Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivní kontrola logu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Alice
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 08 kvě 2015 11:02

Preventivní kontrola logu

#1 Příspěvek od Alice »

Dobrý den, moc bych chtěla poprosit o preventivní kontrolu logu mého NTBku, nic zvláštního na něm nepozoruji, ale jistota je jistota :) Děkuji

Logfile of random's system information tool 1.10 (written by random/random)
Run by KoulovaA at 2015-07-04 14:57:30
Microsoft Windows 8.1 s aplikací Bing
System drive C: has 176 GB (38%) free of 459 GB
Total RAM: 3984 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:57:40, on 4. 7. 2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\KoulovaA.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.search.ask.com/?tpid=ATUSP-S ... psv=&pt=tb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Search App by Ask BHO - {41545534-2D53-5000-76A7-7A786E7484D7} - (no file)
O2 - BHO: Shopping App by Ask BHO - {41545553-502D-5341-5400-7A786E7484D7} - (no file)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: DVDVideoSoft.WebPageAdjuster - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [mcpltui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\RunOnce: [20150107] C:\Program Files\AVAST Software\Avast\setup\emupdate\71d5f7a4-4254-4c48-bd30-7b9448c2bbbe.exe /check
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKUS\S-1-5-21-2592885859-3292131433-3858698835-1002\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q (User 'Kotyna')
O4 - HKUS\S-1-5-21-2592885859-3292131433-3858698835-1002\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Kotyna\AppData\Roaming\Seznam.cz\szninstall.exe" -c (User 'Kotyna')
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - Avast Software s.r.o. - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Home Network (HomeNetSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee AP Service (McAPExe) - McAfee, Inc. - C:\Program Files\McAfee\MSC\McAPExe.exe
O23 - Service: McAfee Activation Service (McAWFwk) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee Platform Services (mcpltsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Anti-Malware Core (mfecore) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: @C:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - C:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\SysWOW64\ssins.exe
O23 - Service: AVG PC TuneUp Service (TuneUp.UtilitiesSvc) - AVG Technologies - C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14266 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 597651660912
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
C:\Windows\system32\svchost.exe -k apphost
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\System32\svchost.exe -k utcsvc
dashost.exe {68e4aa2e-7941-4773-818324a23166af39}
"C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe"
"C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe"
"C:\Windows\system32\mfevtps.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Windows\SysWOW64\ssins.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe"
"C:\Program Files\McAfee\MSC\McAPExe.exe"
"C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe"
"C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe"
"C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc
C:\Windows\system32\svchost.exe -k WbioSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\wmiprvse.exe
taskhostex.exe
"C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe" /TUStart /pid:2148
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Windows\system32\GWX\GWX.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Windows\system32\igfxsrvc.exe" -Embedding
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
"C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe" /hideui
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobroker.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobrokerdsktop.exe"
szndesktop.exe default start
"C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe"
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe" /platui /runkey
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files (x86)\Nero\Update\NASvc.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4964.0.437376937\1471932990" --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,21,44 --gpu-vendor-id=0x8086 --gpu-device-id=0x0f31 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3408 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AutofillEnabled/Default/BackgroundRendererProcesses/AllowIdleFromBrowser/BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.1.1895887664\209997590" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AutofillEnabled/Default/BackgroundRendererProcesses/AllowIdleFromBrowser/BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.2.803290505\1173313790" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.3.1198919985\1038071272" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.7.1844803361\907570345" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.9.1551103500\79697507" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.10.1607478876\2021362022" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.11.337179722\1298535983" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.12.1651706986\1781738405" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="4964.13.467151051\856986984" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.14.205622119\997449328" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.15.1997770670\1920929018" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.16.706172863\1788339964" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.17.1507301693\372805373" /prefetch:673131151

"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.18.133429916\830391819" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.19.1494136708\1869049608" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.20.1653584029\1475092152" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.21.546448798\367443998" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/*AutofillEnabled/Default/*BackgroundRendererProcesses/AllowIdleFromBrowser/*BrowserBlacklist/Enabled/*CTRequiredForEVTrial/RequirementEnforced/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*DomRel-Enable/enable/*EmbeddedSearch/Group2 pct:10b stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/*NewProfileManagement/Enabled/*OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/*PasswordGeneration/Disabled/PasswordLinkInSettings/Disabled/PermissionBubbleRollout/Enabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/*RememberCertificateErrorDecisions/OneWeek/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/*SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/SyncBackingDatabase32K/Disabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_27/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_03/*UMA-Uniformity-Trial-50-Percent/group_01/*UseDelayAgnosticAEC/DefaultEnabled/*VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/*Win32kLockdown/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --font-cache-shared-mem-suffix=4964 --enable-pinch-virtual-viewport --enable-delegated-renderer --num-raster-threads=1 --use-image-texture-target=3553 --channel="4964.23.1654986580\1581857389" /prefetch:673131151
taskeng.exe {F7C85846-954A-4E5A-90D7-4C4CD9FB1937}
"C:\Users\Kotyna\Downloads\RSITx64(1).exe"
C:\Windows\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}

======Scheduled tasks folder======

C:\Windows\tasks\7eca1cd8-2a95-4759-9c0f-ae713062040a-1.job - C:\Program Files (x86)\Super Radio\Super Radio-codedownloader.exe /rawdata=t+NzJ+LOlW/62gHhzN4LzgD0G9eX5qxESJzRBK+aseCGibhBframOvg51wSi9B7oHHEEOC2v0vJ2Zhz3PYqQ0LauDiVMuHrXWcN3W4XsCzVJgnEpbIs7g2mD3Ex2Pl7+6GTg/FzFOQNvztx4u0o6/wTcDcupJPb334hwk8/7uEMt2n1GZv0BLKznS65kyxJDY9cItpCZQjc5K16eGlrxFDDojyNQ7XKyPuS0R3w6RtxZ/WK4wdCInXI91iAFk6BlH0FIXCFxRFetr8mlvQ+CskJiWQNc26/jD6Hyb5C+YuZnMWKupQ6IdzlLj+eCPMrUfAPb2SfqMAqHVSJOIrsN38UY3NybnXM6C8IpXkLjRwfaRexGYPUbgdRN6WH+IVZ1boTUDIzgxLXaZF3/2iz4zL9iDTY2wDN6nn/frwtSSLYqKx51X9roqN9syj+ky4FY3QwYJdejog1yUFt5kJOQ8SXu9flbx6ieTflEJc/XFt5V77VinL8sjiQ7Am6mkFaXL/MZV0etsufP+TakAtTKsjQq5QMlDgCVRRZ2C4yCDS1TaITQX33ueFSG6Z/8u76mzfjZASxy5bEuiHjZ3Pq2x6IM8s4vAmvmc9W+Stp8MPlXwFX2uzJ6+9jz1LnN63rC8CTxiOFuDh99rFNTlTPHwo8gkHUBVEjeXBcnt6INVhqOcuCymmiyrqMcoush5R6bSibEOMpDDvlz3ran5aTsUUiTUR0sIPij3aLNe7GZnW8aseRmuEcBoz4HXxZSzJkcz6uyaA/R3ui6ElPwsjf0OZq+GG89SuJF+WllKgKyvmCQcOOZD7tkWnfZYArMb/hJEugebG0LEffs0J3dVzTi5W7Twg2tJwO5afg2CYLH+ztYi7xP4jNadDIGtH1hc5buW1pNqJD9My7gS3JvNnnwC2Ei9jCLOB6wCHijWDCawuIjsCVpvkviSFuqCBRQOcLe8az4Xb9iBps6n9Nlyf7Nrkf0SExP0ugYd1186UnRYri7gPkKwtEzgGIOMvFVpixXhaMlI+aR5paHHfRunFTXGB+ATxYAQj1FUeUsMJD9nyQiUfz1RXsAtsmjq51Yg1RKyGHBZ9nZQ0KTiyIIg4kdqyJa9KLLhI1V8cDfyqpIYNxBUj0tuV9e1WOocjpCSBnwywAr+ixn1ABjQ8N82ZIUl4W/F8tSuRoR0H6CGwEUaTBVRaAkMIcan3Kz+ysBUtrhQ9Z48DS3PmSlOxs9uXt7PDhhkt3SsLuZpp+apxSQRVIfy4m4QTyT8UbtzegYEW8fy2KYPHb4M+RiscqCL+eONMHlIGXWNzuNrmVnFtOLpQ/2ILXjXxatQ5DI6TLG3316ZTosgC5SymqqqPrjC0Ua4Q==
C:\Windows\tasks\7eca1cd8-2a95-4759-9c0f-ae713062040a-11.job - C:\Program Files (x86)\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-11.exe /rawdata=W7Nrj1tkMh8/LSaQcfVJID08lkO2uwT71W+ARff0nCqGVeDSqlJrg7cPUhwdUPiJDL0sIJL0MxTvyZLhc4hc4+duZR1bA+MVFl3PRWaeOD9BJpmVkWOp9dya6ETcFWAEQmTwV7eC0tu5pQK4l+nqjVoJQD+8tMqRextdJ44WADCZqvwVn12mXuETJXo7P0meYNAH2y0YzCPzfzquTnxnk2eDsG+uN1OzkF5m+EqspvvH8C01oCQ8KxgTYAAffR8LtLyQW9Xd+hmkh7JM/Ssn7tDZUoWHkmSCzjFthuxZ8tVVgNYeJJ6tgrt5SptBqTnrx4KKjNXEZMT4SD6l3iyRLycEh0XtCRL5Lwya+eYHG1FL5dy005u0+fXgtBfx8yPW6sXgT0v1OF0JRe3nB15Pzez0+Cm3rkPvInNiB0EH+dawQ/htP9LO365fcBdF51IF8mOsr79wzwEeQeWE0ZkXb7CbhRS+n9mdczKEytLg88qUqgbjmRewOfq73sYIUfEVsc0j1+9WBNsaZ48121SrShqwU7bm214eAVloo/FQZJqTq/ChcE8Lde89RkWbGRrtr3XTDDslNV0hO1iqWD7rAaCms6wCQxmGWMFGtTsB05Jp/ryWOmjRFrfDcT8ALu8BpCfGf13wmPjwyp8ujlhQcFdqNN1gy/6evf4mMSjlc2ZwvT9yXOJyu+/titulXC4EOKInYFzmyBfr2fLoyhZbsfXVL+8q/vbZSlaAPYQSIvzoAM2HiEOYQqM3ONMB30PirasvIz0lkPskg6WX4DtfYL2BxXGyVc9UEoLjDf/NVnYp4G07+m31TQSzG3LsHtbI82YknQxt4NKbEqQZPTOUj2XPIvSmtZqF1/piTzVLXM6n1pPs/NvBa48vTc0oXWau6BdDkYGGdDFzJT3bDvIU61sPp7H5G6Z1giDaoyD9M+d7rNV1WbpZAQ2rpdCbl4liIqYAD0OggCsG3IthO4TZaiVred8zMKLq5WMTCongjr0GI4yjVPFGJiJwLwukxZQicoY7KJYVRohj3IwnAhFAhYsU+T79fLo4h28l+4Nq8ZJnUgyBTWPC9WNoG5kFUhCXUYdnQO9jSUly/I1YEWPjHKQc1vHrXLaR6+u/v4OOpqKHLPrG4C0AwNIArJuTEhEyUVGUC+RnLPsbfR+INhSe1wi8KcJxViAubGqQqYC16tVx/ecTFYFCP5OIzMHjYS648Si0KoTVp9TaATG7PFEjRRwmc2xe0h8RArJzXkn/j3QwtJswoJxl0IjUM1G+Nzc1oNkrloE6lyt+dajOLaGB5oV3iryUxDOVq90Tm7ygtVSPaEVnaELT5+qPtEqY1X05tri0xZeWMZJ/MhpircibEV3kVqQ7OJPnMQedQTtTHlihmyLlqPyPCIfeiDtvigeIy1P+4yJGAxZrIX2jBklnQKP3gbujubZediyQS2oY8+TomeMTzB2lpY3kZ4XWe2lNH4W+7dNnZikaCjT/zeARSCZKN/LYh53VaDfp+A0HUH9OTwtRNZu0j2/9FnmvC/zPX/0QvZmYk5Kbt0rZys1ujXD03DSgRIqPZTgSpoA0zrgREEPHmxiPzCysTmYSXMY1YyVyhZRwprVf+NZ5lia3L4gNnqx/x7DHPPdCs59WgX4Zmds50h/eh63sYBgzdNljC+ePvp+tojSB3+Uk9FLvuOn/JX/vG4sD87vtSdOxTg2M4j3jXkEKSzTMycUfi+5nWjWD+ooAVuOhANU744SRMYYMx4ydhogEYpZpgd0NzM0sqJFzxq/vSyReXtVt0Dk+t4tPIl5GzfxXoOtapqDn4HcM3QpgXKFB2oXOzYPabuqmtLP9aZXzky75LFBjfoBdAX+hFnUzjioUBvdLbvixDsXYG/C/tLuZ1VlWRdAmJZnA6V/cw/zHblc6wHJOHJOZMlFHLZ35tllSPPqx7TpwjJcvrF99VZbuqdR3fYThd0U+cXEXoivyjZkBOS22OQGVKAMlVwV/KLAtroDe2ver3ayqZC8dkcFPkK5EeokrSIdp1CdgTkC7O0/PI+1UQEMDQOtyoZ14H/kIRp+Pg04RMYZKPvaAzc4nksrxV9XbRrYn3I5hgYIO0L4c04q40+wGCROryH6TZzfIYfB84BQHFnQNHPmwv4ENpC26YNytT8/V0p9pghDn7EUApMN0pQOZvVCxIui6/tZ2e09eZjX56zlC490F7x4BsElVGsbZXOtQtVnatKnOXK2PmUu8p7CpyQK6W5aqmFCOd2dEVlM2JI6TTrTJasrCu89KfxFLpFSve6xTMAgLHNi/L/EwGDDMBJW6nrW2uKIBT3Ae0iXUVfCtOCDApbt8rUN9jXIuFfkF/zbODhVtZ3l0rqc66bW/tBomhm7JLWUFCL11jssu2A==
C:\Windows\tasks\7eca1cd8-2a95-4759-9c0f-ae713062040a-4.job - C:\Program Files (x86)\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-4.exe /rawdata=W0hkQ30+YF7pW6bh0Hsv8pwnEho7JI3Rk/KWo5fsU4NDCYWDhLZPmcopCG9bNH/OjEu6dDCm3qjfZACWEbuTDo47SZthIspMTzdS574iA9nZHT0P8qxje9617uHm3jNDXkOANf1Llr7E5F6rUiLWlBkK64cbo7tXgnUgbom8BreB0VU+fWZ+79mTSuIVqe4jPsvJ/jJmgWy5ip1y2IL4JikVucsg8TO9imsJ+RrYNiA1WBl8nM8EVyL/dK08FogBk4/K2l9vKgI8GZbRm2+RvxuHaCfJvEWbjLI/cyGmm+HAvN6reXf7LYxSMeFI55wIl+wNpfxcLWutEdNRNix3WK6p98QC7KSrxAzDRul/heTQkZeXWgEsxafVyOCSEMQsVOYyP1JKJXEFVIHiq4mj9/asxKCbJeViYX34aAyLNz+G31FchUi0wsJ4cfL6P+g4dARTxWyUAZ7XF27weqQ4cM4gSNF2YquZ6WKaRTL4zKQN+vjdr7xsh5aUXg8OfiY1cqTplY81NcvbHVcDGPCfvaluxpkv9h09jhGoZfFPEoGI913Y6PPrG6oRCGuTsL9CZ1kNQkyJ/vGfeiQ/wlqL5FXddh8l4/GDI9WBF/z3luKB01xkRtLFgT7sh4NnsC453u0gyuNmfdC//+6cjqKV1x0f/DYzWfZhVMQvGWOocDWs2DP5RdlxJWVM23VYAeA5ln3U4vd/TMLCSN5EBEn7zCTlYAGtc1GZG4m92rJjwM0L2uECXRV2cQutdO0TzKZBc4sSWV6brcyvrZGwVBeuF0zyB4hjNsjnMEolMgJ5dlxMSZmbOvQXNpjpFTrc2b2TCcyjXnZVHdHPd08spwOudbUAJPeUAWwJKf84mWAgN4EnGAFWGYGIQ5ybh9t9rN+kT1o56QyZIzAAjh/bHSPlDH4hm9pn4evd+VdsycN92Z+9U6/cTN2mBuPxCN27huEYm3YTfZCn+So+QW7VPPzaTM4DomMaYRK5NQBM861Dao95yRh+zs5mIc0G9jt2DRdHoou+nBlGRAjq0JLQZSOAeoXvQGtQW9Kt3q9w7fh9A0H/6q0C5dUf8wfqdNaVyP9sIiag6yBABA0g2KxD8Xcx6wsJvfw1MJfBFKZ+d4RjN3mRhki4aTh0QATtN4BGs08+1lrsbT071KMlIaHYDLnkdLByRc0CWe10yhgjE7XYkgEHgJ5fQ2vEvL8V3qLuqYutPVETsBq+qmUQA3vYGX7egTNEUtjiiK+XdLLl9ftT8n7qmhW/NNIeHHtJbTZCkUWv/Nt2JX1DmH6JW8SOF4AURvjJMWYlZbNrJJf1EsOwDQtlafffm6t861DV5mNyqVEyinKr/wMzuznr77kW2/PC9G7Twg2tJwO5afg2CYLH+ztYi7xP4jNadDIGtH1hc5buW1pNqJD9My7gS3JvNnnwC2Ei9jCLOB6wCHijWDCawuIjsCVpvkviSFuqCBRQOcLe8az4Xb9iBps6n9Nlyf7Nrkf0SExP0ugYd1186UnRYri7gPkKwtEzgGIOMvFVpixXhaMlI+aR5paHHfRunFTXGB+ATxYAQj1FUeUsMJD9nyQiUfz1RXsAtsmjq51Yg1RKyGHBZ9nZQ0KTiyIIg4kdqyJa9KLLhI1V8cDfyqpIYNxBUj0tuV9e1WOocjpCSBnwywAr+ixn1ABjQ8N82ZIUl4W/F8tSuRoR0H6CGwEUaTBtqoyZ21bxITWzsZ+oe5sickwOKT1pF2kqACkLW45Ruyg+aPg160+PFElJlw6YRwHXs/AfB2Ui8FQ/0qU0cmVeGZLZvgoCIVP8edl40C3IRYzdsPlzEZqRj/2/vkqbxeeMPG5+MwjwmanDopPR+EaKsj8+C71xrxNz3hnBswFrQx9HTlaIzMLumbN19cjRnkMlWgP5aAlrcPz2lPpoloYTwFGtpoE9WnqFa3fx9Y/no0q79E4H1g1AjBsZNjLLDJR8fy4KAd9TGsIQjQvUWPOmYj9e6nP2DQC8T3LxxigcArA10feOzgqvFjAouHI3VkAgT0+HyOz6MHEeCqoOhmrv
C:\Windows\tasks\7eca1cd8-2a95-4759-9c0f-ae713062040a-5.job - C:\Program Files (x86)\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-5.exe /rawdata=oCSNpk9BuatL1Dqwjf5Rmv4BIseOz1hujV+pSLQeGfQAVL3x8AOvduN+b86uEmV0smkgijNWE1Fds5Rq/kRc2q6ggdBrx3m0w5g4cAGN0GZSVBmx9nWu2pFVYNTPlO0o6ufcFkrodG73nFiT8Frq6Yl2htdLuc59MdBCi+hLpMWn0ePO30ykI5uVFHLc12lURp+HscT4HGBgGr/wcuDyITNYArZxS1/w2JoZxgkAvj4d8XTQwrTs4OQqeFEskAhQfN+sFae3dX7qncTJLBChlqlFtfZfWOFb8dq5YzZy91sxfaS+vTnrF9O1E2Yia5L9e4mweACMe6Qp6zMC3UQsFReyPBdaZBWQOZju+vC8i6w4Q92ElAsdqq/HCzShM+oatTh+D/djklsTHwtWtSZzhIKpqAm3GMwbH8mGlhbPvIrYt6/NmRvTmdFoHVzMaGfEstLM5Mw7jITuEX/oP2YBKDI0gSGKEz/aBk23+PesG3wInXKQZqD0/t1s4CvWWHdRJXyennrWRQwPZxQMtBCzB1oqDvrbrYdnz1PiISdTOVXih6ShneSJYoG4ke52yDsaqJ2gY5MwfYjGfSd6gaBBnLkM/7jdybsRA54KhYo9HBZdYPtb3KJ262HLls1Cu+RQitgvgbT+fPOvlmXsa8ILlESu8uZVb6XvJ9sWY47Rydq14onZwepAK9UvS/V2bbzC9KkYliYhjn2M0NdLLm/n1fxNZ/zYpTQP3yU3D4/2V/0BN3XEKg9D3lJRgio7QFO9tmMPxlOVU65fZsKy3lQ6AA27vF/Asx8aFH7eKbN0078lcR+Tt40CHqKVirvoLs2DnL4G2KKWKwPtaky8wsrwoGt24epsKiJIpRHip0x8vn4ZLyO5RgtzO+O1x7wYFEuIXdpM+/RUd6sh/zO8StFcRruO68bj50+sCPRCSv3ZUx9szisTF7+mvSFpWrJ1vykfqI+VD0rDPf6y47XXFoKLu0063ZDUhoGWV4vDHQLGBGsoDxeYyAM1S0WukUIHVSnD
C:\Windows\tasks\7eca1cd8-2a95-4759-9c0f-ae713062040a-5_user.job - C:\Program Files (x86)\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-5.exe /rawdata=oCSNpk9BuatL1Dqwjf5Rmv4BIseOz1hujV+pSLQeGfQAVL3x8AOvduN+b86uEmV0smkgijNWE1Fds5Rq/kRc2q6ggdBrx3m0w5g4cAGN0GZSVBmx9nWu2pFVYNTPlO0o6ufcFkrodG73nFiT8Frq6Yl2htdLuc59MdBCi+hLpMWn0ePO30ykI5uVFHLc12lURp+HscT4HGBgGr/wcuDyITNYArZxS1/w2JoZxgkAvj4d8XTQwrTs4OQqeFEskAhQfN+sFae3dX7qncTJLBChlqlFtfZfWOFb8dq5YzZy91sxfaS+vTnrF9O1E2Yia5L9e4mweACMe6Qp6zMC3UQsFReyPBdaZBWQOZju+vC8i6w4Q92ElAsdqq/HCzShM+oatTh+D/djklsTHwtWtSZzhIKpqAm3GMwbH8mGlhbPvIrYt6/NmRvTmdFoHVzMaGfEstLM5Mw7jITuEX/oP2YBKDI0gSGKEz/aBk23+PesG3wInXKQZqD0/t1s4CvWWHdRJXyennrWRQwPZxQMtBCzB1oqDvrbrYdnz1PiISdTOVXih6ShneSJYoG4ke52yDsaqJ2gY5MwfYjGfSd6gaBBnLkM/7jdybsRA54KhYo9HBZdYPtb3KJ262HLls1Cu+RQitgvgbT+fPOvlmXsa8ILlESu8uZVb6XvJ9sWY47Rydq14onZwepAK9UvS/V2bbzC9KkYliYhjn2M0NdLLm/n1fxNZ/zYpTQP3yU3D4/2V/0BN3XEKg9D3lJRgio7QFO9tmMPxlOVU65fZsKy3lQ6AA27vF/Asx8aFH7eKbN0078lcR+Tt40CHqKVirvoLs2DnL4G2KKWKwPtaky8wsrwoLe5fByNoTfX35T3gwziB+UsVx3G7T6kQYBP09DMBXn+TF4MZN3N98QiSlTWrNAklGgCVpyZxhxOyldxh+LQC+1xNYjrl/hGosLjISi1UcSVvoK67EJpRKL1426NEabdNlIHE0abtMvZW59ga43dIQzKZ1rn33Q2BvUbkYEL+Xtl
C:\Windows\tasks\7eca1cd8-2a95-4759-9c0f-ae713062040a-6.job - C:\Program Files (x86)\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-6.exe /rawdata=lJizujkGU1QxSpk5zuyEjDnCNDDZNAhQn/DaeBugLPQMzaDrpWDxNP6yeb9J7dw0U5yFDmQ0loAOgj70MsJqW4O8Gea6oZlHdFc99Gs6uCMW5kR8uwDMtys7SpoBIt+8lfr1V46yMw15XfNUrlT39EGDvA+1Tb9NilPiael71OInE/v33vtSeednOmbbFM4j6sKyKYOVc3lV90xaUMSwiC140WSw8rt0epJDvNK1g71dVsjCQAPT1EuE1lDWl/UJ5Pyx99bMD/Bd3a/DzW+EOrnDutCmmdJy13lgoteKow+SVXTzpIWqDdPJv1Q2jVcg9sVOE0T/PjPf0/BtXWnn0HDFO9EuriCX7gzs1TDhkj8YZzo4lRhr6jdqZdKy9peH2jcJEVCM7JF8I9JKJpk8Fpd8tx5SfQZldiOTmUT0pNtTsyeKeNWJPGc6C8SfBEv6Qyg720jINkrYAYa81aHFsh1dI7okd26qGp0kfrKPMqkDDdh25x4orhwol8S/OoKuBSyiN3F8oVH0C8bnzqfVGurlooHSeaVCfiG7k4bYhUD1UD5ioHBQFZo78Zi0rXkPpVdF5uBvB/zMynpnjmi4qBG86plqfgEf9pBZ9+SLzDIhRcaOPW+Y3G1wxEGOn0hGcNC/8vDhMMFFKFdaob3xsgm/UvDhNJH0HcDZPnLOdiu4UIr7CT0M0eQU6KUodAYZW+apah8ELnewiLQ6RKJD1lKh3Tq7zw0gtHZQz6cwYAPH5NlTj7ccg+ej4fYluIJInpnkxdn9Z2HgdHkWC1TbmEbqEFfxFzqVgybxjQbSz5JQ9sZ5Adn1Rmtf7bBxdxgV6Y9R/CptTxbVidkHa7SFBBUneB0lrc4sYNqab4uM3Bfxgp7zuOrp0qQiBeSfE6w7F+kYx37A6j9SLcL5cb+VWKRfDroNHPlEi1Vk8LbM/cNSbk5vbu3Ycks4qyNXMUTeCC4ejfR04IEDsKWmDqzlXwX8psQe/DAJK5E4tth/20/uiG6Oh5PcYZ2Iu/7K7RJrJ04sUoYK6rwR52uLETbH4AMzxNYtoomNzQdiiIglbxMLVGnRnmr+CSuSWTz6i6MRSLKOcIZzhRZJpDQ8YL8yOWq076nQ0NABMSbScwZ/ockIR7wKIngEMoRLxMBW6SQUjsY/T13bTOKBlKR85/PS4UgOGYXVHAJpfv1WrDp+9iW9q3hexno/F4WT16VRakZDR/YaOdtfaux0rx98NKCvhR6AFgQ8/t1Qf8tMVXXWdEVS6C2t3A1cNltP5CQH7GcfAQ3b/SPZITRyZFkspjb+DBPcu6v/jI6thYp+OzfxdMx3s5A0UWc+yPuf3gY9IIm5sbjbzVjJPu+ayW6btEvR1zYfMjS+NfGBeHUNo58oh3fLOLgy+J8KLL7Uv3uvEhusC36b0peVRD+Fz/a3P/WdDQ8fQR839vCZNb5+y87BmBfI/wclfB8CiIyyzIxNpa2xj+BF3/RFEzzP6mtfkDmnqX2LeyclxfAQK1C7K36qWuEZ/7Z3O8jlJvGXSSX8qaUWdDGn6tjCllfAZ0MJQtinTcaC+Mdi4AV54O/W95Dh9fkusbuK4ajOBEl6hlXTW2vKs+Gc+lm2gQkQdRRfilEdfzEWAXXtILjRNxH1+9/jeNuj6kwZ2V0o++lcY0v7EAu0x/nNYx08Q5RxWvyRJCFxzSKDcl6NOhz9boMwVsyJVxNM1uZQ9VATT1zE8QPNLmLDd1uFLgzqZXRds8cl3vXcb0qfgN6FGy6y5Uxrs4YSmjDNWPNoidcXLFyMEM048ZW8vUFwT53YAkFc1Ntn2YwQWvAe39GO4raAKxO4LdOM685VnT2ebMraWBZ3zQvBVl22sqEkiOBg/v0qc3WNvIiG47hHTRKB1TCtIX/7q2jXgTpsh9c219KuwQ9djexBgZrB4X3ofCUuOYACDzrL/R1a772ZfTYQeAN4SOPJSHLOlD9cI37orAlfq27moQQL1p+UCenAjbFCBQSVSURtMIeL8XpzDA5kibYPXzE+J7VTFNQkQoxLA19JjkBWqb6MO1/dLLF7QekXTnaENmOVNSuv8XzMEOKHqfxnAuWfa54XCT7PMpPnxuX7YqKiW7T9kjq3soKzznhz6lw6fQoy5piu1PvwMd+JR7W5qyO0XI9FqZYD33fgO/S1CwTUz5PDP/Z/prDLP49yTT6ejlelGVMK4EuEI87j48204NeCn16XRb5XgVvbT+8o1Owhs5MX366J65dbhZrjTqA3ka0DonqqKKubmjiO8WlNIpuov7gGhx2m2pRpNBYywN9Zh7Q2CQhYOFBDzXRP/6lLqzB903FqXERXdJikdXpyouTBLH1stLyEwC40JOmsE3evjB8Ha6Tfd8fqCQOknmKou7ad5+S3IETXjUH0emkPDYbJopWDeW/622oRRd1aS/hyA0KcKoPHnTZxCdUUphFNWt69+1kyxWYr7045BgC12/IQsYEq80bMUveLSd+zuROPAYBWGTyc07NObqnmKulYRMaP1YtCF2ayvNgtZTIENjDxpJv6QNwlZ21u+7a9wLEvtCaMPazG
C:\Windows\tasks\7eca1cd8-2a95-4759-9c0f-ae713062040a-7.job - C:\Program Files (x86)\Super Radio\7eca1cd8-2a95-4759-9c0f-ae713062040a-7.exe /rawdata=LBnfmuNvmLdzeEWDDGhDeOFCNn0PXclmABqb0axDIDyVbMMjPQL0MNPaVqL8AtdlU7JVl61O6N1o8BvhYa7ZBxjRQvl50G3Tvrv+Tem4hk8kN8zXoR223uI4df6BUQvaIcM1lbbkdmetkmDtyEfaqZI7bqQMXYSmv7I4H0n5ajAQ7msPkNN0yIoWHK7kNNpgu4gPd9MNIqtS6HbAr1q//sfVFD2AzVoT06EgXHLy/U1xEmNwiYF0Iy3zhD70AK2FsnjzJ/IVd3FeWqy4i8sYCzB5tmmLDAeYq+TioTC4qgkdLeGuoV1OMCxalaOpHfs9SeT7CWH7mrtu+ilavLHuJxdfRDZ91Gp3bbtT4VYqFoVRq7iIEGuSClt1TVPO2xlq2cPyXF8K5/HInY2Y6Us74lqN4rVfD17vGxxspuJ4uAS9qvYITLJW+lQTfRlNyfmNcWJbf0YCYpPdt8OV6qGeEEqM06Y+9sQFcyogfbfSPGyvUMC2oNcUrcg+/wqcn9S0q9c0RwrbbA1fw6uV7PDzgz7FAfL+XLnTAwWc22foZPzWUDZ7r93KBxskvRaXUkrpyJao2UiNvJ/Lhs3Kl8q81qQ6pCv0vZskXj88u3aSRFD6dS4PkzzWQ5CXqqal7Ult5hniO70uuxjihDpi5GykCKVDXpUWI0/AOAuT6vxtZNU2XRjPcsL9Fcj8WZtaAV915MACkLzeTgphqTM+5RMJQagDhRLbh+xhjyWE9HbOQz/XtAsKlycf8cnXw9nf3KaeunI9hFPqBuukzKhJQwcpTLlLRqnu5ESh77yQuM7zHblE9zSyGkrXQBaM+YvTZQODJvhGOc+k6/z+Dddfh4auSINmopeXGHhUgMkcOK3FDbBSDrkcuhET/9e/ZjMNywtX0e4mVBzQi23NB6VHmKURvOHX50U5TP6fkZYdFcf5VjMZylq/T4Wiz8QkxYvrJ8LTRR8eThDSwfkhfmXJKMojFS3zLsMAHeo9nraS2ZlP1DoCly2apnSkH2ZkjKVqv2GSn+QwsjGuxWvf5d9n3VmSW1Kw+KXRkGtRy+0U667LneOmra3v/m5ab0ceQPusbmfwLcMdu9Oq1cXwRBrhfR5ZRJkR41hdH8Vy5eHbgSzpUCHx7ur+NyOelOQXFfRt/7L9WZPNG7/PVh4HQXdZrS7IwsjHuLcx8Rb4LpABCtL5UFWPU0I1AHAKbg6VpKE9O8ziI7E+eN5gMUFQYzRpuV6jVlX1WiJeFIWgKdVJKZ3EOEkPzkDSf/PccSd/Divuix8wG477d/7NKJCgauRS2Q4V+axNkOKAqOnuUGP29V2n3/i31zsfaRAf3ShCuXBPMYnHKcN2U+OEmFdd5GJqxMWA9kvC7DCGIewikk6vOA9AopBC432gfR70AaSuuKMc+7SYp4NlRkc8jB+MubZcVro8mZ4UFd/sObkSH3A8YYW7GG5CU+8OnijVOiyqCCrQIG8REEmQ4zOWSmm38Nie7MfsijJeKbFek2ZIyhpTUtWxnSanqZIgrkug5NBeG+W/7aadc0vGNeZKBlc8mxn0KXAKfQuNzrHLhqWkxqq45R/BlUZSdikJCqGmfXh9K2K/Vf2DfiUEeiotO8EtcEcG191AcveyeRqz0GXPD13X8hwqV2ft5tm6544c2s8aePf/S/dZx2xhkQ7FHJqsR++/L3liiZWdRVvwzaZRTA8WRppgeKGGVGb0bDZD5ofo4gy6j80FYAWkduHTLTIsHHGrfsihd40JMjETSt4Fwi94n33FyjAwkeTeUshZBtoab0+dx2iXwdQXBj0UiM7J1/z+Wu9Ce4A0y0EMj7ixvCTImBKnLcnKn+d9sMBKkI0SIM7nCNnoqBlrchKGrGV4Ia1a9NWQ855aNazuHnDuSCQyRsSH02+9nR4fs/oVPNbm8n9jSqvxQQNOgizc987WLyfZVrM6iXjhg5GzX8HdDgMXuffWfmWHpng7qxL3KWSP2Wl15HmrMSi3J7L5yPBUf/3keDhz1Ewacp0bJo+XWDn2X7uPA7vwQpYi9OUIwfh0KYHJF+91uUlqrID4POI2WYZYVtQaxZCeYPdg7FAa5+dqK4rJCWeAhfR9Sp/msDj2mOGQR4tdnKBdz0hNGCyGGxMXKJlTyKUBDs2q4mUznsCrc/0cO1o4TupWcxGXBihbVPTeZxOfvBzsNLAEgJIwKfgAnzL+YTqJ3+aD84Z7zgEcdeI8TRQfpR3QyqYBJ+6Wbq3yraT4kFajT7J40j1CCqNzYMB47CeEKn+ZJhQZSLYEo8vi7T1WVK9RwmBq9PXmmfTo48pyyjcFBQtkE6aED4TR0nAVK8yMwqaQ4MPu3Q9KwDKqZjg9PG2/u9UVecMb/KVG46ooaMAu2DJ4PbzVqqrkr2AePA==
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\DLL-Files FixerASKUSER.job - C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe -askuser
C:\Windows\tasks\DLL-Files.Com Fixer_MONTHLY.job - C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe scan
C:\Windows\tasks\DLL-Files.Com Fixer_Updates.job - C:\Program Files (x86)\Dll-Files.com Fixer\DLLFixer.exe -updatecheck
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41545534-2D53-5000-76A7-7A786E7484D7}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41545553-502D-5341-5400-7A786E7484D7}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-07 662672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05 256456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41545534-2D53-5000-76A7-7A786E7484D7}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41545553-502D-5341-5400-7A786E7484D7}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-07 565304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05 194504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05 256456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05 194504]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-02-18 391152]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-02-18 771568]
"Persistence"=C:\Windows\system32\igfxpers.exe [2014-02-18 770544]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-01-14 7510896]
"SimplePass"=C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [2014-03-28 3962936]
"OPBHOBroker"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [2014-03-28 415288]
"OPBHOBrokerDesktop"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [2014-03-28 415288]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-12-13 2803440]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"MSPCLOCK"=streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000} []
"MSPQM"=streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196} []
"MSKSSRV"=streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196} []
"MSTEE.CxTransform"=streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install []
"MSTEE.Splitter"=streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interface.Install []
"WDM_DRMKAUD"=streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\Windows\inf\WDMAUDIO.inf,WDM_DRMKAUD.Interface.Install []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"EADM"=C:\Program Files (x86)\Origin\Origin.exe [2014-12-18 3618648]
"cz.seznam.software.autoupdate"=C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\szninstall.exe [2013-05-16 1062472]
"cz.seznam.software.szndesktop"=C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2013-04-12 92664]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"mcpltui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2014-04-25 537992]
"HPMessageService"=C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [2013-10-08 1045304]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-05-13 5515496]
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2013-05-16 1062472]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"20150107"=C:\Program Files\AVAST Software\Avast\setup\emupdate\71d5f7a4-4254-4c48-bd30-7b9448c2bbbe.exe [2015-06-23 183232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2014-02-18 624640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefire]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfevtp]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=0
"NoFolderOptions"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-07-04 13:09:25 ----D---- C:\Program Files\trend micro
2015-07-04 13:09:24 ----D---- C:\rsit
2015-06-15 12:05:34 ----D---- C:\ProgramData\Mozilla
2015-06-15 12:05:32 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-15 12:05:23 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-06-11 19:36:53 ----D---- C:\Windows\Migration
2015-06-10 20:35:00 ----D---- C:\43cfc473f2703a71676fe2ba
2015-06-10 20:05:30 ----A---- C:\Windows\SYSWOW64\puiobj.dll
2015-06-10 20:05:30 ----A---- C:\Windows\system32\puiobj.dll
2015-06-10 20:05:30 ----A---- C:\Windows\system32\localspl.dll
2015-06-10 20:05:30 ----A---- C:\Windows\system32\compstui.dll
2015-06-10 20:05:24 ----A---- C:\Windows\system32\generaltel.dll
2015-06-10 20:05:24 ----A---- C:\Windows\system32\appraiser.dll
2015-06-10 20:05:24 ----A---- C:\Windows\system32\aepic.dll
2015-06-10 20:05:24 ----A---- C:\Windows\system32\aeinv.dll
2015-06-10 20:05:23 ----A---- C:\Windows\system32\invagent.dll
2015-06-10 20:05:23 ----A---- C:\Windows\system32\devinv.dll
2015-06-10 20:05:23 ----A---- C:\Windows\system32\acmigration.dll
2015-06-10 20:05:22 ----A---- C:\Windows\system32\aepdu.dll
2015-06-10 20:05:20 ----A---- C:\Windows\SYSWOW64\rastapi.dll
2015-06-10 20:05:20 ----A---- C:\Windows\system32\rastapi.dll
2015-06-10 20:05:17 ----A---- C:\Windows\SYSWOW64\msftedit.dll
2015-06-10 20:05:17 ----A---- C:\Windows\system32\msftedit.dll
2015-06-10 20:05:15 ----A---- C:\Windows\system32\win32k.sys
2015-06-10 20:05:13 ----A---- C:\Windows\system32\mssrch.dll
2015-06-10 20:05:12 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2015-06-10 20:05:12 ----A---- C:\Windows\system32\tquery.dll
2015-06-10 20:05:12 ----A---- C:\Windows\system32\mssph.dll
2015-06-10 20:05:11 ----A---- C:\Windows\SYSWOW64\tquery.dll
2015-06-10 20:05:11 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2015-06-10 20:05:11 ----A---- C:\Windows\system32\SearchIndexer.exe
2015-06-10 20:05:11 ----A---- C:\Windows\system32\mssvp.dll
2015-06-10 20:05:10 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2015-06-10 20:05:10 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2015-06-10 20:05:10 ----A---- C:\Windows\SYSWOW64\mssph.dll
2015-06-10 20:05:10 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2015-06-10 20:05:10 ----A---- C:\Windows\system32\mssphtb.dll
2015-06-10 20:05:08 ----A---- C:\Windows\system32\UtcResources.dll
2015-06-10 20:05:08 ----A---- C:\Windows\system32\diagtrack.dll
2015-06-10 20:05:07 ----A---- C:\Windows\system32\UIAutomationCore.dll
2015-06-10 20:05:06 ----A---- C:\Windows\SYSWOW64\UIAutomationCore.dll
2015-06-10 20:05:05 ----A---- C:\Windows\system32\drivers\USBXHCI.SYS
2015-06-10 20:05:03 ----A---- C:\Windows\SYSWOW64\authz.dll
2015-06-10 20:05:03 ----A---- C:\Windows\system32\authz.dll
2015-06-10 20:05:01 ----A---- C:\Windows\SYSWOW64\comctl32.dll
2015-06-10 20:05:01 ----A---- C:\Windows\system32\comctl32.dll
2015-06-10 20:04:53 ----A---- C:\Windows\SYSWOW64\rgb9rast.dll
2015-06-10 20:04:47 ----A---- C:\Windows\system32\mshtml.dll
2015-06-10 20:04:45 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-06-10 20:04:41 ----A---- C:\Windows\system32\jscript9.dll
2015-06-10 20:04:40 ----A---- C:\Windows\system32\wininet.dll
2015-06-10 20:04:39 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-06-10 20:04:38 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-06-10 20:04:37 ----A---- C:\Windows\system32\ieframe.dll
2015-06-10 20:04:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-06-10 20:04:36 ----A---- C:\Windows\system32\iertutil.dll
2015-06-10 20:04:35 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-06-10 20:04:35 ----A---- C:\Windows\system32\urlmon.dll
2015-06-10 20:04:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-06-10 20:04:33 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-06-10 20:04:32 ----A---- C:\Windows\system32\actxprxy.dll
2015-06-10 20:04:31 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-06-10 20:04:31 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-06-10 20:04:31 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-06-10 20:04:31 ----A---- C:\Windows\system32\vbscript.dll
2015-06-10 20:04:31 ----A---- C:\Windows\system32\msfeeds.dll
2015-06-10 20:04:31 ----A---- C:\Windows\system32\jscript.dll
2015-06-10 20:04:30 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-06-10 20:04:30 ----A---- C:\Windows\system32\jscript9diag.dll
2015-06-10 20:04:30 ----A---- C:\Windows\system32\ieapfltr.dll
2015-06-10 20:04:29 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-06-10 20:04:29 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2015-06-10 20:04:29 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-06-10 20:04:29 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-06-10 20:04:29 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2015-06-10 20:04:29 ----A---- C:\Windows\system32\webcheck.dll
2015-06-10 20:04:29 ----A---- C:\Windows\system32\mshtmled.dll
2015-06-10 20:04:29 ----A---- C:\Windows\system32\inetcomm.dll
2015-06-10 20:04:29 ----A---- C:\Windows\system32\ieui.dll
2015-06-10 20:04:29 ----A---- C:\Windows\system32\iepeers.dll
2015-06-10 20:04:29 ----A---- C:\Windows\system32\iedkcs32.dll
2015-06-10 20:04:29 ----A---- C:\Windows\system32\dxtrans.dll
2015-06-10 20:04:28 ----A---- C:\Windows\SYSWOW64\inetcomm.dll

======List of files/folders modified in the last 1 month======

2015-07-04 14:00:04 ----D---- C:\Windows\system32\sru
2015-07-04 13:29:51 ----D---- C:\Windows\Prefetch
2015-07-04 13:23:09 ----D---- C:\Windows\Tasks
2015-07-04 13:23:09 ----D---- C:\Windows\system32\Tasks
2015-07-04 13:20:00 ----D---- C:\Windows\Temp
2015-07-04 13:09:25 ----RD---- C:\Program Files
2015-07-04 12:58:39 ----D---- C:\Windows\AppReadiness
2015-07-04 12:47:41 ----HD---- C:\Program Files\WindowsApps
2015-07-01 19:42:52 ----D---- C:\Windows\system32\config
2015-06-30 21:55:27 ----D---- C:\Windows\Inf
2015-06-30 17:37:07 ----D---- C:\Windows\Microsoft.NET
2015-06-30 17:28:52 ----D---- C:\Windows\system32\catroot2
2015-06-27 18:54:09 ----D---- C:\Windows\system32\drivers
2015-06-26 19:06:59 ----SHD---- C:\System Volume Information
2015-06-26 15:57:57 ----D---- C:\Windows\CbsTemp
2015-06-26 15:57:53 ----D---- C:\Windows\WinSxS
2015-06-26 15:57:52 ----D---- C:\Windows\SysWOW64
2015-06-24 23:17:45 ----SHD---- C:\Windows\Installer
2015-06-20 13:22:59 ----D---- C:\Windows\system32\NDF
2015-06-20 05:02:45 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-06-15 12:05:34 ----HD---- C:\ProgramData
2015-06-15 12:05:32 ----RD---- C:\Program Files (x86)
2015-06-14 14:50:18 ----D---- C:\Windows\system32\catroot
2015-06-14 14:49:53 ----SD---- C:\Windows\system32\CompatTel
2015-06-14 14:49:53 ----RD---- C:\Windows\ToastData
2015-06-14 14:49:53 ----RD---- C:\Windows\System32
2015-06-14 14:49:52 ----D---- C:\Windows\system32\DriverStore
2015-06-14 14:49:52 ----D---- C:\Windows\system32\appraiser
2015-06-14 14:49:52 ----D---- C:\Windows\apppatch
2015-06-13 20:05:25 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-06-11 19:36:53 ----SD---- C:\Windows\SYSWOW64\GWX
2015-06-11 19:36:53 ----SD---- C:\Windows\system32\GWX
2015-06-11 19:36:53 ----D---- C:\Windows
2015-06-11 19:36:51 ----D---- C:\Program Files\Internet Explorer
2015-06-11 19:36:51 ----D---- C:\Program Files (x86)\Internet Explorer
2015-06-11 19:36:50 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-06-11 19:36:50 ----D---- C:\Windows\PolicyDefinitions
2015-06-11 19:36:49 ----D---- C:\Windows\system32\cs-CZ
2015-06-10 20:35:13 ----D---- C:\Windows\system32\MRT
2015-06-10 20:35:07 ----A---- C:\Windows\system32\MRT.exe
2015-06-05 19:28:45 ----RSD---- C:\Windows\assembly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-05-07 65736]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-05-07 272248]
R0 MBI;@oem12.inf,%MBI.SVCDESC%;Intel(R) Sideband Fabric Device Service; C:\Windows\System32\drivers\MBI.sys [2014-01-23 29464]
R0 mfehidk;McAfee Inc. mfehidk; C:\Windows\system32\drivers\mfehidk.sys [2014-06-20 786296]
R0 mfewfpk;McAfee Inc. mfewfpk; C:\Windows\system32\drivers\mfewfpk.sys [2014-06-20 348552]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-05-07 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-05-07 1047320]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-06-26 442264]
R1 CLVirtualDrive;CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [2013-03-05 91712]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-05-07 29168]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-05-07 89944]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-05-07 137288]
R3 cfwids;McAfee Inc. cfwids; C:\Windows\system32\drivers\cfwids.sys [2014-06-20 72128]
R3 clwvd;@oem21.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\Windows\system32\DRIVERS\clwvd.sys [2014-01-28 41704]
R3 GPIO;@oem14.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\Windows\System32\drivers\iaiogpioe.sys [2013-11-11 31232]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-02-18 4222976]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-01-15 3837144]
R3 IntcDAud;@oem7.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-02-18 450520]
R3 iwdbus;@oem10.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2013-12-27 27032]
R3 mfeapfk;McAfee Inc. mfeapfk; C:\Windows\system32\drivers\mfeapfk.sys [2014-06-20 181704]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\Windows\system32\drivers\mfeavfk.sys [2014-06-20 313544]
R3 mfefirek;McAfee Inc. mfefirek; C:\Windows\system32\drivers\mfefirek.sys [2014-06-20 523792]
R3 mfencbdc;McAfee Inc. mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [2014-08-20 445512]
R3 RSP2STOR;@oem16.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [2014-01-04 291544]
R3 RTL8168;@oem15.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-01-28 839896]
R3 RTWlanE;@oem6.inf,%RTWlanE.DeviceDesc.DispName%;Realtek Wireless LAN 802.11n PCI-E Network Adapter; C:\Windows\system32\DRIVERS\rtwlane.sys [2014-03-22 3379416]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2013-12-13 31472]
R3 SynTP;@oem18.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2013-12-13 542448]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [2014-09-09 14112]
R3 TXEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Trusted Execution Engine Interface ; C:\Windows\System32\drivers\TXEIx64.sys [2014-01-15 88592]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]
S0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-11-06 632168]
S0 mfeelamk;McAfee Inc. mfeelamk; C:\Windows\system32\drivers\mfeelamk.sys [2014-06-20 70600]
S3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
S3 dg_ssudbus;@oem22.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 HipShieldK;McAfee Inc. HipShieldK; C:\Windows\system32\drivers\HipShieldK.sys [2013-09-23 197704]
S3 intaud_WaveExtensible;@oem9.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2013-12-27 38296]
S3 mfencrk;McAfee Inc. mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [2014-08-20 96592]
S3 SmbDrv;SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [2013-12-13 29936]
S3 ssudmdm;@oem24.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\Windows\System32\drivers\usbscan.sys [2014-10-29 44544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-06-12 82112]
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2014-10-29 38792]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-05-07 343336]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 DragonUpdater;COMODO Dragon Update Service; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2014-05-27 2139328]
R2 HomeNetSvc;McAfee Home Network; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-07-30 328928]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-01-13 92160]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [2013-10-08 1039160]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [2013-07-01 733696]
R2 McAPExe;McAfee AP Service; C:\Program Files\McAfee\MSC\McAPExe.exe [2014-04-25 178528]
R2 McMPFSvc;McAfee Personal Firewall Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-07-30 328928]
R2 McNaiAnn;McAfee VirusScan Announcer; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [2013-07-30 328928]
R2 mcpltsvc;McAfee Platform Services; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [2013-07-30 328928]
R2 McProxy;McAfee Proxy Service; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [2013-07-30 328928]
R2 mfecore;McAfee Anti-Malware Core; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [2014-08-20 1041192]
R2 mfefire;McAfee Firewall Core Service; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [2014-06-20 219752]
R2 mfevtp;McAfee Validation Trust Protection Service; C:\Windows\system32\mfevtps.exe [2014-06-20 189912]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2013-07-30 328928]
R2 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2014-07-15 786256]
R2 omniserv; HP SimplePass Service; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [2014-03-28 88064]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-12-23 66872]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2015-01-02 107832]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-01-09 290520]
R2 ssinstall;SInstalátor; C:\Windows\SysWOW64\ssins.exe [2015-04-08 2324216]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2014-10-17 2589496]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-18 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-04 268976]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-08-10 50784]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-02-18 279024]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2014-03-18 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-18 116648]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2014-12-18 194032]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-05-13 1129760]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [2013-07-01 822232]
S3 McAWFwk;McAfee Activation Service; c:\PROGRA~1\COMMON~1\mcafee\actwiz\mcawfwk.exe [2013-07-29 334608]
S3 McODS;McAfee Scanner; C:\Program Files\mcafee\VirusScan\mcods.exe [2014-09-04 603424]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-05-26 148080]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2015-01-30 1910128]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 McOobeSv2;McAfee OOBE Service2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [2013-07-30 328928]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivní kontrola logu

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Po spusteni probehne stazeni databaze
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Alice
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 08 kvě 2015 11:02

Re: Preventivní kontrola logu

#3 Příspěvek od Alice »

# AdwCleaner v4.207 - Log vytvořen 04/07/2015 v 18:17:48
# Aktualizováno 21/06/2015 by Xplode
# Databáze : 2015-07-02.1 [Server]
# Operační system : Windows 8.1 Connected (x64)
# Uživatelské jméno : KoulovaA - PC-AJANEK
# Spuštěno z : C:\Users\Kotyna\Desktop\adwcleaner_4.207.exe
# Nastavení : Čištění

***** [ Služby ] *****


***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ProgramData\apn
Složka Smazáno : C:\ProgramData\AskPartnerNetwork
Složka Smazáno : C:\Program Files (x86)\AskPartnerNetwork
Složka Smazáno : C:\Users\KoulovaA\AppData\Local\Temp\apn
Složka Smazáno : C:\Users\ajajan\AppData\Local\AskPartnerNetwork
Složka Smazáno : C:\Users\Kotyna\AppData\Local\AskPartnerNetwork
Složka Smazáno : C:\Users\KoulovaA\AppData\Local\AskPartnerNetwork
Složka Smazáno : C:\Users\KoulovaA\AppData\Roaming\OpenCandy
Složka Smazáno : C:\Users\KoulovaA\AppData\Roaming\RHEng
Složka Smazáno : C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaahaeginbdcckocjkhbciadcafnep
Složka Smazáno : C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaadgepjkdffhjbkfjgnnffnfcffbg
Složka Smazáno : C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaadgepjkdffhjbkfjgnnffnfcffbg
Složka Smazáno : C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaaejaghnbcjilindpkgmcmdflpgjf
Složka Smazáno : C:\Users\KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
Složka Smazáno : C:\Users\KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko
Soubor Smazáno : C:\Users\KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_cmaiofennmphjldldcpphcechfnnohja_0.localstorage
Soubor Smazáno : C:\Users\KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_cmaiofennmphjldldcpphcechfnnohja_0.localstorage-journal
Soubor Smazáno : C:\Windows\System32\roboot64.exe

***** [ Naplánované úlohy ] *****

Úloha Smazáno : RDReminder
Úloha Smazáno : 7eca1cd8-2a95-4759-9c0f-ae713062040a-1
Úloha Smazáno : 7eca1cd8-2a95-4759-9c0f-ae713062040a-11
Úloha Smazáno : 7eca1cd8-2a95-4759-9c0f-ae713062040a-4
Úloha Smazáno : 7eca1cd8-2a95-4759-9c0f-ae713062040a-5
Úloha Smazáno : 7eca1cd8-2a95-4759-9c0f-ae713062040a-5_user
Úloha Smazáno : 7eca1cd8-2a95-4759-9c0f-ae713062040a-6
Úloha Smazáno : 7eca1cd8-2a95-4759-9c0f-ae713062040a-7

***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaahaeginbdcckocjkhbciadcafnep
Klíč Smazáno : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaahaeginbdcckocjkhbciadcafnep
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaadgepjkdffhjbkfjgnnffnfcffbg
Klíč Smazáno : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaadgepjkdffhjbkfjgnnffnfcffbg
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaaejaghnbcjilindpkgmcmdflpgjf
Klíč Smazáno : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\aaaaaejaghnbcjilindpkgmcmdflpgjf
Klíč Smazáno : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Klíč Smazáno : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{44CBC005-6243-4502-8A02-3A096A282664}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{80703783-E415-4EE3-AB60-D36981C5A6F1}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{9945959C-AAD8-4312-8B57-2DE11927E770}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{EEA63863-87BC-4DCA-A5B5-EB97E3B04806}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41545534-2D53-5000-76A7-7A786E7484D7}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41545553-502D-5341-5400-7A786E7484D7}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41545534-2D53-5000-76A7-7A786E7484D7}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{41545534-2D53-5000-76A7-7A786E7484D7}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41545534-2D53-5000-76A7-7A786E7484D7}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41545553-502D-5341-5400-7A786E7484D7}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{6978F29A-3493-40B2-8CDC-9C13A02F85A4}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D7949A66-D936-4028-9552-14F7DC50F38D}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9EE0DDAB-FA04-4063-B196-E36CEB9A8808}
Klíč Smazáno : HKCU\Software\AskPartnerNetwork
Klíč Smazáno : HKCU\Software\InstalledBrowserExtensions
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Super Radio
Klíč Smazáno : HKLM\SOFTWARE\AskPartnerNetwork
Klíč Smazáno : HKLM\SOFTWARE\GlobalUpdate
Klíč Smazáno : HKLM\SOFTWARE\InstalledBrowserExtensions
Klíč Smazáno : HKLM\SOFTWARE\Super Radio
Klíč Smazáno : HKU\.DEFAULT\Software\AskPartnerNetwork
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Super Radio
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{41545553-502D-5341-5400-A758B70C1B00}
Klíč Smazáno : [x64] HKLM\SOFTWARE\AskPartnerNetwork
Klíč Smazáno : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7AB5857A57A0687786597A857BFFFFFF

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17840

Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Google Chrome v43.0.2357.130

[C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms}
[C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","webRequest","webRequestBlocking"],"explicit_host":["hxxp://*/*","hxxps://*/*"],"manifest_permissions":[],"scriptable_host":["*://*.ask.com/
[C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Homepage] : management","nativeMessaging","searchProvider","startupPages","storage","tabs","webRequest","webRequestBlocking"],"explicit_host":["hxxp://*/*","hxxps://*/*"],"manifest_permissions":[],"scriptable_host":["*://*.ask.com/

-\\ Comodo Dragon v33.1.0.1

[C:\Users\KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://search.ask.com/web?o=APN10257&doi=2014-12-22&apn_dtid=%5ECMD011%5EYY%5EUS&apn_ptnrs=%5EAGO&q={searchTerms}

*************************

AdwCleaner[R0].txt - [9038 bytů] - [04/07/2015 16:17:00]
AdwCleaner[S0].txt - [7927 bytů] - [04/07/2015 18:17:48]

########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [7985 bytů] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivní kontrola logu

#4 Příspěvek od vyosek »

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Alice
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 08 kvě 2015 11:02

Re: Preventivní kontrola logu

#5 Příspěvek od Alice »

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by KoulovaA on ne 05. 07. 2015 at 10:44:41,07.
Microsoft Windows 8.1 s aplikací Bing 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Kotyna\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

\zoek-results2015-07-05-082946.log 1788 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-2592885859-3292131433-3858698835-1001\Software\Microsoft\Internet Explorer\SearchScopes\{BAAFB6D0-C20B-4FF6-A710-7CCF9E42134D} deleted successfully
HKEY_USERS\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\SearchScopes\{BAAFB6D0-C20B-4FF6-A710-7CCF9E42134D} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BAAFB6D0-C20B-4FF6-A710-7CCF9E42134D} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BAAFB6D0-C20B-4FF6-A710-7CCF9E42134D} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Kotyna\AppData\Roaming\Mozilla\Firefox\Profiles\yxz9ma7o.default\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/");

Added to C:\Users\Kotyna\AppData\Roaming\Mozilla\Firefox\Profiles\yxz9ma7o.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Kotyna\AppData\Roaming\Mozilla\Firefox\Profiles\yxz9ma7o.default

user.js not found
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----

prefs_201505.07._1153_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\Users\ajajan\AppData\Roaming\dll-files.com deleted
C:\Users\Kotyna\AppData\Roaming\dll-files.com deleted
C:\Users\KoulovaA\AppData\Roaming\dll-files.com deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Windows\tasks\DLL-Files FixerASKUSER.job deleted
C:\Windows\tasks\DLL-Files.Com Fixer_MONTHLY.job deleted
C:\Windows\tasks\DLL-Files.Com Fixer_Updates.job deleted
C:\windows\SysNative\tasks\DLL-Files FixerASKUSER deleted
C:\windows\SysNative\tasks\DLL-Files.Com Fixer_MONTHLY deleted
C:\windows\SysNative\tasks\DLL-Files.Com Fixer_Updates deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
"C:\Windows\Installer\f7b4c29.msi" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Kotyna\AppData\Roaming\Mozilla\Firefox\Profiles\yxz9ma7o.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [28. 05. 2015 21:23]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Kotyna\AppData\Roaming\Mozilla\Firefox\Profiles\yxz9ma7o.default
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================


==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\ajajan\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

Google Chrome Version: 43.0.2357.130

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[07. 04. 2015 19:10]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[07. 04. 2015 19:10]

Seznam Lištička - Email - Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig
Seznam Lištička - Slovník - Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
Avast SafePrice - Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Avast Online Security - Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Seznam Lištička - Rychlá volba - Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak
Comodo Drag&Drop Service - KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aneodkojaglhnkkdbbdnmmmgimlcaogo
Comodo Web Inspector - KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn
Comodo Media Downloader - KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\dihmnpngfonlhjmgkflpnibiaaliendo
Super Radio - KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\icpgdmbkannfhajbcinkekegjlcbcibl
Avast SafePrice - KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Bookmark Manager - KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
Avast Online Security - KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki

==== Chromium Startpages ======================

C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Preferences
:true},"stats.g.doubleclick.net:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":401308}},"survey.g.doubleclick.net:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":50786}},"syndication.twitter.com:443":{"supports_spdy":true},"t0.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":39979}},"t1.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":44525}},"t2.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":44525}},"t3.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":44525}},"theofficeczech.googlepages.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"tools.google.com:80":{"alternative_service":[{"port":80,"probability":0.02,"protocol_str":"quic"}]},"tpc.googlesyndication.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"supports_spdy":true},"tpc.googlesyndication.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":22314}},"translate.google.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":17914}},"translate.google.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":16063}},"translate.google.cz:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":32460}},"translate.google.cz:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}]},"translate.googleapis.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}]},"video-ad-stats.googlesyndication.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}]},"video-ad-stats.googlesyndication.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}]},"www.blogblog.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}]},"www.blogger.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}]},"www.blogger.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":63517}},"www.christinamarsigliese.com:80":{"alternative_service":[{"port":80,"probability":0.5,"protocol_str":"quic"}]},"www.delicious-blog-lucie.cz:80":{"alternative_service":[{"port":80,"probability":0.5,"protocol_str":"quic"}]},"www.dulce-de-leche.eu:80":{"alternative_service":[{"port":80,"probability":0.5,"protocol_str":"quic"}]},"www.gmail.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":75552}},"www.google-analytics.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":21947},"supports_spdy":true},"www.google-analytics.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":165793}},"www.google.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"supports_spdy":true},"www.google.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":55328}},"www.google.cz:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":264332},"supports_spdy":true},"www.google.cz:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":26755}},"www.googleadservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":16544},"supports_spdy":true},"www.googleadservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}]},"www.googleapis.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":36446},"supports_spdy":true},"www.googletagmanager.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"network_stats":{"srtt":21917},"supports_spdy":true},"www.googletagmanager.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":32461}},"www.googletagservices.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}]},"www.googletagservices.com:80":{"alternative_service":[{"port":80,"probability":1.0,"protocol_str":"quic"}]},"www.gstatic.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}],"supports_spdy":true},"www.gstatic.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":38564}},"www.slevomat.cz:443":{"supports_spdy":true},"www.youtube-nocookie.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}]},"www.youtube.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}]},"www.youtube.com:80":{"alternative_service":[{"port":80,"probability":0.0,"protocol_str":"quic"}],"network_stats":{"srtt":44453}},"youtu.be:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}]},"yt3.ggpht.com:443":{"alternative_service":[{"port":443,"probability":1.0,"protocol_str":"quic"}]}},"supports_quic":{"address":"192.168.0.100","used_quic":true},"version":3}},"partition":{"per_host_zoom_levels":{"2166136261":{"cz4.forgeofempires.com":-0.5778829311823857}}},"password_bubble":{"nopes":2},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"printing":{"print_preview_sticky_settings":{"appState":"{\"version\":2,\"isGcpPromoDismissed\":false,\"selectedDestinationId\":\"Save as PDF\",\"selectedDestinationOrigin\":\"local\",\"selectedDestinationAccount\":\"\",\"selectedDestinationCapabilities\":null,\"selectedDestinationName\":\"UloĹľit jako PDF\",\"selectedDestinationExtensionId\":\"\",\"mediaSize\":{\"height_microns\":297000,\"is_default\":true,\"name\":\"ISO_A4\",\"width_microns\":210000,\"custom_display_name\":\"A4\"},\"isColorEnabled\":false,\"selectedDestinationExtensionName\":\"\",\"marginsType\":0,\"customMargins\":null}","savePath":"C:\\Users\\Kotyna\\Desktop"}},"profile":{"avatar_index":26,"content_settings":{"clear_on_exit_migrated":true,"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{"https://www.youtube.com:443,https://www.youtube.com:443":{"setting":1}},"geolocation":{"http://mapy.cz:80,http://mapy.cz:80":{"setting":1}},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"http://mapy.cz:80,http://mapy.cz:80":{"geolocation":1,"last_used":{"geolocation":1428526567.913353}},"https://www.youtube.com:443,https://www.youtube.com:443":{"fullscreen":1}},"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"icon_version":3,"managed_user_id":"","migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"PrvnĂ­ uĹľivatel","per_host_zoom_levels":{}},"protection":{"macs":{}},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13064529847775114"},"sync_promo":{"show_on_first_run_allowed":false},"translate_accepted_count":{"en":0},"translate_blocked_languages":["cs"],"translate_denied_count":{"en":3},"translate_last_denied_time":1423595454857.419,"translate_too_often_denied":true,"translate_whitelists":{}}
","location":1,"manifest":{"app":{"launch":{"container":"tab","web_url":"https://mail.google.com/mail/ca"},"urls":["*://mail.google.com/mail/ca"]},"current_locale":"cs","default_locale":"en","description":"Rychlý e-mail s možností vyhledávání a menším množstvím spamu.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB","manifest_version":2,"name":"Gmail","options_page":"https://mail.google.com/mail/ca/#settings","permissions":["notifications"],"update_url":"http://clients2.google.com/service/upda ... artup_urls":["http://www.google.com/"]}}

C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Preferences
JgxdFwaLr5WBzgC3y5x0/wwPIwN4PtIaK3BhH6njlksfnKwwIJ9iRT41V4BqbWu4mszO/7VJ3HJyw2DBpIc2grU9ZRRxrV3fRQG4wIDAQAB","manifest_version":2,"name":"Google Now","oauth2":{"auto_approve":true,"scopes":["https://www.googleapis.com/auth/googlenow"]},"optional_permissions":["background"],"permissions":["alarms","identity","metricsPrivate","notifications","pushMessaging","storage","tabs","webstorePrivate","*://*.google.com/*","*://*.gstatic.com/*","https://*.googleapis.com/chromenow/v1/*","https://*.googleusercontent.com/*"],"version":"1.2.0.1"},"path":"C:\\Program Files (x86)\\Google\\Chrome\\Application\\39.0.2171.95\\resources\\google_now","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":false,"was_installed_by_oem":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"active_permissions":{"api":["notifications"],"manifest_permissions":[]},"app_launcher_ordinal":"x","commands":{},"content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["notifications"],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13077824860972786","lastpingday":"13079862017573213","location":1,"manifest":{"app":{"launch":{"container":"tab","web_url":"https://mail.google.com/mail/ca"},"urls":["*://mail.google.com/mail/ca"]},"current_locale":"cs","default_locale":"en","description":"Rychlý e-mail s možností vyhledávání a menším množstvím spamu.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB","manifest_version":2,"name":"Gmail","options_page":"https://mail.google.com/mail/ca/#settings","permissions":["notifications"],"update_url":"http://clients2.google.com/service/upda ... artup_urls":["http://www.google.com/"]}}

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences
"startup_urls": [ "http://www.google.com/" ]


==== Chromium Fix ======================

C:\Users\KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\icpgdmbkannfhajbcinkekegjlcbcibl deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.bing.com?pc=HPNTDFJS"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.bing.com?pc=HPNTDFJS"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.bing.com?pc=HPNTDFJS"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Preferences was reset successfully
C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Web Data was reset successfully
C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4355451435D20005677A7A857BC08110 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{41545534-2D53-5000-76A7-A758B70C1801} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\4355451435D20005677A7A857BC08110 deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\ajajan\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\ajajan\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Kotyna\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Kotyna\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Users\KoulovaA\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\KoulovaA\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\ajajan\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\ajajan\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Default User\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Kotyna\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Kotyna\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\Users\KoulovaA\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\KoulovaA\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Kotyna\AppData\Local\Mozilla\Firefox\Profiles\yxz9ma7o.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\KoulovaA\AppData\Local\Comodo\Dragon\User Data\Default\Cache emptied successfully
C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache is not empty, a reboot is needed

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=152 folders=33 26009198 bytes)

==== Empty Temp Folders ======================

C:\Users\ajajan\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Kotyna\AppData\Local\Temp will be emptied at reboot
C:\Users\KoulovaA\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\KoulovaA\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Kotyna\AppData\Local\Temp\FXSAPIDebugLogFile.txt" not deleted
"C:\Users\Kotyna\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\RY28PA3H\img.csfd.cz" not found

==== EOF on ne 05. 07. 2015 at 12:32:21,89 ======================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivní kontrola logu

#6 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Alice
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 08 kvě 2015 11:02

Re: Preventivní kontrola logu

#7 Příspěvek od Alice »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
Ran by Kotyna (ATTENTION: The logged in user is not administrator) on PC-AJANEK on 05-07-2015 20:54:50
Running from C:\Users\Kotyna\Desktop
Loaded Profiles: KoulovaA & Kotyna (Available Profiles: KoulovaA & Kotyna & ajajan)
Platform: Windows 8.1 Connected (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> csrss.exe
Failed to access process -> winlogon.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> dwm.exe
Failed to access process -> OmniServ.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> RtkAudioService64.exe
Failed to access process -> RAVBg64.exe
Failed to access process -> svchost.exe
Failed to access process -> wlanext.exe
Failed to access process -> AvastSvc.exe
Failed to access process -> conhost.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> armsvc.exe
Failed to access process -> AERTSr64.exe
Failed to access process -> svchost.exe
Failed to access process -> mDNSResponder.exe
Failed to access process -> svchost.exe
Failed to access process -> dasHost.exe
Failed to access process -> dragon_updater.exe
Failed to access process -> HPWMISVC.exe
Failed to access process -> HeciServer.exe
Failed to access process -> mfevtps.exe
Failed to access process -> PnkBstrA.exe
Failed to access process -> PnkBstrB.exe
Failed to access process -> ssins.exe
Failed to access process -> svchost.exe
Failed to access process -> TuneUpUtilitiesService64.exe
Failed to access process -> McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
Failed to access process -> mfefire.exe
Failed to access process -> McSvHost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> HPSA_Service.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> NASvc.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Failed to access process -> opvapp.exe
Failed to access process -> WmiPrvSE.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
() C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
Failed to access process -> WmiPrvSE.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Failed to access process -> SearchProtocolHost.exe
Failed to access process -> SearchFilterHost.exe
(forum.viry.cz) C:\Users\Kotyna\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7510896 2014-01-14] (Realtek Semiconductor)
HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [3962936 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [415288 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [415288 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2803440 2013-12-13] (Synaptics Incorporated)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-10-08] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-13] (Avast Software s.r.o.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\RunOnce: [MSPCLOCK] => rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000}
HKLM\...\RunOnce: [MSPQM] => rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196}
HKLM\...\RunOnce: [MSKSSRV] => rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196}
HKLM\...\RunOnce: [MSTEE.CxTransform] => rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interf (the data entry has 11 more characters).
HKLM\...\RunOnce: [MSTEE.Splitter] => rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interf (the data entry has 11 more characters).
HKLM\...\RunOnce: [WDM_DRMKAUD] => rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\Windows\inf\WDMAUDIO.inf,WDM_DRMKAUD. (the data entry has 17 more characters).
HKLM-x32\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast\setup\emupdate\71d5f7a4-4254-4c48-bd30-7b9448c2bbbe.exe [183232 2015-06-23] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-05-07] (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
URLSearchHook: [S-1-5-21-2592885859-3292131433-3858698835-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?PC=WCUG&FORM ... earchTerms}
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?PC=WCUG&FORM ... earchTerms}
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {097A9339-E635-4D1D-91B9-53C1D2B63A87} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {19B9F848-0C34-4607-BDD9-739F047362D8} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {1B3DBC27-D6A1-45EF-A14F-C6D88E109C3B} URL = http://www.search.ask.com/web?tpid=ATUS ... psv=&pt=tb
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {540A0B5D-36A8-4F66-9331-37E2CAFAB0A8} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {67ADAF9F-78F2-42D8-AF6C-07286CF2D405} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {9BFC5A1E-A56F-403A-956C-899DC51419CF} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {9F07A403-F77C-4DE0-BD87-F87ECA833576} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {A16B8375-A194-430F-AC0E-03F7EE72D9A8} URL = http://search.seznam.cz/?q={searchTerms ... chmodule_1
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {C099FCD3-A8D7-4F40-9E08-BF226956BFCE} URL = http://www.novinky.cz/hledej?w={searchT ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {C4339E82-3611-415D-86F8-1FF202B5397F} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-07] (Avast Software s.r.o.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05] (Google Inc.)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-07] (Avast Software s.r.o.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05] (Google Inc.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05] (Google Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2014-04-25] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2014-04-25] (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{30E1B1AE-59C3-4294-937C-04EAAACFA530}: [DhcpNameServer] 10.98.231.66 10.98.0.227
Tcpip\..\Interfaces\{D134968B-B3C4-4016-8BA4-C5BFB74013D3}: [DhcpNameServer] 213.46.172.36 213.46.172.37

FireFox:
========
FF ProfilePath: C:\Users\Kotyna\AppData\Roaming\Mozilla\Firefox\Profiles\yxz9ma7o.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_194.dll [2015-07-04] ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-07-04] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Extension: Seznam lištička - C:\Users\Kotyna\AppData\Roaming\Mozilla\Firefox\Profiles\yxz9ma7o.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-06-16]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-07]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-09-16]

Chrome:
=======
CHR Profile: C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-08]
CHR Extension: (Google Docs) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-31]
CHR Extension: (Google Drive) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-31]
CHR Extension: (YouTube) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-31]
CHR Extension: (Google Search) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-31]
CHR Extension: (Avast SafePrice) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-04-13]
CHR Extension: (Google Sheets) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-08]
CHR Extension: (Avast Online Security) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-04-07]
CHR Extension: (Google Wallet) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-31]
CHR Extension: (Gmail) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-31]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-07]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-07] (Avast Software s.r.o.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2139328 2014-05-27] (Comodo Security Solutions, Inc.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2014-01-13] (Hewlett-Packard Company) [File not signed]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-10-08] (Hewlett-Packard Development Company, L.P.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [38792 2014-10-29] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [33088 2014-10-29] (Microsoft Corporation)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-29] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-09-04] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 NlaSvc; C:\Windows\System32\svchost.exe [38792 2014-10-29] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [33088 2014-10-29] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [38792 2014-10-29] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [33088 2014-10-29] (Microsoft Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [88064 2014-03-28] (Softex Inc.) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-01-30] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2014-12-23] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2015-01-02] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-09] (Realtek Semiconductor)
R2 ssinstall; C:\Windows\SysWOW64\ssins.exe [2324216 2015-04-08] (PS Media s.r.o.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2589496 2014-10-17] (AVG Technologies)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-05-07] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-05-07] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-05-07] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-05-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-05-07] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-06-26] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-05-07] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-05-07] ()
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R3 GPIO; C:\Windows\System32\drivers\iaiogpioe.sys [31232 2013-11-11] (Intel Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2014-01-23] (Intel Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [291544 2014-01-04] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3379416 2014-03-22] (Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [29936 2013-12-13] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2013-12-13] (Synaptics Incorporated)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-09-09] (TuneUp Software)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-05 20:54 - 2015-07-05 20:55 - 00026860 _____ C:\Users\Kotyna\Desktop\FRST.txt
2015-07-05 20:49 - 2015-07-05 20:50 - 00112640 _____ (forum.viry.cz) C:\Users\Kotyna\Desktop\FRSTLauncher.exe
2015-07-05 20:46 - 2015-07-05 20:54 - 00000000 ____D C:\FRST
2015-07-05 20:42 - 2015-07-05 20:42 - 02112512 _____ (Farbar) C:\Users\Kotyna\Desktop\FRST64.exe
2015-07-05 12:03 - 2015-07-05 10:44 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-05 10:48 - 2015-07-05 10:29 - 00001788 _____ C:\zoek-results2015-07-05-082946.log
2015-07-05 10:23 - 2015-07-05 12:32 - 00034934 _____ C:\zoek-results.log
2015-07-05 10:13 - 2015-07-05 11:58 - 00000000 ____D C:\zoek_backup
2015-07-05 10:10 - 2015-07-05 10:10 - 01308672 _____ C:\Users\Kotyna\Desktop\zoek.exe
2015-07-04 23:56 - 2015-07-05 00:02 - 941340672 _____ C:\Users\Kotyna\Downloads\Navždy spolu CZ-dabing (2012) NOVINKA.avi
2015-07-04 23:50 - 2015-07-04 23:59 - 783577088 _____ C:\Users\Kotyna\Downloads\Neobyčejný život Timothyho Greena-Odd Life of Timothy Green, The (2012) Komedie Drama Fantasy Rodinný CZ dabing.avi
2015-07-04 23:48 - 2015-07-04 23:58 - 778887168 _____ C:\Users\Kotyna\Downloads\Nic nás nerozdělí 2012 CZ Dabing.avi
2015-07-04 23:38 - 2015-07-04 23:42 - 730267648 _____ C:\Users\Kotyna\Downloads\V pasti (2005)CZdab.avi
2015-07-04 23:29 - 2015-07-04 23:35 - 1007022080 _____ C:\Users\Kotyna\Downloads\Zimní příběh [Winters Tale] (2014) CZ dabing.avi
2015-07-04 23:19 - 2015-07-04 23:26 - 783331328 _____ C:\Users\Kotyna\Downloads\Andělé všedního dne (2014) CZfilm.avi
2015-07-04 23:17 - 2015-07-04 23:23 - 733585196 _____ C:\Users\Kotyna\Downloads\Milionář z chatrče CZ Dabing.avi
2015-07-04 20:47 - 2015-07-04 21:05 - 731587350 _____ C:\Users\Kotyna\Downloads\Proroctví Knowing (2009) CZdub.avi
2015-07-04 20:43 - 2015-07-04 21:05 - 928528384 _____ C:\Users\Kotyna\Downloads\Pokani-CZ-dabing-2007--WAR.avi
2015-07-04 20:41 - 2015-07-04 21:02 - 787724288 _____ C:\Users\Kotyna\Downloads\Terapie láskou CZ-dabing (2012) NOVINKA.avi
2015-07-04 20:34 - 2015-07-04 21:05 - 1101279232 _____ C:\Users\Kotyna\Downloads\Sin City 2 Ženská, pre ktorú by som vraždil (2014) CZ-Dabing NOVINKY.avi
2015-07-04 20:31 - 2015-07-04 20:56 - 919232978 _____ C:\Users\Kotyna\Downloads\Mocný-vládce-Oz-(2013)-CZ-dabing.avi
2015-07-04 20:28 - 2015-07-04 20:43 - 782127104 _____ C:\Users\Kotyna\Downloads\Apokalypsa v Hollywoodu CZ DABING 2013.avi
2015-07-04 20:27 - 2015-07-04 20:51 - 890165248 _____ C:\Users\Kotyna\Downloads\Upíří akademie Vampire Academy Blood Sisters (2014) CZdub.avi
2015-07-04 20:26 - 2015-07-04 20:44 - 734208000 _____ C:\Users\Kotyna\Downloads\Lucy (2014) CZ dabing.avi
2015-07-04 20:20 - 2015-07-04 20:42 - 1017452544 _____ C:\Users\Kotyna\Downloads\Transcendence Transcendence (2014) CZdub.avi
2015-07-04 20:13 - 2015-07-04 20:18 - 860028694 _____ C:\Users\Kotyna\Downloads\Jupiter vychází (2015) CZ-Dabing NOVINKA.avi
2015-07-04 20:11 - 2015-07-04 20:24 - 1024780248 _____ C:\Users\Kotyna\Downloads\Imaginárium Dr. Parnasse 2009 CZ dabing.avi
2015-07-04 20:09 - 2015-07-04 20:11 - 00000000 ____D C:\Users\Kotyna\Downloads\Merlin
2015-07-04 20:07 - 2015-07-04 20:12 - 791291904 _____ C:\Users\Kotyna\Downloads\Mordecai, Grandiozni pripad.avi
2015-07-04 20:07 - 2015-07-04 20:09 - 00000000 ____D C:\Users\Kotyna\Downloads\2 socky
2015-07-04 18:42 - 2015-07-04 18:42 - 00000000 ____D C:\Users\Kotyna\AppData\Local\Macromedia
2015-07-04 16:16 - 2015-07-04 18:18 - 00000000 ____D C:\AdwCleaner
2015-07-04 16:14 - 2015-07-04 16:15 - 02244096 _____ C:\Users\Kotyna\Desktop\adwcleaner_4.207.exe
2015-07-04 13:23 - 2015-07-05 20:41 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-04 13:11 - 2015-07-04 13:11 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(2).exe
2015-07-04 13:09 - 2015-07-04 14:57 - 00000000 ____D C:\Program Files\trend micro
2015-07-04 13:09 - 2015-07-04 13:09 - 00000000 ____D C:\rsit
2015-07-04 13:08 - 2015-07-04 13:08 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(1).exe
2015-06-29 16:40 - 2015-07-04 20:11 - 00000000 ____D C:\Users\Kotyna\Downloads\Nové filmy
2015-06-27 19:06 - 2015-06-27 19:15 - 1468043264 _____ C:\Users\Kotyna\Downloads\Male zeny 1994 cz český dabing.avi
2015-06-26 21:32 - 2015-06-26 22:01 - 937294946 _____ C:\Users\Kotyna\Downloads\Ghost Rider 2 Duch pomsty-Ghost Rider Spirit of Vengeance (2011) Akční Fantasy Thriller CZ dabing.avi
2015-06-26 21:32 - 2015-06-26 21:59 - 829683712 _____ C:\Users\Kotyna\Downloads\Dárce (2014)CZ Dabing,drama, fantasy, sci-f.avi
2015-06-26 18:52 - 2015-06-26 19:34 - 1576656896 _____ C:\Users\Kotyna\Downloads\Dohola (2001) HIT cz dabing.avi
2015-06-15 12:05 - 2015-06-15 12:06 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\Mozilla
2015-06-15 12:05 - 2015-06-15 12:06 - 00000000 ____D C:\Users\Kotyna\AppData\Local\Mozilla
2015-06-15 12:05 - 2015-06-15 12:05 - 00001182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-06-15 12:05 - 2015-06-15 12:05 - 00001170 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-06-15 12:05 - 2015-06-15 12:05 - 00000000 ____D C:\ProgramData\Mozilla
2015-06-15 12:05 - 2015-06-15 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-15 12:05 - 2015-06-15 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-06-15 11:58 - 2015-06-15 11:58 - 40140168 _____ C:\Users\Kotyna\Downloads\FirefoxSetup38.0.5cz.exe
2015-06-14 11:57 - 2015-06-14 11:57 - 00000000 ____D C:\Users\Kotyna\AppData\Local\GWX
2015-06-10 20:35 - 2015-06-10 20:35 - 00000000 ____D C:\43cfc473f2703a71676fe2ba
2015-06-10 20:05 - 2015-05-25 15:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 20:05 - 2015-05-25 15:07 - 01430528 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 20:05 - 2015-05-22 15:08 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 20:05 - 2015-05-21 18:47 - 04177920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 20:05 - 2015-05-21 15:08 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 01020928 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00756736 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00422912 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 20:05 - 2015-04-25 04:34 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 20:05 - 2015-04-25 04:33 - 00549888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-10 20:05 - 2015-04-17 00:07 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 20:05 - 2015-04-16 08:17 - 00325464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2015-06-10 20:05 - 2015-04-14 00:37 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll
2015-06-10 20:05 - 2015-04-14 00:34 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll
2015-06-10 20:05 - 2015-04-10 02:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2015-06-10 20:05 - 2015-04-10 02:17 - 01018880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2015-06-10 20:05 - 2015-04-09 00:07 - 00410336 _____ C:\Windows\system32\ApnDatabase.xml
2015-06-10 20:05 - 2015-04-02 00:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-06-10 20:05 - 2015-04-02 00:30 - 02483712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-06-10 20:05 - 2015-04-01 06:21 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2015-06-10 20:05 - 2015-04-01 06:18 - 00468480 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2015-06-10 20:05 - 2015-04-01 06:17 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2015-06-10 20:05 - 2015-04-01 06:08 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2015-06-10 20:05 - 2015-04-01 05:46 - 03633664 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-06-10 20:05 - 2015-04-01 05:17 - 02551808 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-06-10 20:05 - 2015-04-01 05:17 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2015-06-10 20:05 - 2015-04-01 04:53 - 00391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2015-06-10 20:05 - 2015-04-01 04:53 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2015-06-10 20:05 - 2015-04-01 04:45 - 02749952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2015-06-10 20:05 - 2015-04-01 04:45 - 00699392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2015-06-10 20:05 - 2015-04-01 04:14 - 01920000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2015-06-10 20:05 - 2015-04-01 04:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2015-06-10 20:05 - 2015-03-20 05:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\compstui.dll
2015-06-10 20:05 - 2015-03-20 05:08 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2015-06-10 20:05 - 2015-03-20 04:37 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2015-06-10 20:05 - 2015-03-20 04:07 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-06-10 20:05 - 2015-03-02 03:43 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2015-06-10 20:05 - 2015-03-02 03:21 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastapi.dll
2015-06-10 20:04 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 20:04 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-10 20:04 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-10 20:04 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-10 20:04 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-10 20:04 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-10 20:04 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-10 20:04 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-10 20:04 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-10 20:04 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-10 20:04 - 2015-05-23 04:47 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-06-10 20:04 - 2015-05-23 04:43 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-06-10 20:04 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-10 20:04 - 2015-05-23 04:38 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-10 20:04 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-10 20:04 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-10 20:04 - 2015-05-23 04:28 - 01042944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-06-10 20:04 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-10 20:04 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-10 20:04 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-10 20:04 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 20:04 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 20:04 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 20:04 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 20:04 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 20:04 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 20:04 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 20:04 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 20:04 - 2015-05-22 20:23 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-06-10 20:04 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 20:04 - 2015-05-22 20:15 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-06-10 20:04 - 2015-05-22 20:09 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-06-10 20:04 - 2015-05-22 20:08 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 20:04 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 20:04 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 20:04 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 20:04 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 20:04 - 2015-05-22 19:49 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-06-10 20:04 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 20:04 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 20:04 - 2015-04-09 00:41 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rgb9rast.dll
2015-06-08 16:04 - 2015-06-08 16:04 - 00024833 _____ C:\Users\Kotyna\Desktop\Headway.odt
2015-06-08 16:02 - 2015-06-08 16:02 - 00003584 _____ C:\Users\Kotyna\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-08 11:57 - 2015-06-14 21:38 - 00000000 ____D C:\Users\Kotyna\Desktop\Nová složka (2)

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-05 20:50 - 2014-12-18 13:54 - 01106768 _____ C:\Windows\WindowsUpdate.log
2015-07-05 20:47 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness
2015-07-05 20:39 - 2014-04-26 06:40 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2015-07-05 20:31 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-07-05 12:21 - 2015-04-08 09:34 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\Seznam.cz
2015-07-05 12:17 - 2014-12-20 21:44 - 00000000 ____D C:\Users\Kotyna\Documents\Youcam
2015-07-05 12:15 - 2014-12-18 21:46 - 00000976 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-05 12:11 - 2014-12-18 21:46 - 00000980 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-05 12:10 - 2015-04-08 00:04 - 00000000 _____ C:\Windows\SysWOW64\sinstall.log
2015-07-05 12:10 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-05 12:09 - 2014-03-18 11:44 - 00063934 _____ C:\Windows\PFRO.log
2015-07-05 12:09 - 2013-08-22 16:46 - 00059667 _____ C:\Windows\setupact.log
2015-07-05 02:44 - 2015-03-13 11:41 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\vlc
2015-07-04 13:25 - 2015-04-07 23:56 - 00000000 ____D C:\Users\Kotyna\AppData\Local\Adobe
2015-06-28 20:06 - 2015-01-01 21:37 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\Tropico 4
2015-06-26 15:57 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2015-06-26 15:47 - 2015-04-07 19:11 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-06-23 17:23 - 2014-12-18 21:47 - 00002210 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-20 13:22 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\NDF
2015-06-20 05:02 - 2014-12-21 21:03 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-20 05:02 - 2014-12-21 21:03 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-14 15:14 - 2014-12-20 21:38 - 00000000 ____D C:\Users\Kotyna
2015-06-14 14:49 - 2014-12-23 00:21 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-14 14:49 - 2014-12-23 00:21 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-14 14:49 - 2013-08-22 17:36 - 00000000 ___RD C:\Windows\ToastData
2015-06-13 20:05 - 2014-04-26 15:47 - 00768392 _____ C:\Windows\system32\perfh005.dat
2015-06-13 20:05 - 2014-04-26 15:47 - 00166490 _____ C:\Windows\system32\perfc005.dat
2015-06-13 20:05 - 2014-03-18 11:53 - 01883040 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-13 19:10 - 2015-04-07 23:55 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-06-11 19:41 - 2013-08-22 16:44 - 00405824 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-11 19:36 - 2015-04-05 16:23 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-06-11 19:36 - 2015-04-05 16:23 - 00000000 ___SD C:\Windows\system32\GWX
2015-06-11 19:36 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-10 20:35 - 2014-12-22 11:46 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-10 20:35 - 2014-12-22 11:46 - 00000000 ____D C:\Windows\system32\MRT

==================== Files in the root of some directories =======

2015-06-08 16:02 - 2015-06-08 16:02 - 0003584 _____ () C:\Users\Kotyna\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


ATTENTION: ==> Could not access BCD. Check to make sure user is administrator or see Addition.txt for additional information.




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: (Windows) (Fixed) (Total:448.18 GB) (Free:160.8 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:16.56 GB) (Free:1.51 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Available physical RAM: 1898.15 MB
Total physical RAM: 3984.27 MB
Percentage of memory in use: 52%

==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job =>
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job =>
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job =>

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: McAfee Firewall (Disabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Kotyna\Desktop" je 94453 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Alice
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 08 kvě 2015 11:02

Re: Preventivní kontrola logu

#8 Příspěvek od Alice »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
Ran by Kotyna (ATTENTION: The logged in user is not administrator) on PC-AJANEK on 05-07-2015 20:54:50
Running from C:\Users\Kotyna\Desktop
Loaded Profiles: KoulovaA & Kotyna (Available Profiles: KoulovaA & Kotyna & ajajan)
Platform: Windows 8.1 Connected (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> csrss.exe
Failed to access process -> winlogon.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> dwm.exe
Failed to access process -> OmniServ.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> RtkAudioService64.exe
Failed to access process -> RAVBg64.exe
Failed to access process -> svchost.exe
Failed to access process -> wlanext.exe
Failed to access process -> AvastSvc.exe
Failed to access process -> conhost.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> armsvc.exe
Failed to access process -> AERTSr64.exe
Failed to access process -> svchost.exe
Failed to access process -> mDNSResponder.exe
Failed to access process -> svchost.exe
Failed to access process -> dasHost.exe
Failed to access process -> dragon_updater.exe
Failed to access process -> HPWMISVC.exe
Failed to access process -> HeciServer.exe
Failed to access process -> mfevtps.exe
Failed to access process -> PnkBstrA.exe
Failed to access process -> PnkBstrB.exe
Failed to access process -> ssins.exe
Failed to access process -> svchost.exe
Failed to access process -> TuneUpUtilitiesService64.exe
Failed to access process -> McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
Failed to access process -> mfefire.exe
Failed to access process -> McSvHost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> HPSA_Service.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> NASvc.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Failed to access process -> opvapp.exe
Failed to access process -> WmiPrvSE.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
() C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
Failed to access process -> WmiPrvSE.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Failed to access process -> SearchProtocolHost.exe
Failed to access process -> SearchFilterHost.exe
(forum.viry.cz) C:\Users\Kotyna\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7510896 2014-01-14] (Realtek Semiconductor)
HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [3962936 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [415288 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [415288 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2803440 2013-12-13] (Synaptics Incorporated)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-10-08] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-13] (Avast Software s.r.o.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\RunOnce: [MSPCLOCK] => rundll32.exe streamci,StreamingDeviceSetup {97ebaacc-95bd-11d0-a3ea-00a0c9223196},{53172480-4791-11D0-A5D6-28DB04C10000},{53172480-4791-11D0-A5D6-28DB04C10000}
HKLM\...\RunOnce: [MSPQM] => rundll32.exe streamci,StreamingDeviceSetup {DDF4358E-BB2C-11D0-A42F-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196},{97EBAACB-95BD-11D0-A3EA-00A0C9223196}
HKLM\...\RunOnce: [MSKSSRV] => rundll32.exe streamci,StreamingDeviceSetup {96E080C7-143C-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196},{3C0D501A-140B-11D1-B40F-00A0C9223196}
HKLM\...\RunOnce: [MSTEE.CxTransform] => rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},{CF1DDA2C-9743-11D0-A3EE-00A0C9223196},C:\Windows\inf\ksfilter.inf,MSTEE.Interf (the data entry has 11 more characters).
HKLM\...\RunOnce: [MSTEE.Splitter] => rundll32.exe streamci,StreamingDeviceSetup {cfd669f1-9bc2-11d0-8299-0000f822fe8a},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},{0A4252A0-7E70-11D0-A5D6-28DB04C10000},C:\Windows\inf\ksfilter.inf,MSTEE.Interf (the data entry has 11 more characters).
HKLM\...\RunOnce: [WDM_DRMKAUD] => rundll32.exe streamci,StreamingDeviceSetup {EEC12DB6-AD9C-4168-8658-B03DAEF417FE},{ABD61E00-9350-47e2-A632-4438B90C6641},{FFBB6E3F-CCFE-4D84-90D9-421418B03A8E},C:\Windows\inf\WDMAUDIO.inf,WDM_DRMKAUD. (the data entry has 17 more characters).
HKLM-x32\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast\setup\emupdate\71d5f7a4-4254-4c48-bd30-7b9448c2bbbe.exe [183232 2015-06-23] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-05-07] (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
URLSearchHook: [S-1-5-21-2592885859-3292131433-3858698835-1001] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?PC=WCUG&FORM ... earchTerms}
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?PC=WCUG&FORM ... earchTerms}
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {097A9339-E635-4D1D-91B9-53C1D2B63A87} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {19B9F848-0C34-4607-BDD9-739F047362D8} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {1B3DBC27-D6A1-45EF-A14F-C6D88E109C3B} URL = http://www.search.ask.com/web?tpid=ATUS ... psv=&pt=tb
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {540A0B5D-36A8-4F66-9331-37E2CAFAB0A8} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {67ADAF9F-78F2-42D8-AF6C-07286CF2D405} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {9BFC5A1E-A56F-403A-956C-899DC51419CF} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {9F07A403-F77C-4DE0-BD87-F87ECA833576} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {A16B8375-A194-430F-AC0E-03F7EE72D9A8} URL = http://search.seznam.cz/?q={searchTerms ... chmodule_1
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {C099FCD3-A8D7-4F40-9E08-BF226956BFCE} URL = http://www.novinky.cz/hledej?w={searchT ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {C4339E82-3611-415D-86F8-1FF202B5397F} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-07] (Avast Software s.r.o.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05] (Google Inc.)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-07] (Avast Software s.r.o.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05] (Google Inc.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05] (Google Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2014-04-25] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2014-04-25] (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{30E1B1AE-59C3-4294-937C-04EAAACFA530}: [DhcpNameServer] 10.98.231.66 10.98.0.227
Tcpip\..\Interfaces\{D134968B-B3C4-4016-8BA4-C5BFB74013D3}: [DhcpNameServer] 213.46.172.36 213.46.172.37

FireFox:
========
FF ProfilePath: C:\Users\Kotyna\AppData\Roaming\Mozilla\Firefox\Profiles\yxz9ma7o.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_194.dll [2015-07-04] ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-07-04] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Extension: Seznam lištička - C:\Users\Kotyna\AppData\Roaming\Mozilla\Firefox\Profiles\yxz9ma7o.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-06-16]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-07]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-09-16]

Chrome:
=======
CHR Profile: C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-08]
CHR Extension: (Google Docs) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-31]
CHR Extension: (Google Drive) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-31]
CHR Extension: (YouTube) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-31]
CHR Extension: (Google Search) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-31]
CHR Extension: (Avast SafePrice) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-04-13]
CHR Extension: (Google Sheets) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-08]
CHR Extension: (Avast Online Security) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-04-07]
CHR Extension: (Google Wallet) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-31]
CHR Extension: (Gmail) - C:\Users\Kotyna\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-31]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-07]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-07] (Avast Software s.r.o.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2139328 2014-05-27] (Comodo Security Solutions, Inc.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2014-01-13] (Hewlett-Packard Company) [File not signed]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-10-08] (Hewlett-Packard Development Company, L.P.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [38792 2014-10-29] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [33088 2014-10-29] (Microsoft Corporation)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-29] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-09-04] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 NlaSvc; C:\Windows\System32\svchost.exe [38792 2014-10-29] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [33088 2014-10-29] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [38792 2014-10-29] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [33088 2014-10-29] (Microsoft Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [88064 2014-03-28] (Softex Inc.) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-01-30] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2014-12-23] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2015-01-02] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-09] (Realtek Semiconductor)
R2 ssinstall; C:\Windows\SysWOW64\ssins.exe [2324216 2015-04-08] (PS Media s.r.o.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2589496 2014-10-17] (AVG Technologies)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-05-07] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-05-07] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-05-07] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-05-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-05-07] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-06-26] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-05-07] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-05-07] ()
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R3 GPIO; C:\Windows\System32\drivers\iaiogpioe.sys [31232 2013-11-11] (Intel Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2014-01-23] (Intel Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [291544 2014-01-04] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3379416 2014-03-22] (Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [29936 2013-12-13] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2013-12-13] (Synaptics Incorporated)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-09-09] (TuneUp Software)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-05 20:54 - 2015-07-05 20:55 - 00026860 _____ C:\Users\Kotyna\Desktop\FRST.txt
2015-07-05 20:49 - 2015-07-05 20:50 - 00112640 _____ (forum.viry.cz) C:\Users\Kotyna\Desktop\FRSTLauncher.exe
2015-07-05 20:46 - 2015-07-05 20:54 - 00000000 ____D C:\FRST
2015-07-05 20:42 - 2015-07-05 20:42 - 02112512 _____ (Farbar) C:\Users\Kotyna\Desktop\FRST64.exe
2015-07-05 12:03 - 2015-07-05 10:44 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-05 10:48 - 2015-07-05 10:29 - 00001788 _____ C:\zoek-results2015-07-05-082946.log
2015-07-05 10:23 - 2015-07-05 12:32 - 00034934 _____ C:\zoek-results.log
2015-07-05 10:13 - 2015-07-05 11:58 - 00000000 ____D C:\zoek_backup
2015-07-05 10:10 - 2015-07-05 10:10 - 01308672 _____ C:\Users\Kotyna\Desktop\zoek.exe
2015-07-04 23:56 - 2015-07-05 00:02 - 941340672 _____ C:\Users\Kotyna\Downloads\Navždy spolu CZ-dabing (2012) NOVINKA.avi
2015-07-04 23:50 - 2015-07-04 23:59 - 783577088 _____ C:\Users\Kotyna\Downloads\Neobyčejný život Timothyho Greena-Odd Life of Timothy Green, The (2012) Komedie Drama Fantasy Rodinný CZ dabing.avi
2015-07-04 23:48 - 2015-07-04 23:58 - 778887168 _____ C:\Users\Kotyna\Downloads\Nic nás nerozdělí 2012 CZ Dabing.avi
2015-07-04 23:38 - 2015-07-04 23:42 - 730267648 _____ C:\Users\Kotyna\Downloads\V pasti (2005)CZdab.avi
2015-07-04 23:29 - 2015-07-04 23:35 - 1007022080 _____ C:\Users\Kotyna\Downloads\Zimní příběh [Winters Tale] (2014) CZ dabing.avi
2015-07-04 23:19 - 2015-07-04 23:26 - 783331328 _____ C:\Users\Kotyna\Downloads\Andělé všedního dne (2014) CZfilm.avi
2015-07-04 23:17 - 2015-07-04 23:23 - 733585196 _____ C:\Users\Kotyna\Downloads\Milionář z chatrče CZ Dabing.avi
2015-07-04 20:47 - 2015-07-04 21:05 - 731587350 _____ C:\Users\Kotyna\Downloads\Proroctví Knowing (2009) CZdub.avi
2015-07-04 20:43 - 2015-07-04 21:05 - 928528384 _____ C:\Users\Kotyna\Downloads\Pokani-CZ-dabing-2007--WAR.avi
2015-07-04 20:41 - 2015-07-04 21:02 - 787724288 _____ C:\Users\Kotyna\Downloads\Terapie láskou CZ-dabing (2012) NOVINKA.avi
2015-07-04 20:34 - 2015-07-04 21:05 - 1101279232 _____ C:\Users\Kotyna\Downloads\Sin City 2 Ženská, pre ktorú by som vraždil (2014) CZ-Dabing NOVINKY.avi
2015-07-04 20:31 - 2015-07-04 20:56 - 919232978 _____ C:\Users\Kotyna\Downloads\Mocný-vládce-Oz-(2013)-CZ-dabing.avi
2015-07-04 20:28 - 2015-07-04 20:43 - 782127104 _____ C:\Users\Kotyna\Downloads\Apokalypsa v Hollywoodu CZ DABING 2013.avi
2015-07-04 20:27 - 2015-07-04 20:51 - 890165248 _____ C:\Users\Kotyna\Downloads\Upíří akademie Vampire Academy Blood Sisters (2014) CZdub.avi
2015-07-04 20:26 - 2015-07-04 20:44 - 734208000 _____ C:\Users\Kotyna\Downloads\Lucy (2014) CZ dabing.avi
2015-07-04 20:20 - 2015-07-04 20:42 - 1017452544 _____ C:\Users\Kotyna\Downloads\Transcendence Transcendence (2014) CZdub.avi
2015-07-04 20:13 - 2015-07-04 20:18 - 860028694 _____ C:\Users\Kotyna\Downloads\Jupiter vychází (2015) CZ-Dabing NOVINKA.avi
2015-07-04 20:11 - 2015-07-04 20:24 - 1024780248 _____ C:\Users\Kotyna\Downloads\Imaginárium Dr. Parnasse 2009 CZ dabing.avi
2015-07-04 20:09 - 2015-07-04 20:11 - 00000000 ____D C:\Users\Kotyna\Downloads\Merlin
2015-07-04 20:07 - 2015-07-04 20:12 - 791291904 _____ C:\Users\Kotyna\Downloads\Mordecai, Grandiozni pripad.avi
2015-07-04 20:07 - 2015-07-04 20:09 - 00000000 ____D C:\Users\Kotyna\Downloads\2 socky
2015-07-04 18:42 - 2015-07-04 18:42 - 00000000 ____D C:\Users\Kotyna\AppData\Local\Macromedia
2015-07-04 16:16 - 2015-07-04 18:18 - 00000000 ____D C:\AdwCleaner
2015-07-04 16:14 - 2015-07-04 16:15 - 02244096 _____ C:\Users\Kotyna\Desktop\adwcleaner_4.207.exe
2015-07-04 13:23 - 2015-07-05 20:41 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-04 13:11 - 2015-07-04 13:11 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(2).exe
2015-07-04 13:09 - 2015-07-04 14:57 - 00000000 ____D C:\Program Files\trend micro
2015-07-04 13:09 - 2015-07-04 13:09 - 00000000 ____D C:\rsit
2015-07-04 13:08 - 2015-07-04 13:08 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(1).exe
2015-06-29 16:40 - 2015-07-04 20:11 - 00000000 ____D C:\Users\Kotyna\Downloads\Nové filmy
2015-06-27 19:06 - 2015-06-27 19:15 - 1468043264 _____ C:\Users\Kotyna\Downloads\Male zeny 1994 cz český dabing.avi
2015-06-26 21:32 - 2015-06-26 22:01 - 937294946 _____ C:\Users\Kotyna\Downloads\Ghost Rider 2 Duch pomsty-Ghost Rider Spirit of Vengeance (2011) Akční Fantasy Thriller CZ dabing.avi
2015-06-26 21:32 - 2015-06-26 21:59 - 829683712 _____ C:\Users\Kotyna\Downloads\Dárce (2014)CZ Dabing,drama, fantasy, sci-f.avi
2015-06-26 18:52 - 2015-06-26 19:34 - 1576656896 _____ C:\Users\Kotyna\Downloads\Dohola (2001) HIT cz dabing.avi
2015-06-15 12:05 - 2015-06-15 12:06 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\Mozilla
2015-06-15 12:05 - 2015-06-15 12:06 - 00000000 ____D C:\Users\Kotyna\AppData\Local\Mozilla
2015-06-15 12:05 - 2015-06-15 12:05 - 00001182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-06-15 12:05 - 2015-06-15 12:05 - 00001170 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-06-15 12:05 - 2015-06-15 12:05 - 00000000 ____D C:\ProgramData\Mozilla
2015-06-15 12:05 - 2015-06-15 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-15 12:05 - 2015-06-15 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-06-15 11:58 - 2015-06-15 11:58 - 40140168 _____ C:\Users\Kotyna\Downloads\FirefoxSetup38.0.5cz.exe
2015-06-14 11:57 - 2015-06-14 11:57 - 00000000 ____D C:\Users\Kotyna\AppData\Local\GWX
2015-06-10 20:35 - 2015-06-10 20:35 - 00000000 ____D C:\43cfc473f2703a71676fe2ba
2015-06-10 20:05 - 2015-05-25 15:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 20:05 - 2015-05-25 15:07 - 01430528 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 20:05 - 2015-05-22 15:08 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 20:05 - 2015-05-21 18:47 - 04177920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 20:05 - 2015-05-21 15:08 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 01020928 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00756736 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00422912 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 20:05 - 2015-04-25 04:34 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 20:05 - 2015-04-25 04:33 - 00549888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-10 20:05 - 2015-04-17 00:07 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 20:05 - 2015-04-16 08:17 - 00325464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2015-06-10 20:05 - 2015-04-14 00:37 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll
2015-06-10 20:05 - 2015-04-14 00:34 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll
2015-06-10 20:05 - 2015-04-10 02:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2015-06-10 20:05 - 2015-04-10 02:17 - 01018880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2015-06-10 20:05 - 2015-04-09 00:07 - 00410336 _____ C:\Windows\system32\ApnDatabase.xml
2015-06-10 20:05 - 2015-04-02 00:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-06-10 20:05 - 2015-04-02 00:30 - 02483712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-06-10 20:05 - 2015-04-01 06:21 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2015-06-10 20:05 - 2015-04-01 06:18 - 00468480 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2015-06-10 20:05 - 2015-04-01 06:17 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2015-06-10 20:05 - 2015-04-01 06:08 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2015-06-10 20:05 - 2015-04-01 05:46 - 03633664 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-06-10 20:05 - 2015-04-01 05:17 - 02551808 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-06-10 20:05 - 2015-04-01 05:17 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2015-06-10 20:05 - 2015-04-01 04:53 - 00391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2015-06-10 20:05 - 2015-04-01 04:53 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2015-06-10 20:05 - 2015-04-01 04:45 - 02749952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2015-06-10 20:05 - 2015-04-01 04:45 - 00699392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2015-06-10 20:05 - 2015-04-01 04:14 - 01920000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2015-06-10 20:05 - 2015-04-01 04:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2015-06-10 20:05 - 2015-03-20 05:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\compstui.dll
2015-06-10 20:05 - 2015-03-20 05:08 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2015-06-10 20:05 - 2015-03-20 04:37 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2015-06-10 20:05 - 2015-03-20 04:07 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-06-10 20:05 - 2015-03-02 03:43 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2015-06-10 20:05 - 2015-03-02 03:21 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastapi.dll
2015-06-10 20:04 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 20:04 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-10 20:04 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-10 20:04 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-10 20:04 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-10 20:04 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-10 20:04 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-10 20:04 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-10 20:04 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-10 20:04 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-10 20:04 - 2015-05-23 04:47 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-06-10 20:04 - 2015-05-23 04:43 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-06-10 20:04 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-10 20:04 - 2015-05-23 04:38 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-10 20:04 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-10 20:04 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-10 20:04 - 2015-05-23 04:28 - 01042944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-06-10 20:04 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-10 20:04 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-10 20:04 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-10 20:04 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 20:04 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 20:04 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 20:04 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 20:04 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 20:04 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 20:04 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 20:04 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 20:04 - 2015-05-22 20:23 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-06-10 20:04 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 20:04 - 2015-05-22 20:15 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-06-10 20:04 - 2015-05-22 20:09 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-06-10 20:04 - 2015-05-22 20:08 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 20:04 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 20:04 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 20:04 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 20:04 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 20:04 - 2015-05-22 19:49 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-06-10 20:04 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 20:04 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 20:04 - 2015-04-09 00:41 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rgb9rast.dll
2015-06-08 16:04 - 2015-06-08 16:04 - 00024833 _____ C:\Users\Kotyna\Desktop\Headway.odt
2015-06-08 16:02 - 2015-06-08 16:02 - 00003584 _____ C:\Users\Kotyna\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-08 11:57 - 2015-06-14 21:38 - 00000000 ____D C:\Users\Kotyna\Desktop\Nová složka (2)

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-05 20:50 - 2014-12-18 13:54 - 01106768 _____ C:\Windows\WindowsUpdate.log
2015-07-05 20:47 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness
2015-07-05 20:39 - 2014-04-26 06:40 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2015-07-05 20:31 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-07-05 12:21 - 2015-04-08 09:34 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\Seznam.cz
2015-07-05 12:17 - 2014-12-20 21:44 - 00000000 ____D C:\Users\Kotyna\Documents\Youcam
2015-07-05 12:15 - 2014-12-18 21:46 - 00000976 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-05 12:11 - 2014-12-18 21:46 - 00000980 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-05 12:10 - 2015-04-08 00:04 - 00000000 _____ C:\Windows\SysWOW64\sinstall.log
2015-07-05 12:10 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-05 12:09 - 2014-03-18 11:44 - 00063934 _____ C:\Windows\PFRO.log
2015-07-05 12:09 - 2013-08-22 16:46 - 00059667 _____ C:\Windows\setupact.log
2015-07-05 02:44 - 2015-03-13 11:41 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\vlc
2015-07-04 13:25 - 2015-04-07 23:56 - 00000000 ____D C:\Users\Kotyna\AppData\Local\Adobe
2015-06-28 20:06 - 2015-01-01 21:37 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\Tropico 4
2015-06-26 15:57 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2015-06-26 15:47 - 2015-04-07 19:11 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-06-23 17:23 - 2014-12-18 21:47 - 00002210 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-20 13:22 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\NDF
2015-06-20 05:02 - 2014-12-21 21:03 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-20 05:02 - 2014-12-21 21:03 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-14 15:14 - 2014-12-20 21:38 - 00000000 ____D C:\Users\Kotyna
2015-06-14 14:49 - 2014-12-23 00:21 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-14 14:49 - 2014-12-23 00:21 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-14 14:49 - 2013-08-22 17:36 - 00000000 ___RD C:\Windows\ToastData
2015-06-13 20:05 - 2014-04-26 15:47 - 00768392 _____ C:\Windows\system32\perfh005.dat
2015-06-13 20:05 - 2014-04-26 15:47 - 00166490 _____ C:\Windows\system32\perfc005.dat
2015-06-13 20:05 - 2014-03-18 11:53 - 01883040 _____ C:\Windows\system32\PerfStringBackup.INI
2015-06-13 19:10 - 2015-04-07 23:55 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-06-11 19:41 - 2013-08-22 16:44 - 00405824 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-11 19:36 - 2015-04-05 16:23 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-06-11 19:36 - 2015-04-05 16:23 - 00000000 ___SD C:\Windows\system32\GWX
2015-06-11 19:36 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-10 20:35 - 2014-12-22 11:46 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-10 20:35 - 2014-12-22 11:46 - 00000000 ____D C:\Windows\system32\MRT

==================== Files in the root of some directories =======

2015-06-08 16:02 - 2015-06-08 16:02 - 0003584 _____ () C:\Users\Kotyna\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


ATTENTION: ==> Could not access BCD. Check to make sure user is administrator or see Addition.txt for additional information.




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: (Windows) (Fixed) (Total:448.18 GB) (Free:160.8 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:16.56 GB) (Free:1.51 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Available physical RAM: 1898.15 MB
Total physical RAM: 3984.27 MB
Percentage of memory in use: 52%

==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job =>
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job =>
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job =>

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: McAfee Firewall (Disabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Kotyna\Desktop" je 94453 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Přílohy
Addition.zip
(8.36 KiB) Staženo 17 x

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivní kontrola logu

#9 Příspěvek od vyosek »

Je nutne FRST spustit pod uctem administratora, ve vasem pripade je to tento
KoulovaA (S-1-5-21-2592885859-3292131433-3858698835-1001 - Administrator - Enabled) => C:\Users\KoulovaA
jinak FRST nemuze ziskat plny pristup a provest dusledny sken\opravy
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Alice
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 08 kvě 2015 11:02

Re: Preventivní kontrola logu

#10 Příspěvek od Alice »

Snad už to takhle bude v pořádku :)

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
Ran by KoulovaA (administrator) on PC-AJANEK on 06-07-2015 11:45:00
Running from C:\Users\KoulovaA\Desktop
Loaded Profiles: KoulovaA & Kotyna (Available Profiles: KoulovaA & Kotyna & ajajan)
Platform: Windows 8.1 Connected (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
() C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
() C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Microsoft Corporation) C:\Windows\Temp\662E175E-4EB6-4BE2-A11F-BB9C81975F4E\DismHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe
(forum.viry.cz) C:\Users\KoulovaA\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7510896 2014-01-14] (Realtek Semiconductor)
HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [3962936 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [415288 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [415288 2014-03-28] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2803440 2013-12-13] (Synaptics Incorporated)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-10-08] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-13] (Avast Software s.r.o.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-12-18] (Electronic Arts)
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\RunOnce: [SeznamInstall-uninstall:bb8a75c57009f43ed56ed3b8cc48ccd2] => C:\Users\KoulovaA\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe [534528 2015-07-06] () <===== ATTENTION
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\MountPoints2: {dd0eea73-3dbb-11e4-825c-806e6f6e6963} - "E:\autorun.exe"
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Kotyna\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-04-02] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-05-07] (Avast Software s.r.o.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?PC=WCUG&FORM ... earchTerms}
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search?PC=WCUG&FORM ... earchTerms}
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {097A9339-E635-4D1D-91B9-53C1D2B63A87} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {19B9F848-0C34-4607-BDD9-739F047362D8} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {1B3DBC27-D6A1-45EF-A14F-C6D88E109C3B} URL = http://www.search.ask.com/web?tpid=ATUS ... psv=&pt=tb
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {540A0B5D-36A8-4F66-9331-37E2CAFAB0A8} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {67ADAF9F-78F2-42D8-AF6C-07286CF2D405} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {9BFC5A1E-A56F-403A-956C-899DC51419CF} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {9F07A403-F77C-4DE0-BD87-F87ECA833576} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {A16B8375-A194-430F-AC0E-03F7EE72D9A8} URL = http://search.seznam.cz/?q={searchTerms ... chmodule_1
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {C099FCD3-A8D7-4F40-9E08-BF226956BFCE} URL = http://www.novinky.cz/hledej?w={searchT ... arch_12454
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {C4339E82-3611-415D-86F8-1FF202B5397F} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-07] (Avast Software s.r.o.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05] (Google Inc.)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-07] (Avast Software s.r.o.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05] (Google Inc.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-05] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-05] (Google Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2014-04-25] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2014-04-25] (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37
Tcpip\..\Interfaces\{30E1B1AE-59C3-4294-937C-04EAAACFA530}: [DhcpNameServer] 10.98.231.66 10.98.0.227
Tcpip\..\Interfaces\{D134968B-B3C4-4016-8BA4-C5BFB74013D3}: [DhcpNameServer] 213.46.172.36 213.46.172.37

FireFox:
========
FF ProfilePath: C:\Users\KoulovaA\AppData\Roaming\Mozilla\Firefox\Profiles\j0b6p7mp.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_194.dll [2015-07-04] ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-07-04] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Extension: Seznam lištička - C:\Users\KoulovaA\AppData\Roaming\Mozilla\Firefox\Profiles\j0b6p7mp.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-07-06]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-04-07]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-09-16]

Chrome:
=======
CHR Profile: C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-18]
CHR Extension: (Google Drive) - C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-18]
CHR Extension: (YouTube) - C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-18]
CHR Extension: (Google Search) - C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-18]
CHR Extension: (Avast SafePrice) - C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-06-03]
CHR Extension: (Bookmark Manager) - C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-06-27]
CHR Extension: (Avast Online Security) - C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-06-03]
CHR Extension: (Google Wallet) - C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-18]
CHR Extension: (Gmail) - C:\Users\KoulovaA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-18]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-07]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-07]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-05-07] (Avast Software s.r.o.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2139328 2014-05-27] (Comodo Security Solutions, Inc.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2014-01-13] (Hewlett-Packard Company) [File not signed]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-10-08] (Hewlett-Packard Development Company, L.P.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-29] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-09-04] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [88064 2014-03-28] (Softex Inc.) [File not signed]
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2004488 2015-07-06] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2014-12-23] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2015-01-02] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-09] (Realtek Semiconductor)
R2 ssinstall; C:\Windows\SysWOW64\ssins.exe [2324216 2015-04-08] (PS Media s.r.o.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2589496 2014-10-17] (AVG Technologies)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-05-07] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-05-07] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-05-07] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-05-07] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-05-07] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-06-26] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-05-07] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-05-07] ()
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R3 GPIO; C:\Windows\System32\drivers\iaiogpioe.sys [31232 2013-11-11] (Intel Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2014-01-23] (Intel Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [291544 2014-01-04] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3379416 2014-03-22] (Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [29936 2013-12-13] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2013-12-13] (Synaptics Incorporated)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-09-09] (TuneUp Software)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-06 11:45 - 2015-07-06 11:47 - 00027219 _____ C:\Users\KoulovaA\Desktop\FRST.txt
2015-07-06 11:42 - 2015-07-06 11:43 - 00112640 _____ (forum.viry.cz) C:\Users\KoulovaA\Desktop\FRSTLauncher.exe
2015-07-06 11:39 - 2015-07-06 11:40 - 02112512 _____ (Farbar) C:\Users\KoulovaA\Desktop\FRST64.exe
2015-07-06 11:36 - 2015-07-06 11:36 - 00000000 ____D C:\Users\KoulovaA\AppData\Local\VirtualStore
2015-07-06 11:34 - 2015-07-06 11:34 - 00000000 ____D C:\Users\KoulovaA\AppData\Roaming\Mozilla
2015-07-06 11:34 - 2015-07-06 11:34 - 00000000 ____D C:\Users\KoulovaA\AppData\Roaming\AVAST Software
2015-07-06 11:34 - 2015-07-06 11:34 - 00000000 ____D C:\Users\KoulovaA\AppData\Local\Mozilla
2015-07-05 22:19 - 2015-07-05 22:22 - 747872256 _____ C:\Users\Kotyna\Downloads\Scott Pilgrim proti zbytku sveta 2010.avi
2015-07-05 22:09 - 2015-07-05 22:13 - 739270590 _____ C:\Users\Kotyna\Downloads\29 a ješte panna.avi
2015-07-05 21:55 - 2015-07-05 21:59 - 732698624 _____ C:\Users\Kotyna\Downloads\Mafiánovi Family, The (2013) CZdub.avi
2015-07-05 21:53 - 2015-07-05 21:58 - 808682242 _____ C:\Users\Kotyna\Downloads\Spanish Movie (Spanish Movie) CZ.avi
2015-07-05 21:30 - 2015-07-05 21:34 - 1017190400 _____ C:\Users\Kotyna\Downloads\Kandidát CZ (2013).avi
2015-07-05 21:26 - 2015-07-05 21:29 - 909805770 _____ C:\Users\Kotyna\Downloads\fakju-pane-ucitely-cz.avi
2015-07-05 21:21 - 2015-07-05 21:25 - 888997888 _____ C:\Users\Kotyna\Downloads\Kronika CZ-dabing (2012) NOVINKA.avi
2015-07-05 21:05 - 2015-07-05 21:05 - 00008562 _____ C:\Users\Kotyna\Desktop\Addition.zip
2015-07-05 20:56 - 2015-07-05 20:57 - 00029363 _____ C:\Users\Kotyna\Desktop\Addition.txt
2015-07-05 20:54 - 2015-07-05 20:57 - 00049372 _____ C:\Users\Kotyna\Desktop\FRST.txt
2015-07-05 20:49 - 2015-07-05 20:50 - 00112640 _____ (forum.viry.cz) C:\Users\Kotyna\Desktop\FRSTLauncher.exe
2015-07-05 20:46 - 2015-07-06 11:45 - 00000000 ____D C:\FRST
2015-07-05 20:42 - 2015-07-05 20:42 - 02112512 _____ (Farbar) C:\Users\Kotyna\Desktop\FRST64.exe
2015-07-05 12:03 - 2015-07-05 10:44 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-05 10:48 - 2015-07-05 10:29 - 00001788 _____ C:\zoek-results2015-07-05-082946.log
2015-07-05 10:23 - 2015-07-05 12:32 - 00034934 _____ C:\zoek-results.log
2015-07-05 10:13 - 2015-07-05 11:58 - 00000000 ____D C:\zoek_backup
2015-07-05 10:10 - 2015-07-05 10:10 - 01308672 _____ C:\Users\Kotyna\Desktop\zoek.exe
2015-07-04 23:56 - 2015-07-05 00:02 - 941340672 _____ C:\Users\Kotyna\Downloads\Navždy spolu CZ-dabing (2012) NOVINKA.avi
2015-07-04 23:50 - 2015-07-04 23:59 - 783577088 _____ C:\Users\Kotyna\Downloads\Neobyčejný život Timothyho Greena-Odd Life of Timothy Green, The (2012) Komedie Drama Fantasy Rodinný CZ dabing.avi
2015-07-04 23:48 - 2015-07-04 23:58 - 778887168 _____ C:\Users\Kotyna\Downloads\Nic nás nerozdělí 2012 CZ Dabing.avi
2015-07-04 23:38 - 2015-07-04 23:42 - 730267648 _____ C:\Users\Kotyna\Downloads\V pasti (2005)CZdab.avi
2015-07-04 23:29 - 2015-07-04 23:35 - 1007022080 _____ C:\Users\Kotyna\Downloads\Zimní příběh [Winters Tale] (2014) CZ dabing.avi
2015-07-04 23:19 - 2015-07-04 23:26 - 783331328 _____ C:\Users\Kotyna\Downloads\Andělé všedního dne (2014) CZfilm.avi
2015-07-04 23:17 - 2015-07-04 23:23 - 733585196 _____ C:\Users\Kotyna\Downloads\Milionář z chatrče CZ Dabing.avi
2015-07-04 20:47 - 2015-07-04 21:05 - 731587350 _____ C:\Users\Kotyna\Downloads\Proroctví Knowing (2009) CZdub.avi
2015-07-04 20:43 - 2015-07-04 21:05 - 928528384 _____ C:\Users\Kotyna\Downloads\Pokani-CZ-dabing-2007--WAR.avi
2015-07-04 20:41 - 2015-07-04 21:02 - 787724288 _____ C:\Users\Kotyna\Downloads\Terapie láskou CZ-dabing (2012) NOVINKA.avi
2015-07-04 20:34 - 2015-07-04 21:05 - 1101279232 _____ C:\Users\Kotyna\Downloads\Sin City 2 Ženská, pre ktorú by som vraždil (2014) CZ-Dabing NOVINKY.avi
2015-07-04 20:31 - 2015-07-04 20:56 - 919232978 _____ C:\Users\Kotyna\Downloads\Mocný-vládce-Oz-(2013)-CZ-dabing.avi
2015-07-04 20:28 - 2015-07-04 20:43 - 782127104 _____ C:\Users\Kotyna\Downloads\Apokalypsa v Hollywoodu CZ DABING 2013.avi
2015-07-04 20:27 - 2015-07-04 20:51 - 890165248 _____ C:\Users\Kotyna\Downloads\Upíří akademie Vampire Academy Blood Sisters (2014) CZdub.avi
2015-07-04 20:26 - 2015-07-04 20:44 - 734208000 _____ C:\Users\Kotyna\Downloads\Lucy (2014) CZ dabing.avi
2015-07-04 20:20 - 2015-07-04 20:42 - 1017452544 _____ C:\Users\Kotyna\Downloads\Transcendence Transcendence (2014) CZdub.avi
2015-07-04 20:13 - 2015-07-04 20:18 - 860028694 _____ C:\Users\Kotyna\Downloads\Jupiter vychází (2015) CZ-Dabing NOVINKA.avi
2015-07-04 20:11 - 2015-07-04 20:24 - 1024780248 _____ C:\Users\Kotyna\Downloads\Imaginárium Dr. Parnasse 2009 CZ dabing.avi
2015-07-04 20:09 - 2015-07-04 20:11 - 00000000 ____D C:\Users\Kotyna\Downloads\Merlin
2015-07-04 20:07 - 2015-07-04 20:12 - 791291904 _____ C:\Users\Kotyna\Downloads\Mordecai, Grandiozni pripad.avi
2015-07-04 20:07 - 2015-07-04 20:09 - 00000000 ____D C:\Users\Kotyna\Downloads\2 socky
2015-07-04 18:42 - 2015-07-04 18:42 - 00000000 ____D C:\Users\Kotyna\AppData\Local\Macromedia
2015-07-04 16:16 - 2015-07-04 18:18 - 00000000 ____D C:\AdwCleaner
2015-07-04 16:14 - 2015-07-04 16:15 - 02244096 _____ C:\Users\Kotyna\Desktop\adwcleaner_4.207.exe
2015-07-04 13:23 - 2015-07-06 11:41 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-04 13:23 - 2015-07-04 13:23 - 00003802 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-04 13:11 - 2015-07-04 13:11 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(2).exe
2015-07-04 13:09 - 2015-07-04 14:57 - 00000000 ____D C:\Program Files\trend micro
2015-07-04 13:09 - 2015-07-04 13:09 - 00000000 ____D C:\rsit
2015-07-04 13:08 - 2015-07-04 13:08 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(1).exe
2015-06-29 16:40 - 2015-07-05 21:17 - 00000000 ____D C:\Users\Kotyna\Downloads\Nové filmy
2015-06-26 21:32 - 2015-06-26 22:01 - 937294946 _____ C:\Users\Kotyna\Downloads\Ghost Rider 2 Duch pomsty-Ghost Rider Spirit of Vengeance (2011) Akční Fantasy Thriller CZ dabing.avi
2015-06-26 21:16 - 2015-06-26 21:21 - 733869394 _____ C:\Users\Kotyna\Downloads\zase-ona-novinky-2010-komedie-cz-dabing.avi
2015-06-26 18:54 - 2015-06-26 19:28 - 863353314 _____ C:\Users\Kotyna\Downloads\Hodinový manžel 2014 Česká Komedie.avi
2015-06-26 18:53 - 2015-06-26 19:24 - 742557554 _____ C:\Users\Kotyna\Downloads\Doba kamenná (komedie 2013---) Cz dabing.avi
2015-06-26 18:52 - 2015-06-26 19:34 - 1576656896 _____ C:\Users\Kotyna\Downloads\Dohola (2001) HIT cz dabing.avi
2015-06-26 18:51 - 2015-06-26 19:22 - 734498816 _____ C:\Users\Kotyna\Downloads\Do_naha_1997.avi
2015-06-24 23:56 - 2015-06-25 00:04 - 949778432 _____ C:\Users\Kotyna\Downloads\Život mé sestry (2013)CZ Dabing,komedie, drama.avi
2015-06-24 23:17 - 2015-06-24 23:17 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-21 13:44 - 2015-06-21 13:56 - 1270824960 _____ C:\Users\Kotyna\Downloads\Zmizelá [Gone Girl] (2014) CZ dabing.avi
2015-06-21 13:43 - 2015-06-21 13:52 - 946333696 _____ C:\Users\Kotyna\Downloads\Nevědomí CZ-dabing (2013) NOVINKA.avi
2015-06-20 20:24 - 2015-06-20 20:35 - 859700512 _____ C:\Users\Kotyna\Downloads\NOVINKY!! Kingsman-tajná služba (2015) BRrip.XviD.640 SUPER KVALITA krimi akční má ČESKÝ DABING.avi
2015-06-15 12:05 - 2015-06-15 12:06 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\Mozilla
2015-06-15 12:05 - 2015-06-15 12:06 - 00000000 ____D C:\Users\Kotyna\AppData\Local\Mozilla
2015-06-15 12:05 - 2015-06-15 12:05 - 00001182 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-06-15 12:05 - 2015-06-15 12:05 - 00001170 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-06-15 12:05 - 2015-06-15 12:05 - 00000000 ____D C:\ProgramData\Mozilla
2015-06-15 12:05 - 2015-06-15 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-15 12:05 - 2015-06-15 12:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-06-15 11:58 - 2015-06-15 11:58 - 40140168 _____ C:\Users\Kotyna\Downloads\FirefoxSetup38.0.5cz.exe
2015-06-14 11:57 - 2015-06-14 11:57 - 00000000 ____D C:\Users\Kotyna\AppData\Local\GWX
2015-06-10 20:35 - 2015-06-10 20:35 - 00000000 ____D C:\43cfc473f2703a71676fe2ba
2015-06-10 20:05 - 2015-05-25 15:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 20:05 - 2015-05-25 15:07 - 01430528 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 20:05 - 2015-05-22 15:08 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 20:05 - 2015-05-21 18:47 - 04177920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 20:05 - 2015-05-21 15:08 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 01020928 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00756736 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00422912 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 20:05 - 2015-05-21 15:08 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 20:05 - 2015-04-25 04:34 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 20:05 - 2015-04-25 04:33 - 00549888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-10 20:05 - 2015-04-17 00:07 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 20:05 - 2015-04-16 08:17 - 00325464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2015-06-10 20:05 - 2015-04-14 00:37 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll
2015-06-10 20:05 - 2015-04-14 00:34 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll
2015-06-10 20:05 - 2015-04-10 02:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2015-06-10 20:05 - 2015-04-10 02:17 - 01018880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2015-06-10 20:05 - 2015-04-09 00:07 - 00410336 _____ C:\Windows\system32\ApnDatabase.xml
2015-06-10 20:05 - 2015-04-02 00:42 - 03097600 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-06-10 20:05 - 2015-04-02 00:30 - 02483712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-06-10 20:05 - 2015-04-01 06:21 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2015-06-10 20:05 - 2015-04-01 06:18 - 00468480 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2015-06-10 20:05 - 2015-04-01 06:17 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2015-06-10 20:05 - 2015-04-01 06:08 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2015-06-10 20:05 - 2015-04-01 05:46 - 03633664 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-06-10 20:05 - 2015-04-01 05:17 - 02551808 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-06-10 20:05 - 2015-04-01 05:17 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2015-06-10 20:05 - 2015-04-01 04:53 - 00391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2015-06-10 20:05 - 2015-04-01 04:53 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2015-06-10 20:05 - 2015-04-01 04:45 - 02749952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2015-06-10 20:05 - 2015-04-01 04:45 - 00699392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2015-06-10 20:05 - 2015-04-01 04:14 - 01920000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2015-06-10 20:05 - 2015-04-01 04:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2015-06-10 20:05 - 2015-03-20 05:49 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\compstui.dll
2015-06-10 20:05 - 2015-03-20 05:08 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2015-06-10 20:05 - 2015-03-20 04:37 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2015-06-10 20:05 - 2015-03-20 04:07 - 01091072 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2015-06-10 20:05 - 2015-03-02 03:43 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2015-06-10 20:05 - 2015-03-02 03:21 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastapi.dll
2015-06-10 20:04 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 20:04 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-10 20:04 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-10 20:04 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-10 20:04 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-10 20:04 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-10 20:04 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-10 20:04 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-10 20:04 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-10 20:04 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-10 20:04 - 2015-05-23 04:47 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2015-06-10 20:04 - 2015-05-23 04:43 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-06-10 20:04 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-10 20:04 - 2015-05-23 04:38 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-10 20:04 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-10 20:04 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-10 20:04 - 2015-05-23 04:28 - 01042944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-06-10 20:04 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-10 20:04 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-10 20:04 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-10 20:04 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 20:04 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 20:04 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 20:04 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 20:04 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 20:04 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 20:04 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 20:04 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 20:04 - 2015-05-22 20:23 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-06-10 20:04 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 20:04 - 2015-05-22 20:15 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-06-10 20:04 - 2015-05-22 20:09 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-06-10 20:04 - 2015-05-22 20:08 - 00374272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 20:04 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 20:04 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 20:04 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 20:04 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 20:04 - 2015-05-22 19:49 - 02865152 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-06-10 20:04 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 20:04 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 20:04 - 2015-04-09 00:41 - 00158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rgb9rast.dll
2015-06-08 16:04 - 2015-06-08 16:04 - 00024833 _____ C:\Users\Kotyna\Desktop\Headway.odt
2015-06-08 16:02 - 2015-06-08 16:02 - 00003584 _____ C:\Users\Kotyna\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-06-08 11:57 - 2015-06-14 21:38 - 00000000 ____D C:\Users\Kotyna\Desktop\Nová složka (2)

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-06 11:45 - 2014-12-20 21:44 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2592885859-3292131433-3858698835-1002
2015-07-06 11:45 - 2014-12-18 14:00 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2592885859-3292131433-3858698835-1001
2015-07-06 11:44 - 2014-12-18 13:54 - 01261046 _____ C:\Windows\WindowsUpdate.log
2015-07-06 11:43 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness
2015-07-06 11:40 - 2015-04-08 00:00 - 00000000 ____D C:\Users\KoulovaA\AppData\Roaming\Seznam.cz
2015-07-06 11:40 - 2014-04-26 06:40 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2015-07-06 11:38 - 2014-12-18 15:10 - 00003986 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{CDC825C2-CBD1-4092-A5A5-2D1C7758BAB7}
2015-07-06 11:37 - 2014-12-20 21:43 - 00003978 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{1EE0349C-1664-4024-9C18-E82B1E07FDC5}
2015-07-06 11:35 - 2014-12-18 22:35 - 00000000 ____D C:\Program Files (x86)\Origin
2015-07-06 11:33 - 2014-12-18 21:46 - 00000976 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-06 11:32 - 2013-08-22 16:46 - 00060970 _____ C:\Windows\setupact.log
2015-07-06 11:30 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\sru
2015-07-05 22:47 - 2014-04-26 15:47 - 00768392 _____ C:\Windows\system32\perfh005.dat
2015-07-05 22:47 - 2014-04-26 15:47 - 00166490 _____ C:\Windows\system32\perfc005.dat
2015-07-05 22:47 - 2014-03-18 11:53 - 01883040 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-05 22:11 - 2014-12-18 21:46 - 00000980 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-05 21:14 - 2014-12-22 11:01 - 00000000 ____D C:\Users\Kotyna\Desktop\Nová složka
2015-07-05 12:21 - 2015-04-08 09:34 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\Seznam.cz
2015-07-05 12:17 - 2014-12-20 21:44 - 00000000 ____D C:\Users\Kotyna\Documents\Youcam
2015-07-05 12:10 - 2015-04-08 00:04 - 00000000 _____ C:\Windows\SysWOW64\sinstall.log
2015-07-05 12:10 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-05 12:09 - 2014-03-18 11:44 - 00063934 _____ C:\Windows\PFRO.log
2015-07-05 12:09 - 2013-08-22 15:25 - 00524288 ___SH C:\Windows\system32\config\BBI
2015-07-05 11:55 - 2014-12-23 10:27 - 00000000 ____D C:\Users\ajajan\AppData\Local\Google
2015-07-05 10:38 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\ELAM
2015-07-05 02:44 - 2015-03-13 11:41 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\vlc
2015-07-04 13:25 - 2015-04-07 23:56 - 00000000 ____D C:\Users\Kotyna\AppData\Local\Adobe
2015-06-28 20:06 - 2015-01-01 21:37 - 00000000 ____D C:\Users\Kotyna\AppData\Roaming\Tropico 4
2015-06-27 12:54 - 2015-04-07 19:12 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-06-26 15:57 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2015-06-26 15:47 - 2015-04-07 19:11 - 00442264 _____ (Avast Software s.r.o.) C:\Windows\system32\Drivers\aswsp.sys
2015-06-23 17:23 - 2014-12-18 21:47 - 00002210 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-20 13:22 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\NDF
2015-06-20 05:02 - 2014-12-21 21:03 - 00792568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-06-20 05:02 - 2014-12-21 21:03 - 00178168 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-14 15:14 - 2014-12-20 21:38 - 00000000 ____D C:\Users\Kotyna
2015-06-14 14:49 - 2014-12-23 00:21 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-14 14:49 - 2014-12-23 00:21 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-14 14:49 - 2013-08-22 17:36 - 00000000 ___RD C:\Windows\ToastData
2015-06-13 19:10 - 2015-04-07 23:55 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-06-11 19:41 - 2013-08-22 16:44 - 00405824 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-11 19:36 - 2015-04-05 16:23 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-06-11 19:36 - 2015-04-05 16:23 - 00000000 ___SD C:\Windows\system32\GWX
2015-06-11 19:36 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-10 20:35 - 2014-12-22 11:46 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-10 20:35 - 2014-12-22 11:46 - 00000000 ____D C:\Windows\system32\MRT

==================== Files in the root of some directories =======


Files to move or delete:
====================
C:\Users\KoulovaA\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe


Some files in TEMP:
====================
C:\Users\KoulovaA\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: McAfee Firewall (Disabled) {959DA8E2-3527-57D1-4915-924367AD4FE9}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\KoulovaA\Desktop" je 890 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Přílohy
Addition.zip
(5.82 KiB) Staženo 16 x

Alice
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 08 kvě 2015 11:02

Re: Preventivní kontrola logu

#11 Příspěvek od Alice »

Doufám, že podruhé jsem to už udělala správně ... počítačům nerozumím, tak se omlouvám, pokud se mi to hned na první pokus nepovede :oops:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivní kontrola logu

#12 Příspěvek od vyosek »

:arrow: Odinstalujte vse od McAfee - je v kolizi s Avastem a pak pouzijte jeste tento remover http://download.mcafee.com/products/lic ... s/MCPR.exe

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
    HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
    HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
    HKLM\...\Policies\Explorer: [NoFolderOptions] 0
    HKLM\...\Policies\Explorer: [NoControlPanel] 0
    HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-12-18] (Electronic Arts)
    HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
    HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
    HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\RunOnce: [SeznamInstall-uninstall:bb8a75c57009f43ed56ed3b8cc48ccd2] => C:\Users\KoulovaA\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe [534528 2015-07-06] () <===== ATTENTION
    HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\MountPoints2: {dd0eea73-3dbb-11e4-825c-806e6f6e6963} - "E:\autorun.exe"
    HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
    HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
    
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
    HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {1B3DBC27-D6A1-45EF-A14F-C6D88E109C3B} URL = http://www.search.ask.com/web?tpid=ATUS ... &pf=V7&p2=^B1W^YYYYYY^YY^CZ&gct=&itbv=12.21.0.3825&apn_uid=5497EFEA-E84A-4D0E-9CEF-0D18B33AA0CD&apn_ptnrs=^B1W&apn_dtid=^YYYYYY^YY^CZ&apn_dbr=iexplore.exe_6_11.0.9600.17416&doi=2014-12-31&trgb=IE&q={searchTerms}&psv=&pt=tb
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2014-04-25] (McAfee, Inc.)
    Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2014-04-25] (McAfee, Inc.)
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-09-16]
    
    R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
    S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-29] (McAfee, Inc.)
    R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-09-04] (McAfee, Inc.)
    S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.)
    R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
    R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
    R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
    R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2589496 2014-10-17] (AVG Technologies)
    
    R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
    S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
    R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
    R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
    S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
    R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
    R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
    R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.)
    S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.)
    R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
    R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-09-09] (TuneUp Software)
    
    C:\Program Files (x86)\AVG
    C:\Program Files\McAfee.com
    C:\Program Files\Common Files\McAfee
    2015-07-06 11:42 - 2015-07-06 11:43 - 00112640 _____ (forum.viry.cz) C:\Users\KoulovaA\Desktop\FRSTLauncher.exe
    2015-07-06 11:45 - 2015-07-06 11:47 - 00027219 _____ C:\Users\KoulovaA\Desktop\FRST.txt
    2015-07-05 21:05 - 2015-07-05 21:05 - 00008562 _____ C:\Users\Kotyna\Desktop\Addition.zip
    2015-07-05 20:56 - 2015-07-05 20:57 - 00029363 _____ C:\Users\Kotyna\Desktop\Addition.txt
    2015-07-05 20:54 - 2015-07-05 20:57 - 00049372 _____ C:\Users\Kotyna\Desktop\FRST.txt
    2015-07-05 20:49 - 2015-07-05 20:50 - 00112640 _____ (forum.viry.cz) C:\Users\Kotyna\Desktop\FRSTLauncher.exe
    2015-07-05 12:03 - 2015-07-05 10:44 - 00024064 _____ C:\Windows\zoek-delete.exe
    2015-07-05 10:48 - 2015-07-05 10:29 - 00001788 _____ C:\zoek-results2015-07-05-082946.log
    2015-07-05 10:23 - 2015-07-05 12:32 - 00034934 _____ C:\zoek-results.log
    2015-07-05 10:13 - 2015-07-05 11:58 - 00000000 ____D C:\zoek_backup
    2015-07-05 10:10 - 2015-07-05 10:10 - 01308672 _____ C:\Users\Kotyna\Desktop\zoek.exe
    2015-07-04 16:16 - 2015-07-04 18:18 - 00000000 ____D C:\AdwCleaner
    2015-07-04 13:11 - 2015-07-04 13:11 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(2).exe
    2015-07-04 13:09 - 2015-07-04 14:57 - 00000000 ____D C:\Program Files\trend micro
    2015-07-04 13:09 - 2015-07-04 13:09 - 00000000 ____D C:\rsit
    2015-07-04 13:08 - 2015-07-04 13:08 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(1).exe
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Alice
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 08 kvě 2015 11:02

Re: Preventivní kontrola logu

#13 Příspěvek od Alice »

Fix result of Farbar Recovery Scan Tool (x64) Version:05-07-2015
Ran by KoulovaA at 2015-07-07 21:08:49 Run:1
Running from C:\Users\KoulovaA\Desktop
Loaded Profiles: KoulovaA (Available Profiles: KoulovaA & Kotyna & ajajan)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-12-18] (Electronic Arts)
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\Run: [cz.seznam.software.szndesktop] => C:\Users\KoulovaA\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\RunOnce: [SeznamInstall-uninstall:bb8a75c57009f43ed56ed3b8cc48ccd2] => C:\Users\KoulovaA\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe [534528 2015-07-06] () <===== ATTENTION
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\...\MountPoints2: {dd0eea73-3dbb-11e4-825c-806e6f6e6963} - "E:\autorun.exe"
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Kotyna\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()

HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPNTDFJS
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2592885859-3292131433-3858698835-1002 -> {1B3DBC27-D6A1-45EF-A14F-C6D88E109C3B} URL = http://www.search.ask.com/web?tpid=ATUS ... &pf=V7&p2=^B1W^YYYYYY^YY^CZ&gct=&itbv=12.21.0.3825&apn_uid=5497EFEA-E84A-4D0E-9CEF-0D18B33AA0CD&apn_ptnrs=^B1W&apn_dtid=^YYYYYY^YY^CZ&apn_dbr=iexplore.exe_6_11.0.9600.17416&doi=2014-12-31&trgb=IE&q={searchTerms}&psv=&pt=tb
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2014-04-25] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2014-04-25] (McAfee, Inc.)
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-09-16]

R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-29] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-09-04] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2589496 2014-10-17] (AVG Technologies)

R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-09-09] (TuneUp Software)

C:\Program Files (x86)\AVG
C:\Program Files\McAfee.com
C:\Program Files\Common Files\McAfee
2015-07-06 11:42 - 2015-07-06 11:43 - 00112640 _____ (forum.viry.cz) C:\Users\KoulovaA\Desktop\FRSTLauncher.exe
2015-07-06 11:45 - 2015-07-06 11:47 - 00027219 _____ C:\Users\KoulovaA\Desktop\FRST.txt
2015-07-05 21:05 - 2015-07-05 21:05 - 00008562 _____ C:\Users\Kotyna\Desktop\Addition.zip
2015-07-05 20:56 - 2015-07-05 20:57 - 00029363 _____ C:\Users\Kotyna\Desktop\Addition.txt
2015-07-05 20:54 - 2015-07-05 20:57 - 00049372 _____ C:\Users\Kotyna\Desktop\FRST.txt
2015-07-05 20:49 - 2015-07-05 20:50 - 00112640 _____ (forum.viry.cz) C:\Users\Kotyna\Desktop\FRSTLauncher.exe
2015-07-05 12:03 - 2015-07-05 10:44 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-05 10:48 - 2015-07-05 10:29 - 00001788 _____ C:\zoek-results2015-07-05-082946.log
2015-07-05 10:23 - 2015-07-05 12:32 - 00034934 _____ C:\zoek-results.log
2015-07-05 10:13 - 2015-07-05 11:58 - 00000000 ____D C:\zoek_backup
2015-07-05 10:10 - 2015-07-05 10:10 - 01308672 _____ C:\Users\Kotyna\Desktop\zoek.exe
2015-07-04 16:16 - 2015-07-04 18:18 - 00000000 ____D C:\AdwCleaner
2015-07-04 13:11 - 2015-07-04 13:11 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(2).exe
2015-07-04 13:09 - 2015-07-04 14:57 - 00000000 ____D C:\Program Files\trend micro
2015-07-04 13:09 - 2015-07-04 13:09 - 00000000 ____D C:\rsit
2015-07-04 13:08 - 2015-07-04 13:08 - 01222144 _____ C:\Users\Kotyna\Downloads\RSITx64(1).exe

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mcpltui_exe => value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\seznam-listicka-distribuce => value not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoControlPanel => value removed successfully
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\Software\Microsoft\Windows\CurrentVersion\Run\\EADM => value removed successfully
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => value removed successfully
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => value removed successfully
HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SeznamInstall-uninstall:bb8a75c57009f43ed56ed3b8cc48ccd2 => value not found.
"HKU\S-1-5-21-2592885859-3292131433-3858698835-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{dd0eea73-3dbb-11e4-825c-806e6f6e6963}" => key removed successfully
HKCR\CLSID\{dd0eea73-3dbb-11e4-825c-806e6f6e6963} => key not found.
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.szndesktop => value not found.
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Windows\CurrentVersion\Run\\cz.seznam.software.autoupdate => value not found.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Error setting value.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-2592885859-3292131433-3858698835-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1B3DBC27-D6A1-45EF-A14F-C6D88E109C3B} => key not found.
HKCR\CLSID\{1B3DBC27-D6A1-45EF-A14F-C6D88E109C3B} => key not found.
HKCR\PROTOCOLS\Filter\application/x-mfe-ipt => key not found.
HKCR\CLSID\{3EF5086B-5478-4598-A054-786C45D75692} => key not found.
HKCR\Wow6432Node\PROTOCOLS\Filter\application/x-mfe-ipt => key not found.
HKCR\Wow6432Node\CLSID\{3EF5086B-5478-4598-A054-786C45D75692} => key not found.
HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\msktbird@mcafee.com => value not found.
C:\Program Files\McAfee\MSK not found.
HomeNetSvc => Service not found.
McAPExe => Service not found.
McAWFwk => Service not found.
McMPFSvc => Service not found.
McNaiAnn => Service not found.
McODS => Service not found.
McOobeSv2 => Service not found.
mcpltsvc => Service not found.
McProxy => Service not found.
mfecore => Service not found.
mfefire => Service not found.
mfevtp => Service not found.
MSK80Service => Service not found.
TuneUp.UtilitiesSvc => Service removed successfully
cfwids => Service not found.
HipShieldK => Service not found.
mfeapfk => Service not found.
mfeavfk => Service not found.
mfeelamk => Service not found.
mfefirek => Service not found.
mfehidk => Service not found.
mfencbdc => Service not found.
mfencrk => Service not found.
mfewfpk => Service not found.
TuneUpUtilitiesDrv => Unable to stop service.
TuneUpUtilitiesDrv => Service removed successfully
C:\Program Files (x86)\AVG => moved successfully.
"C:\Program Files\McAfee.com" => File/Folder not found.
"C:\Program Files\Common Files\McAfee" => File/Folder not found.
C:\Users\KoulovaA\Desktop\FRSTLauncher.exe => moved successfully.
C:\Users\KoulovaA\Desktop\FRST.txt => moved successfully.
C:\Users\Kotyna\Desktop\Addition.zip => moved successfully.
C:\Users\Kotyna\Desktop\Addition.txt => moved successfully.
C:\Users\Kotyna\Desktop\FRST.txt => moved successfully.
C:\Users\Kotyna\Desktop\FRSTLauncher.exe => moved successfully.
C:\Windows\zoek-delete.exe => moved successfully.
C:\zoek-results2015-07-05-082946.log => moved successfully.
C:\zoek-results.log => moved successfully.
C:\zoek_backup => moved successfully.
C:\Users\Kotyna\Desktop\zoek.exe => moved successfully.
C:\AdwCleaner => moved successfully.
C:\Users\Kotyna\Downloads\RSITx64(2).exe => moved successfully.
C:\Program Files\trend micro => moved successfully.
C:\rsit => moved successfully.
C:\Users\Kotyna\Downloads\RSITx64(1).exe => moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully.
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 183.7 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 21:10:31 ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Preventivní kontrola logu

#14 Příspěvek od vyosek »

Jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Alice
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 08 kvě 2015 11:02

Re: Preventivní kontrola logu

#15 Příspěvek od Alice »

Dobrý den, chová se normálně, všechno běží ...on i předtím nebyl velký problém, jen mi antivir zahlásil, že zablokoval nějaký vir, tak jsem si to pro jistotu nechala u Vás zkontrolovat :) Díky moc za pomoc :thumbsup:

Odpovědět