010 - MSI)
System Control Manager (HKLM-x32\...\{ED9C5D25-55DF-48D8-9328-2AC0D75DE5D8}) (Version: 2.209.1106.005.10 - Micro-Star International Co., Ltd.)
TT-Dynamic-Range 1.4 (HKLM-x32\...\TT-Dynamic-Range 1.4) (Version: - )
Ulož.to File Manager verze 1.6 (HKLM-x32\...\{8190420D-F4BA-4744-8940-A466F81AF89C}_is1) (Version: 1.6 - Nodus Technologies s.r.o.)
Unity Web Player (HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS)
Valokuvavalikoima (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Driver Package - Intel (NETwNe64) net (09/12/2012 15.5.4.45) (HKLM\...\A007E57753F87B14A4737DA95057F173950A6A3D) (Version: 09/12/2012 15.5.4.45 - Intel)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation)
WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
WinX YouTube Downloader 3.2.3 (HKLM-x32\...\WinX YouTube Downloader_is1) (Version: - Digiarty Software, Inc.)
WinZip 16.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240D3}) (Version: 16.5.10095 - WinZip Computing, S.L. )
Συλλογή φωτογραφιών (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Основи Windows Live (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 16.4.3503.0728 - Корпорация Майкрософт) Hidden
Фотоальбом (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Фотогалерия (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Фотографии (общедоступная версия) (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
Фотоколекція (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
フォト ギャラリー (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
גלריית התמונות (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
معرض الصور (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
사진 갤러리 (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
影像中心 (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden
照片库 (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-2802680610-4246973846-2910803817-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)

==================== Restore Points =========================

29-04-2015 20:18:44 Naplánovaný kontrolní bod
08-05-2015 09:35:34 Naplánovaný kontrolní bod
15-05-2015 14:43:28 Naplánovaný kontrolní bod

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2015-05-15 21:03 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {203C624E-497C-40BC-92E9-DCBED2BC9B2C} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-24] (Microsoft Corporation)
Task: {299F97D2-4E37-4685-9DFE-B731A2EF3286} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-08] (Piriform Ltd)
Task: {2AF5793B-0E42-44CF-925C-85FDE16F7CC6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-04-22] (Avast Software s.r.o.)
Task: {2C3592BA-2EF3-4CD6-801E-AF77DA66FF67} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {71B41D3C-8B5A-40A4-894B-3B9AC5B4EFD0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19] (Google Inc.)
Task: {85995927-17ED-434A-B1E0-1939D76BFC86} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {9EF08CCF-D706-42D1-8CE9-0D539C13606D} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-15] (Adobe Systems Incorporated)
Task: {B8BC7EDC-3722-410E-9B59-D3D7CB5B7199} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-24] (Microsoft Corporation)
Task: {BC35E6C7-B617-4D31-B271-0BFE26E43759} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-05-15] (Microsoft Corporation)
Task: {E711AC47-7698-478F-B529-042FABBD0ECC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-19] (Google Inc.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2013-09-05 03:36 - 2013-09-05 03:36 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2015-04-22 09:59 - 2015-04-22 09:59 - 00104400 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-04-22 09:59 - 2015-04-22 09:59 - 00081728 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-05-15 20:08 - 2015-05-15 20:08 - 02929664 _____ () C:\Program Files\AVAST Software\Avast\defs\15051501\algo.dll
2015-04-22 09:59 - 2015-04-22 09:59 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-11-28 14:34 - 2014-11-28 14:34 - 00016384 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\PSIClient\1706c668394b6917a63634ebd3bedcf2\PSIClient.ni.dll
2012-11-29 00:31 - 2012-11-28 18:34 - 01198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, the associated entry will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
DNS Servers: 192.168.2.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run: => "BCSSync"
HKLM\...\StartupApproved\Run: => "Služba Acronis Scheduler2"
HKLM\...\StartupApproved\Run32: => "seznam-listicka-distribuce"
HKLM\...\StartupApproved\Run32: => "AdobeCS6ServiceManager"
HKLM\...\StartupApproved\Run32: => "SwitchBoard"
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\StartupApproved\StartupFolder: => "default-3d.lnk"
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\StartupApproved\Run: => "OfficeSyncProcess"
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\StartupApproved\Run: => "cz.seznam.software.autoupdate"
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\StartupApproved\Run: => "cz.seznam.software.szndesktop"
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\StartupApproved\Run: => "DAEMON Tools Lite"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [UDP Query User{057CDDCB-0215-4224-8D37-9042F0FCAC6C}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [TCP Query User{019AB0C5-DCD4-49B5-9D3C-BFE17FA9EFBB}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe
FirewallRules: [{B66A8579-2729-4C5C-A1CD-4A5DEE91E12B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{4516328A-0F0D-4FC2-9AB1-5999F058119B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{1028F54E-54D0-4577-9F95-744F03B14FF1}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{9A722CA2-2EF1-415B-B175-36D098867DE7}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{208ACDB2-28E4-4353-BD22-6B3E1A5C3959}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{80E6F86B-D6D4-4DF1-8570-4C1244947B39}] => (Allow) LPort=1900
FirewallRules: [{0AFD600E-FFF2-437F-8C98-1AD7404A2264}] => (Allow) LPort=2869
FirewallRules: [{0598FD00-2DAA-46D2-A321-586DCC771AAE}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [TCP Query User{60BE0928-342E-493C-9C2E-F3F06FDECF4E}C:\program files\microsoft office\office14\groove.exe] => (Block) C:\program files\microsoft office\office14\groove.exe
FirewallRules: [UDP Query User{938FF914-6576-4DA8-B523-69DEFA95B75C}C:\program files\microsoft office\office14\groove.exe] => (Block) C:\program files\microsoft office\office14\groove.exe
FirewallRules: [TCP Query User{475ECA3D-6E3E-4DF7-A1AE-A670040D0D9D}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{821025A1-CAAB-4860-9987-910B3C6FD365}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{8D819DD3-5F52-4A67-9B6C-E995FA989F7C}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Allow) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [UDP Query User{3E14533A-2142-4828-8E0F-95FE860880E6}C:\program files (x86)\mozilla firefox\plugin-container.exe] => (Allow) C:\program files (x86)\mozilla firefox\plugin-container.exe
FirewallRules: [{7AC5D066-D2EB-43DE-8757-76DDE203258D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{28138A78-06FD-4EFA-A1E9-13D73B555417}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{363D2F68-3291-44B4-82A6-F366AD01DE14}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{60B5E025-00B5-449B-A60E-910296044441}C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_25\bin\javaw.exe
FirewallRules: [{E6AA6E0F-20B3-4DC2-B5F1-B96FFEC373FA}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{D3ADD8EE-3A3E-4AE3-8048-C27C326846DA}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [TCP Query User{EA5B26B4-B28F-4CEB-AC9E-50A7FD24FAB0}E:\flatout 2\flatout2.exe] => (Block) E:\flatout 2\flatout2.exe
FirewallRules: [UDP Query User{7B3B1BC6-3F54-47C7-885B-1883D5B176EF}E:\flatout 2\flatout2.exe] => (Block) E:\flatout 2\flatout2.exe
FirewallRules: [TCP Query User{FDB0CCE1-C2C5-48FB-A36F-752E7F829AD4}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{122517E8-F40B-4FF7-90B7-E6DDF448C768}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{482712E0-78F7-4641-A81B-96C62962EFD6}E:\easysetupassistant\tl-wr1043nd\easysetupassistant.exe] => (Allow) E:\easysetupassistant\tl-wr1043nd\easysetupassistant.exe
FirewallRules: [UDP Query User{09E439C7-F4A9-42AF-A230-3558FB784DF2}E:\easysetupassistant\tl-wr1043nd\easysetupassistant.exe] => (Allow) E:\easysetupassistant\tl-wr1043nd\easysetupassistant.exe
FirewallRules: [TCP Query User{1E3A4963-5001-4386-9922-BD4C9CDB69C7}C:\program files (x86)\videolan\vlc\vlc.exe] => (Block) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{81DB6301-A511-4F57-B46C-DDE77ABD7659}C:\program files (x86)\videolan\vlc\vlc.exe] => (Block) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [{14763D3E-477D-46A3-A097-67F7FF836751}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{5EFC6A58-F2A1-46C2-B267-330FED052F5C}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{CED39A75-8960-40CE-89A6-8C6B0D3EBB27}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Index nebyl inicializován.

Podrobnosti:
Zadaný objekt nebyl nalezen. Zadejte název existujícího objektu. (HRESULT : 0x80040d06) (0x80040d06)

Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Aplikace nebyla inicializována.

Kontext: aplikace Windows

Podrobnosti:
Zadaný objekt nebyl nalezen. Zadejte název existujícího objektu. (HRESULT : 0x80040d06) (0x80040d06)

Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Objekt indexovacího modulu nebyl inicializován.

Kontext: aplikace Windows, katalog SystemIndex

Podrobnosti:
Zadaný objekt nebyl nalezen. Zadejte název existujícího objektu. (HRESULT : 0x80040d06) (0x80040d06)

Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Modul plug-in v <Search.TripoliIndexer> nebyl inicializován.

Kontext: aplikace Windows, katalog SystemIndex

Podrobnosti:
Zadaný objekt nebyl nalezen. Zadejte název existujícího objektu. (HRESULT : 0x80040d06) (0x80040d06)

Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 3057) (User: )
Description: Správce modulu plug-in <Search.TripoliIndexer> nebyl inicializován.

Kontext: aplikace Windows

Podrobnosti:
(HRESULT : 0x8e5e0210) (0x8e5e0210)

Error: (05/15/2015 08:41:48 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Služba Windows Search byla zastavena, protože došlo k problému s indexovacím modulem The catalog is corrupt.

Podrobnosti:
Katalog indexu obsahu je poškozený. 0xc0041801 (0xc0041801)

Error: (05/15/2015 08:41:48 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Vyhledávací služby zjistila, že index {id=4810 - enduser\mssearch2\search\ytrip\common\util\jetutil.cpp (167)} obsahuje poškozené datové soubory. Služba se pokusí tyto potíže automaticky odstranit vytvořením nového indexu.

Podrobnosti:
0x8e5e0210 (0x8e5e0210)

Error: (05/15/2015 08:41:48 PM) (Source: ESENT) (EventID: 455) (User: )
Description: SearchIndexer (1920) Windows: Při otevírání souboru protokolu C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb020F2.log došlo k chybě -1811 (0xfffff8ed).

Error: (05/11/2015 02:26:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Explorer.EXE verze 6.3.9600.17667 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.

ID procesu: c5c

Čas spuštění: 01d08bab56d539b2

Čas ukončení: 0

Cesta k aplikaci: C:\WINDOWS\Explorer.EXE

ID hlášení: bae8eeaf-f7d8-11e4-bf2e-8c89a5083c00

Úplný název chybujícího balíčku:

ID aplikace související s chybujícím balíčkem:

Error: (05/01/2015 00:45:12 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: There was an error with the Windows Location Provider database


System errors:
=============
Error: (05/15/2015 10:08:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba NVIDIA Update Service Daemon neuspěla při spuštění v důsledku následující chyby:
%%1069

Error: (05/15/2015 10:08:40 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba nvUpdatusService se nemohla přihlásit jako .\UpdatusUser s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%1326

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (05/15/2015 09:53:36 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (05/15/2015 09:53:35 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (05/15/2015 09:53:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (05/15/2015 09:53:34 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (05/15/2015 09:53:33 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (05/15/2015 08:46:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba NVIDIA Update Service Daemon neuspěla při spuštění v důsledku následující chyby:
%%1069

Error: (05/15/2015 08:46:23 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba nvUpdatusService se nemohla přihlásit jako .\UpdatusUser s aktuálně konfigurovaným heslem z důvodu následující chyby:
%%1326

Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (05/15/2015 08:42:42 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správce služeb se pokusil o opravnou akci (Restartovat službu) po nečekaném ukončení služby Windows Search, ale tato akce selhala kvůli následující chybě:
%%1056


Microsoft Office Sessions:
=========================
Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: Podrobnosti:
Zadaný objekt nebyl nalezen. Zadejte název existujícího objektu. (HRESULT : 0x80040d06) (0x80040d06)

Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: Kontext: aplikace Windows

Podrobnosti:
Zadaný objekt nebyl nalezen. Zadejte název existujícího objektu. (HRESULT : 0x80040d06) (0x80040d06)

Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Kontext: aplikace Windows, katalog SystemIndex

Podrobnosti:
Zadaný objekt nebyl nalezen. Zadejte název existujícího objektu. (HRESULT : 0x80040d06) (0x80040d06)

Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: Kontext: aplikace Windows, katalog SystemIndex

Podrobnosti:
Zadaný objekt nebyl nalezen. Zadejte název existujícího objektu. (HRESULT : 0x80040d06) (0x80040d06)
Search.TripoliIndexer

Error: (05/15/2015 08:41:49 PM) (Source: Windows Search Service) (EventID: 3057) (User: )
Description: Kontext: aplikace Windows

Podrobnosti:
(HRESULT : 0x8e5e0210) (0x8e5e0210)
Search.TripoliIndexer

Error: (05/15/2015 08:41:48 PM) (Source: Windows Search Service) (EventID: 7042) (User: )
Description: Podrobnosti:
Katalog indexu obsahu je poškozený. 0xc0041801 (0xc0041801)
The catalog is corrupt

Error: (05/15/2015 08:41:48 PM) (Source: Windows Search Service) (EventID: 7040) (User: )
Description: Podrobnosti:
0x8e5e0210 (0x8e5e0210)
4810 - enduser\mssearch2\search\ytrip\common\util\jetutil.cpp (167)

Error: (05/15/2015 08:41:48 PM) (Source: ESENT) (EventID: 455) (User: )
Description: SearchIndexer1920Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb020F2.log-1811 (0xfffff8ed)

Error: (05/11/2015 02:26:18 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Explorer.EXE6.3.9600.17667c5c01d08bab56d539b20C:\WINDOWS\Explorer.EXEbae8eeaf-f7d8-11e4-bf2e-8c89a5083c00

Error: (05/01/2015 00:45:12 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: -2147024883


CodeIntegrity Errors:
===================================
Date: 2015-01-08 20:43:51.523
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-01-08 20:43:51.335
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-01-08 20:43:51.163
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-01-08 20:43:50.991
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-01-08 20:43:50.790
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-01-08 20:43:50.619
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-01-08 20:43:50.407
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-01-08 20:43:50.220
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-01-08 20:43:50.017
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-01-08 20:43:49.830
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
Percentage of memory in use: 21%
Total physical RAM: 8081.44 MB
Available physical RAM: 6325.19 MB
Total Pagefile: 16273.44 MB
Available Pagefile: 14443.32 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB

==================== Drives ================================

Drive c: (OS_Install) (Fixed) (Total:474.29 GB) (Free:214.67 GB) NTFS
Drive d: (Data) (Fixed) (Total:201.96 GB) (Free:49.43 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: AC38BDF4)

Partition: GPT Partition Type.

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#9 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
    HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8202008 2015-04-08] (Piriform Ltd)
    HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk [2012-11-29]
    Startup: C:\Users\darka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\default-3d.lnk [2015-02-02]
    
    URLSearchHook: [S-1-5-21-2802680610-4246973846-2910803817-1002] ATTENTION ==> Default URLSearchHook is missing.
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    DefaultPrefix-x32: => http://yamdex.net/?searchid=1&l10n=ru&f ... 354d&text= <==== ATTENTION
    
    2015-05-15 22:36 - 2015-05-15 22:36 - 00017627 _____ () C:\Users\darka_000\Desktop\FRST.txt
    2015-05-15 22:04 - 2015-05-15 22:04 - 00000330 _____ () C:\WINDOWS\PFRO.log
    2015-05-15 22:02 - 2015-05-15 21:01 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
    2015-05-15 21:02 - 2015-05-15 22:05 - 00026191 _____ () C:\zoek-results.log
    2015-05-15 21:01 - 2015-05-15 21:54 - 00000000 ____D () C:\zoek_backup
    2015-05-15 21:00 - 2015-05-15 21:00 - 01308672 _____ () C:\Users\darka_000\Desktop\zoek.exe
    2015-05-15 20:43 - 2015-05-15 22:04 - 00000154 _____ () C:\WINDOWS\setupact.log
    2015-05-15 20:43 - 2015-05-15 20:43 - 00000000 _____ () C:\WINDOWS\setuperr.log
    2015-05-15 20:38 - 2015-05-15 20:38 - 02209792 _____ () C:\Users\darka_000\Desktop\adwcleaner_4.204.exe
    2015-05-15 20:05 - 2015-05-15 20:05 - 01222144 _____ () C:\Users\darka_000\Desktop\RSITx64.exe
    2015-04-16 18:23 - 2015-04-16 18:24 - 00000109 ____H () C:\iexplore.bat
    2015-04-16 18:23 - 2015-04-16 18:24 - 00000108 ____H () C:\firefox.bat
    2015-04-16 15:10 - 2015-04-16 15:12 - 00000197 _____ () C:\WINDOWS\system32\2015-04-16-13-10-28.082-AvastVBoxSVC.exe-3888.log
    2015-04-16 08:28 - 2015-04-16 08:28 - 00000197 _____ () C:\WINDOWS\system32\2015-04-16-06-28-32.088-AvastVBoxSVC.exe-2768.log
    2015-05-15 20:06 - 2015-02-03 19:49 - 00000000 ____D () C:\rsit
    2015-05-15 20:06 - 2015-02-03 19:49 - 00000000 ____D () C:\Program Files\trend micro
    
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#10 Příspěvek od darkane »

fixlog zde :)

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-05-2015 02
Ran by darkane at 2015-05-15 23:01:14 Run:1
Running from C:\Users\darka_000\Desktop
Loaded Profiles: darkane (Available profiles: UpdatusUser & darkane & Guest)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8202008 2015-04-08] (Piriform Ltd)
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk [2012-11-29]
Startup: C:\Users\darka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\default-3d.lnk [2015-02-02]

URLSearchHook: [S-1-5-21-2802680610-4246973846-2910803817-1002] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
DefaultPrefix-x32: => http://yamdex.net/?searchid=1&l10n=ru&f ... 354d&text= <==== ATTENTION

2015-05-15 22:36 - 2015-05-15 22:36 - 00017627 _____ () C:\Users\darka_000\Desktop\FRST.txt
2015-05-15 22:04 - 2015-05-15 22:04 - 00000330 _____ () C:\WINDOWS\PFRO.log
2015-05-15 22:02 - 2015-05-15 21:01 - 00024064 _____ () C:\WINDOWS\zoek-delete.exe
2015-05-15 21:02 - 2015-05-15 22:05 - 00026191 _____ () C:\zoek-results.log
2015-05-15 21:01 - 2015-05-15 21:54 - 00000000 ____D () C:\zoek_backup
2015-05-15 21:00 - 2015-05-15 21:00 - 01308672 _____ () C:\Users\darka_000\Desktop\zoek.exe
2015-05-15 20:43 - 2015-05-15 22:04 - 00000154 _____ () C:\WINDOWS\setupact.log
2015-05-15 20:43 - 2015-05-15 20:43 - 00000000 _____ () C:\WINDOWS\setuperr.log
2015-05-15 20:38 - 2015-05-15 20:38 - 02209792 _____ () C:\Users\darka_000\Desktop\adwcleaner_4.204.exe
2015-05-15 20:05 - 2015-05-15 20:05 - 01222144 _____ () C:\Users\darka_000\Desktop\RSITx64.exe
2015-04-16 18:23 - 2015-04-16 18:24 - 00000109 ____H () C:\iexplore.bat
2015-04-16 18:23 - 2015-04-16 18:24 - 00000108 ____H () C:\firefox.bat
2015-04-16 15:10 - 2015-04-16 15:12 - 00000197 _____ () C:\WINDOWS\system32\2015-04-16-13-10-28.082-AvastVBoxSVC.exe-3888.log
2015-04-16 08:28 - 2015-04-16 08:28 - 00000197 _____ () C:\WINDOWS\system32\2015-04-16-06-28-32.088-AvastVBoxSVC.exe-2768.log
2015-05-15 20:06 - 2015-02-03 19:49 - 00000000 ____D () C:\rsit
2015-05-15 20:06 - 2015-02-03 19:49 - 00000000 ____D () C:\Program Files\trend micro

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\RemoteControl10 => value deleted successfully.
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
HKU\S-1-5-21-2802680610-4246973846-2910803817-1002\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk => Moved successfully.
C:\Users\darka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\default-3d.lnk => Moved successfully.
Error setting Default URLSearchHook.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix\\Default => Value was restored successfully.
"C:\Users\darka_000\Desktop\FRST.txt" => File/Directory not found.
C:\WINDOWS\PFRO.log => Moved successfully.
C:\WINDOWS\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\darka_000\Desktop\zoek.exe => Moved successfully.
C:\WINDOWS\setupact.log => Moved successfully.
C:\WINDOWS\setuperr.log => Moved successfully.
C:\Users\darka_000\Desktop\adwcleaner_4.204.exe => Moved successfully.
C:\Users\darka_000\Desktop\RSITx64.exe => Moved successfully.
C:\iexplore.bat => Moved successfully.
C:\firefox.bat => Moved successfully.
C:\WINDOWS\system32\2015-04-16-13-10-28.082-AvastVBoxSVC.exe-3888.log => Moved successfully.
C:\WINDOWS\system32\2015-04-16-06-28-32.088-AvastVBoxSVC.exe-2768.log => Moved successfully.
C:\rsit => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 56.4 MB temporary data.


The system needed a reboot.

==== End of Fixlog 23:02:09 ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#11 Příspěvek od vyosek »

Jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#12 Příspěvek od darkane »

zdravím :)
Dostal jsem se k ntb až nyní a po krátké prohlídce mi připadá vše v pořádku. Měl jsem ntb hodně zaneřáděn? V poslední době jsem se mu moc nevěnoval.
mockrát děkuji :worship:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#13 Příspěvek od vyosek »

Tak jeste uklidime :James008:

:arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remove disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner https://www.piriform.com/ccleaner/download/standard
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

darkane
Návštěvník
Návštěvník
Příspěvky: 96
Registrován: 19 říj 2006 08:06

Re: Prosím o kontrolu logu

#14 Příspěvek od darkane »

Uklizeno a vyčištěno.
Ještě jednou mockrát děkuji. :)
:worship: :worship: :worship: :worship:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Prosím o kontrolu logu

#15 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :worship: Zase nekdy :)


A na zaklade Pravidla o zamykani temat :lock:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno