kamarádka mi donesla notebook synka, že ho má zavirovaný.
NTB je pomalý, vyskakují okýnka ADS By Helper, samy se otevírají záložky, nejde vůbec spustit Internet Explorer.
Projel jsem jej ESET on-line, AdwCleanerem a jsem udělal log v FRST.
Prosím moc o pomoc
Jirka
Log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015
Ran by Vojta (administrator) on VOJTA-PC on 13-07-2015 23:04:29
Running from C:\Users\Vojta\Desktop
Loaded Profiles: UpdatusUser & Vojta (Available Profiles: UpdatusUser & Vojta)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Vojta\Desktop\FRSTLauncher (1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2481163647-550643762-1494268911-1001\...\MountPoints2: {0dfe8100-fd40-11e3-837a-b888e309ba37} - F:\MafiaLauncher.EXE
HKU\S-1-5-21-2481163647-550643762-1494268911-1001\...\MountPoints2: {0dfe8105-fd40-11e3-837a-b888e309ba37} - G:\Setup.exe
HKU\S-1-5-21-2481163647-550643762-1494268911-1001\...\MountPoints2: {409a0cbd-ba5d-11e1-aea8-806e6f6e6963} - D:\autorun.exe
HKU\S-1-5-21-2481163647-550643762-1494268911-1001\...\MountPoints2: {a60e1717-dac0-11e3-a19f-b888e309ba37} - E:\MafiaLauncher.EXE
HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [168616 2013-09-05] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-09-05] (NVIDIA Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
URLSearchHook: HKU\S-1-5-21-2481163647-550643762-1494268911-1001 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
URLSearchHook: HKU\S-1-5-21-2481163647-550643762-1494268911-1001 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2014-06-30] (McAfee, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-07-25] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2014-06-30] (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-07-25] (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2014-06-30] (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2014-06-30] (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2014-06-30] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2014-06-30] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2014-06-30] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2014-06-30] (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.200.1.1 8.8.8.8
Tcpip\..\Interfaces\{33B7A10B-0CBA-4D1B-89E6-4488C4D31D5B}: [DhcpNameServer] 10.200.1.1 8.8.8.8
Tcpip\..\Interfaces\{425A1498-80EA-4D3C-AE21-CE2B95C16894}: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Vojta\AppData\Roaming\Mozilla\Firefox\Profiles\a9q67czb.default
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-07-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-07-25] (Oracle Corporation)
FF Plugin-x32: @live.heroesandgenerals.com/npretox -> C:\Program Files (x86)\Heroes & Generals\live\npretox-1.0.6.1\npretoxlive-1.0.6.1.dll [2014-10-20] (Reto-Moto ApS)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-14] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2012-10-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2481163647-550643762-1494268911-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Vojta\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-04-02] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppluginrichmediaplayer.dll [2013-03-12] ()
FF Extension: firepickerthedarkone - C:\Users\Vojta\AppData\Roaming\Mozilla\Firefox\Profiles\a9q67czb.default\Extensions\firepicker@thedarkone [2015-06-02]
FF Extension: Rise Gaming Store - C:\Users\Vojta\AppData\Roaming\Mozilla\Firefox\Profiles\a9q67czb.default\Extensions\s4LVk@gmail.com [2015-06-02]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2012-01-19]
Chrome:
=======
CHR HomePage: Default -> https://www.google.cz/
CHR Profile: C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-05-04]
CHR Extension: (Google Docs) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-04]
CHR Extension: (Google Drive) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-04]
CHR Extension: (YouTube) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-04]
CHR Extension: (cfhdojbkjhnklbpkdaibdccddilifddb) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-06-02]
CHR Extension: (Google Search) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-04]
CHR Extension: (Google Sheets) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-05-04]
CHR Extension: (SiteAdvisor) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-03-27]
CHR Extension: (Heroes & Generals) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbophcdhblbipoaacgchllkobdaolpge [2015-03-05]
CHR Extension: (Rise Gaming Store) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdlmjkfoidldghacbhdinlbmgpcplpal [2015-06-02]
CHR Extension: (Google Wallet) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Air Globe) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogcbggiopalifiakkabfhjbbkpjmjogo [2015-05-21]
CHR Extension: (Gmail) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-04]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-08-19]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-05-23] (BitRaider, LLC)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-24] (NTI Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1997168 2015-06-23] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-06-16] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 McAfee SiteAdvisor Service; "C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2014-05-24] (BitRaider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-06-26] (Disc Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-13 23:04 - 2015-07-13 23:05 - 00015956 _____ C:\Users\Vojta\Desktop\FRST.txt
2015-07-13 23:03 - 2015-07-13 23:04 - 00000000 ____D C:\FRST
2015-07-13 23:02 - 2015-07-13 23:02 - 00112640 _____ (forum.viry.cz) C:\Users\Vojta\Desktop\FRSTLauncher (1).exe
2015-07-13 22:58 - 2015-07-13 22:58 - 00112640 _____ (forum.viry.cz) C:\Users\Vojta\Downloads\Nepotvrzeno 858228.crdownload
2015-07-13 22:50 - 2015-07-13 22:50 - 02133504 _____ (Farbar) C:\Users\Vojta\Desktop\FRST64.exe
2015-07-13 22:30 - 2015-07-13 22:30 - 00037534 _____ C:\Users\Vojta\Desktop\AdwCleaner[S0].txt
2015-07-13 22:19 - 2015-07-13 22:19 - 00107046 _____ C:\Users\Vojta\Desktop\viry.txt
2015-07-13 13:25 - 2015-07-13 22:26 - 00000000 ____D C:\AdwCleaner
2015-07-13 13:24 - 2015-07-13 13:24 - 02248704 _____ C:\Users\Vojta\Downloads\adwcleaner_4.208.exe
2015-07-13 13:08 - 2015-07-13 13:08 - 00000000 ____D C:\Program Files (x86)\ESET
2015-07-13 13:07 - 2015-07-13 13:07 - 02870984 _____ (ESET) C:\Users\Vojta\Downloads\esetsmartinstaller_csy.exe
2015-07-11 21:22 - 2015-07-11 21:22 - 01406401 _____ C:\Users\Vojta\Downloads\mu0v3-36.zip
2015-07-11 21:15 - 2015-07-11 21:15 - 01774247 _____ C:\Users\Vojta\Downloads\mu4v3-36.zip
2015-06-24 16:55 - 2015-06-24 16:55 - 00001340 _____ C:\Users\Vojta\Desktop\Men of War. Condemned Heroes.lnk
2015-06-24 15:43 - 2015-06-24 15:43 - 00000000 ____D C:\Users\Vojta\minecraft
2015-06-22 15:04 - 2015-06-22 15:04 - 00000000 ____D C:\Windows\TempAB899B82-FD6D-22FF-FE03-BDCBBC0B52BF-Signatures
2015-06-19 13:01 - 2015-06-19 13:01 - 00000000 ____D C:\1fa629e8bc87a2777b8391a4d76bc262
2015-06-15 19:02 - 2015-06-15 19:02 - 00000000 ____D C:\Windows\Temp10C3E64C-C0A2-DD0B-280E-2575F113FA3B-Signatures
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-13 22:41 - 2014-08-20 16:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-07-13 22:41 - 2012-01-19 14:19 - 00000000 ____D C:\ProgramData\McAfee
2015-07-13 22:39 - 2012-06-20 00:25 - 02085887 _____ C:\Windows\WindowsUpdate.log
2015-07-13 22:38 - 2012-06-20 00:46 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-07-13 22:38 - 2009-07-14 06:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-13 22:38 - 2009-07-14 06:45 - 00024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-13 22:35 - 2015-04-17 18:59 - 00000000 ____D C:\Program Files (x86)\microsoft office 2013 plna verze cz zdarma
2015-07-13 22:30 - 2012-11-10 11:38 - 00000000 ____D C:\ProgramData\clear.fi
2015-07-13 22:28 - 2014-08-20 16:53 - 00037652 _____ C:\Windows\setupact.log
2015-07-13 22:28 - 2010-11-21 05:47 - 00140472 _____ C:\Windows\PFRO.log
2015-07-13 22:28 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-13 22:26 - 2013-09-26 17:23 - 00000601 _____ C:\Users\Vojta\Desktop\Search.lnk
2015-07-13 22:26 - 2012-11-09 19:34 - 00000000 ____D C:\Users\Vojta
2015-07-13 22:26 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-07-13 22:08 - 2013-05-18 18:19 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-13 22:00 - 2015-06-01 19:33 - 00000000 ____D C:\Users\Vojta\AppData\Roaming\MiUi-temp
2015-07-13 22:00 - 2013-05-25 20:44 - 00000000 ____D C:\Users\Vojta\AppData\Roaming\uTorrent
2015-07-13 21:58 - 2014-02-02 17:30 - 00000000 ____D C:\ProgramData\YTAedRaemoval
2015-07-13 21:58 - 2013-09-26 17:22 - 00000000 ____D C:\Program Files (x86)\Zula Games
2015-07-13 21:57 - 2015-06-02 20:04 - 00000000 ____D C:\Program Files (x86)\Rise Gaming Store
2015-07-13 21:09 - 2009-07-14 04:34 - 00000612 _____ C:\Windows\win.ini
2015-07-13 13:02 - 2015-04-12 11:39 - 00000000 ____D C:\ProgramData\Datamngr
2015-07-13 13:01 - 2014-06-25 18:43 - 00000000 ____D C:\Program Files (x86)\2K Games
2015-07-13 13:01 - 2013-11-17 00:19 - 00000000 ____D C:\Program Files (x86)\1C Company
2015-07-13 12:56 - 2015-05-21 20:32 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-13 12:56 - 2014-09-22 19:11 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-13 12:56 - 2013-10-27 18:58 - 00001105 _____ C:\Users\Public\Desktop\WarThunder.lnk
2015-07-13 12:56 - 2012-11-09 19:37 - 00001397 _____ C:\Users\Vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-07-13 12:56 - 2012-11-09 19:37 - 00001363 _____ C:\Users\Vojta\Desktop\Internet Explorer (64-bit).lnk
2015-07-13 10:36 - 2015-04-17 20:48 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-07-13 10:12 - 2013-11-19 23:35 - 00488245 _____ C:\Windows\IE11_main.log
2015-07-13 10:11 - 2014-08-20 16:50 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2015-07-13 10:11 - 2014-08-20 16:49 - 00002113 _____ C:\Windows\epplauncher.mif
2015-07-13 10:11 - 2014-08-20 16:49 - 00000000 ____D C:\Program Files\Microsoft Security Client
2015-07-13 09:59 - 2015-04-25 19:57 - 00000000 _____ C:\Users\Vojta\rgmnr
2015-07-12 20:54 - 2013-01-05 19:44 - 00000000 ____D C:\Users\Vojta\AppData\Local\ArmA 2 OA
2015-07-11 20:11 - 2013-05-18 18:19 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-11 20:11 - 2013-05-18 18:19 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-11 20:11 - 2012-01-19 14:47 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-06-27 18:23 - 2013-10-20 13:47 - 00000000 ____D C:\Users\Vojta\Documents\Euro Truck Simulator 2
2015-06-27 15:11 - 2013-05-02 15:15 - 00000000 ____D C:\ProgramData\Origin
2015-06-26 11:27 - 2013-10-27 18:58 - 00000000 ____D C:\Program Files (x86)\WarThunder
2015-06-24 18:28 - 2012-11-09 22:33 - 00000000 ____D C:\Users\Vojta\AppData\Roaming\Skype
2015-06-24 16:57 - 2012-12-16 13:09 - 00000000 ____D C:\Users\Vojta\Documents\My Games
2015-06-24 16:55 - 2013-01-20 21:45 - 00000000 ___HD C:\Windows\msdownld.tmp
2015-06-24 16:55 - 2013-01-20 21:45 - 00000000 ____D C:\Windows\SysWOW64\directx
2015-06-24 16:55 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-06-24 16:54 - 2014-01-11 21:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\1C Company
2015-06-24 15:45 - 2015-05-06 20:54 - 00000000 ____D C:\Users\Vojta\Desktop\Vojta
2015-06-23 20:51 - 2013-05-02 15:18 - 00000000 ____D C:\Users\Vojta\AppData\Roaming\Origin
2015-06-23 20:04 - 2013-05-02 15:14 - 00000000 ____D C:\Program Files (x86)\Origin
==================== Files in the root of some directories =======
2003-04-16 14:49 - 2003-04-16 14:49 - 0233472 ____R () C:\Users\Vojta\AppData\Roaming\MafiaSetup.exe
2012-06-20 00:52 - 2012-06-20 00:55 - 0015222 _____ () C:\ProgramData\ArcadeDeluxe5.log
Some files in TEMP:
====================
C:\Users\Vojta\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Vojta\AppData\Local\Temp\drm_dyndata_7310011.dll
C:\Users\Vojta\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\Vojta\AppData\Local\Temp\ose00000.exe
C:\Users\Vojta\AppData\Local\Temp\Quarantine.exe
C:\Users\Vojta\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Vojta\AppData\Local\Temp\sqlite3.dll
C:\Users\Vojta\AppData\Local\Temp\TsuA35C02E6.dll
C:\Users\Vojta\AppData\Local\Temp\_isCB3A.exe
C:\Users\Vojta\AppData\Local\Temp\_isDEEA.exe
C:\Users\Vojta\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0408b82623e6b.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0408b8301b510.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Vojta\Desktop" je 32881 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeMovieService
"C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupManagerTray
"C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" -h -k [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dolby Advanced Audio v2
"C:\Dolby PCEE4\pcee4.exe" -autostart [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM
"C:\Program Files (x86)\Origin\Origin.exe" -AutoStart [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ETDCtrl
%ProgramFiles%\Elantech\ETDCtrl.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor
"C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
C:\Windows\system32\hkcmd.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
C:\Windows\system32\igfxtray.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iLivid
"C:\Users\Vojta\AppData\Local\iLivid\iLivid.exe" -autorun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager
C:\Program Files (x86)\Launch Manager\LManager.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncnkdxpSrv
C:\Windows\inf\mncnkdxp.vbe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msartfcSrv
"C:\Windows\system32\msartfc.vbe" mswmrhl mstklrxl [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msaxwsfSrv
C:\Windows\inf\msaxwsf.vbe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC
"c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp
C:\Windows\system32\msstp.vbe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NextLive
C:\Windows\SysWOW64\rundll32.exe "C:\Users\Vojta\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Online Backup
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSpeedUp
C:\Program Files (x86)\Zrychleni Pocitace\PCSUNotifier.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence
C:\Windows\system32\igfxpers.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power Management
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RGSC
C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVBg_Dolby
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE4 [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPDriver
C:\Program Files (x86)\ShopperPro\JSDriver\1.42.1.1916\jsdrv.exe [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
"C:\Program Files (x86)\Steam\steam.exe" -silent [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StickyPassword
"C:\Program Files (x86)\Sticky Password\stpass.exe" /autorunned [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuiteTray
"C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TBHostSupport
"C:\Windows\SysWOW64\Rundll32.exe" "C:\Users\Vojta\AppData\Local\TBHostSupport\TBHostSupport_0.dll",DLLRunTBHostSupportPlugin [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent
"C:\Users\Vojta\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YTDownloader
"C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================



Přispějete na provoz fóra?