Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Zellguras
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 02 srp 2015 17:59

Kontrola logu

#1 Příspěvek od Zellguras »

Dobrý den, chtěl bych zkontrolovat log, mám totiž potíže s administrátorem PC.
Počítač mám 6 roků a nikdy na něm nebyl jinej účet, jenom můj a vždy jsem byl administrátor, ale posledni dobou mi počítač píše, že nemám opravněni administrátora u nějákých programú, např. u Windows update mi to napiše, že nejsem správce systému a že přístup byl odepřen. Kamarád mi řekl, že by to mohl být virus a že by jste mi mohli pomoc :)
Děkuji předem za pomoc.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Dominik at 2015-08-03 16:26:36
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 328 GB (34%) free of 953 GB
Total RAM: 4095 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:26:47, on 3.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\SysWOW64\C2MP\TrayMenu.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_209.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_209.exe
C:\ProgramData\Battle.net\Agent\Agent.4271\Agent.exe
C:\Program Files (x86)\Battle.net\Battle.net.5952\Battle.net.exe
C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\trend micro\Dominik.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... 5_147F3B54
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mystartsearch.com/?type=hp&t ... 5_147F3B54
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mystartsearch.com/web/?type= ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.mystartsearch.com/web/?type= ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkID= ... 6pc%3DMSSE
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {B9C767DD-F66A-40B4-8F12-4199A9A4393C} - (no file)
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Browser Extensions] "C:\Users\Dominik\AppData\Roaming\BrowserExtensions\BEHelper.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: TrayMenu.lnk = C:\Windows\SysWOW64\C2MP\TrayMenu.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 11.51.2) -
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} (Java Plug-in 1.6.0_27) -
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 11.51.2) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Program Manager - Unknown owner - C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Razer Game Scanner (Razer Game Scanner Service) - Unknown owner - C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13341 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
atieclxx
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe"
"C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Windows\system32\GWX\GWX.exe"
"C:\Windows\SysWOW64\C2MP\TrayMenu.exe" vlc.ico
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
WLIDSvcM.exe 2528
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe"
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:2444
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="1208.0.1016285087\279668982" "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 1208 "\\.\pipe\gecko-crash-server-pipe.1208" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_209.exe" --proxy-stub-channel=Flash4036.634FD9E8.17620 --host-broker-channel=Flash4036.634FD9E8.2883 --host-pid=4036 --host-npapi-version=28 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_209.exe" --channel=2596.002CF36C.1597914694 --proxy-stub-channel=Flash4036.634FD9E8.17620 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll" --host-npapi-version=28 --type=renderer
"C:\ProgramData\Battle.net\Agent\Agent.4271\Agent.exe" --locale=enUS --session=6981516073082503523
\??\C:\Windows\system32\conhost.exe "-1975001993-693329031-106108235219436358149086480851208629558-1601734833-167679736
"C:\Program Files (x86)\Battle.net\Battle.net.5952\Battle.net.exe" "--gamepath=C:\Program Files (x86)\Hearthstone" --game=hs_beta
taskeng.exe {92DC971C-C703-42C1-8600-81A6295FEF36}
"C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Users\Dominik\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\Bidaily Synchronize Task.job - C:\ProgramData\{dbdfc82f-3620-ac0d-dbdf-fc82f36220bc}\Download.exe --startup=1 --single
C:\Windows\tasks\EasyShare Registration Task.job - C:\Windows\system32\rundll32.exe C:\PROGRA~3\Kodak\EasyShareSetup\$REGIS~1\Registration_7.9.30.1.sxt _RegistrationOffer@16
C:\Windows\tasks\LyricsXX.job - c:\programdata\{8052f28d-d3b7-967d-8052-2f28dd3bca37}\4819421097505549757b.exe --startup=1 --single
C:\Windows\tasks\RubyBuddy.job - c:\programdata\{5d2e0172-bea4-de59-5d2e-e0172bea05ca}\6870889780498486551b.exe --startup=1 --single
C:\Windows\tasks\SystemReset.job - c:\programdata\{c9458b30-ed1b-8553-c945-58b30ed12cc3}\8954514573165499247b.exe --startup=1 --single

=========Mozilla firefox=========

ProfilePath - C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563

prefs.js - "browser.startup.homepage" - "https://www.seznam.cz"
prefs.js - "keyword.URL" - "http://search.seznam.cz/?sourceid=quick ... earchTerms}&"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.209 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.209 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@esn/npbattlelog,version=2.5.1]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL


C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
nppdf32.dll
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563\searchplugins\
seznam-avast.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-23 655480]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-23 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-23 559624]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-23 172640]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-07-18 53753984]
"Browser Extensions"=C:\Users\Dominik\AppData\Roaming\BrowserExtensions\BEHelper.exe [2015-06-09 540656]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2010-05-24 2439072]
""= []
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2015-07-14 5579624]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-07-23 6109776]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
TrayMenu.lnk - C:\Windows\SysWOW64\C2MP\TrayMenu.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-08-25 271360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2013-12-19 6671064]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\weatherbugalert.exe]
"Debugger=""C:\Program Files (x86)\TuneUp Utilities 2011\TUAutoReactivator64.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"MSVideo8"=VfWWDM32.dll
"vidc.ffds"=ff_vfw.dll
"vidc.mjpg"=bdmjpeg64.dll
"vidc.mpeg"=bdmpegv64.dll
"msacm.bdmpeg"=bdmpega64.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux4"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux5"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux6"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open -

======List of files/folders created in the last 1 month======

2015-08-03 16:13:51 ----D---- C:\Program Files\trend micro
2015-08-03 16:13:50 ----D---- C:\rsit
2015-08-02 13:17:00 ----D---- C:\Program Files (x86)\Overwolf
2015-08-02 13:16:52 ----D---- C:\ProgramData\Overwolf
2015-07-23 17:33:22 ----D---- C:\Users\Dominik\AppData\Roaming\AVAST Software
2015-07-23 17:28:39 ----A---- C:\Windows\system32\drivers\aswStm.sys
2015-07-23 17:28:38 ----A---- C:\Windows\system32\drivers\aswVmm.sys
2015-07-23 17:28:36 ----A---- C:\Windows\system32\drivers\aswSP.sys
2015-07-23 17:28:35 ----A---- C:\Windows\system32\drivers\aswRvrt.sys
2015-07-23 17:28:33 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2015-07-23 17:28:32 ----A---- C:\Windows\system32\drivers\aswHwid.sys
2015-07-23 17:28:31 ----A---- C:\Windows\system32\drivers\aswRdr2.sys
2015-07-23 17:28:27 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2015-07-23 17:28:23 ----A---- C:\Windows\system32\aswBoot.exe
2015-07-23 17:28:21 ----A---- C:\Windows\avastSS.scr
2015-07-23 17:27:05 ----D---- C:\Program Files\AVAST Software
2015-07-23 17:23:54 ----D---- C:\ProgramData\AVAST Software
2015-07-23 14:50:06 ----D---- C:\ProgramData\{8052f28d-d3b7-967d-8052-2f28dd3bca37}
2015-07-22 08:51:21 ----D---- C:\Program Files (x86)\Movenote for Gmail
2015-07-22 08:50:34 ----D---- C:\Program Files (x86)\WhIteOOffersApup
2015-07-22 08:50:07 ----D---- C:\ProgramData\{5d2e0172-bea4-de59-5d2e-e0172bea05ca}
2015-07-21 19:59:57 ----D---- C:\Program Files (x86)\RobaoSavver
2015-07-21 19:59:14 ----D---- C:\Program Files (x86)\RobOSAVeer
2015-07-21 19:58:37 ----D---- C:\Program Files (x86)\RobboSaver
2015-07-21 19:39:56 ----D---- C:\Program Files (x86)\ChEappMe
2015-07-21 19:39:17 ----D---- C:\Program Files (x86)\CeheaPMe
2015-07-21 19:38:55 ----D---- C:\Program Files (x86)\CheAApMe
2015-07-21 19:38:40 ----D---- C:\Program Files (x86)\Autofill IRCTC Tatkal FormPlugin Extension
2015-07-21 09:17:45 ----D---- C:\Program Files (x86)\Google
2015-07-16 15:33:58 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2015-07-08 16:01:12 ----D---- C:\Program Files (x86)\CheeaPMe
2015-07-08 16:00:43 ----D---- C:\Program Files (x86)\CheApeMei
2015-07-08 16:00:20 ----D---- C:\Program Files (x86)\Hypothesis Web PDF Annotation
2015-07-08 15:59:28 ----D---- C:\Program Files (x86)\CiheapME
2015-07-07 12:09:17 ----D---- C:\Program Files (x86)\Tart Management

======List of files/folders modified in the last 1 month======

2015-08-03 16:13:51 ----RD---- C:\Program Files
2015-08-03 16:13:09 ----D---- C:\Users\Dominik\AppData\Roaming\Skype
2015-08-03 10:07:48 ----D---- C:\Windows\Temp
2015-08-02 19:13:00 ----D---- C:\Windows\Prefetch
2015-08-02 18:56:34 ----D---- C:\Windows\system32\drivers
2015-08-02 13:56:34 ----D---- C:\Users\Dominik\AppData\Roaming\vlc
2015-08-02 13:17:36 ----D---- C:\Windows\system32\Tasks
2015-08-02 13:17:00 ----RD---- C:\Program Files (x86)
2015-08-02 13:17:00 ----D---- C:\Program Files (x86)\Common Files
2015-08-02 13:16:52 ----HD---- C:\ProgramData
2015-08-01 21:20:02 ----D---- C:\Windows\system32\config
2015-08-01 21:19:08 ----SHD---- C:\System Volume Information
2015-07-30 21:08:31 ----D---- C:\Windows\System32
2015-07-30 21:08:31 ----D---- C:\Windows\inf
2015-07-30 21:08:31 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-07-30 10:15:15 ----D---- C:\Program Files (x86)\World of Warcraft
2015-07-30 10:13:00 ----D---- C:\Program Files (x86)\Hearthstone
2015-07-29 10:44:27 ----SD---- C:\Users\Dominik\AppData\Roaming\Microsoft
2015-07-25 10:15:31 ----D---- C:\Program Files (x86)\Steam
2015-07-25 10:07:58 ----SD---- C:\Windows\system32\GWX
2015-07-23 22:49:20 ----SHD---- C:\Windows\Installer
2015-07-23 22:48:03 ----D---- C:\ProgramData\Skype
2015-07-23 22:47:31 ----D---- C:\Windows\SysWOW64
2015-07-23 22:47:02 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2015-07-23 22:46:54 ----D---- C:\Program Files (x86)\Java
2015-07-23 22:46:32 ----D---- C:\Program Files (x86)\WinRAR
2015-07-23 19:07:06 ----D---- C:\ProgramData\{dbdfc82f-3620-ac0d-dbdf-fc82f36220bc}
2015-07-23 19:07:06 ----D---- C:\ProgramData\{c9458b30-ed1b-8553-c945-58b30ed12cc3}
2015-07-23 19:00:53 ----D---- C:\Program Files (x86)\VaudIx
2015-07-23 18:37:22 ----D---- C:\Program Files (x86)\Haoppy2Save
2015-07-23 18:37:22 ----D---- C:\Program Files (x86)\Haappuy2Savie
2015-07-23 18:37:21 ----D---- C:\Program Files (x86)\HaaPPpuy2Siave
2015-07-23 18:36:49 ----D---- C:\Program Files (x86)\EXIF Viewer
2015-07-23 18:36:49 ----D---- C:\Program Files (x86)\couponight
2015-07-23 18:19:14 ----D---- C:\Program Files (x86)\New Tab New Window
2015-07-23 18:18:15 ----D---- C:\Program Files (x86)\MinimuMPrice
2015-07-23 17:57:02 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-07-23 17:28:25 ----D---- C:\Windows\winsxs
2015-07-23 17:28:22 ----D---- C:\Windows
2015-07-23 17:14:48 ----D---- C:\Windows\Tasks
2015-07-22 08:51:29 ----D---- C:\ProgramData\6960076357452959605
2015-07-21 19:58:50 ----A---- C:\Program Files (x86)\prefs.js
2015-07-20 15:30:01 ----RSD---- C:\Windows\assembly
2015-07-17 09:29:43 ----RD---- C:\Program Files (x86)\Skype
2015-07-16 17:21:32 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-07-13 21:44:54 ----SD---- C:\Windows\SYSWOW64\GWX
2015-07-13 11:15:06 ----D---- C:\Windows\system32\NDF
2015-07-09 13:24:45 ----D---- C:\Program Files (x86)\Application Updater
2015-07-08 20:26:56 ----D---- C:\Windows\Minidump
2015-07-08 20:16:07 ----A---- C:\Windows\wininit.ini
2015-07-08 15:59:58 ----D---- C:\Program Files (x86)\Vauudix
2015-07-08 15:59:58 ----D---- C:\Program Files (x86)\MinimumPruiuce
2015-07-08 15:59:58 ----D---- C:\Program Files (x86)\MinaimumPrice
2015-07-08 15:59:58 ----D---- C:\Program Files (x86)\bestadblocker
2015-07-05 17:25:54 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-05 12:08:23 ----N---- C:\Windows\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2015-07-23 65224]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2015-07-23 274808]
R0 nvstor64;nvstor64; C:\Windows\system32\drivers\nvstor64.sys [2010-04-08 244328]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2013-08-03 564824]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2015-07-23 93528]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2015-07-23 1048856]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2015-07-23 447944]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2015-07-23 28656]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2015-07-23 90968]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2015-07-23 150160]
R2 rzpmgrk;rzpmgrk; \??\C:\Windows\system32\drivers\rzpmgrk.sys [2014-08-26 37184]
R2 rzpnk;rzpnk; \??\C:\Windows\system32\drivers\rzpnk.sys [2014-09-02 129856]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-04-18 15376384]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-04-18 638976]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2013-12-19 94720]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\drivers\ASACPI.sys [2009-07-16 15416]
R3 NVNET;NVIDIA nForce Ethernet Driver; C:\Windows\system32\DRIVERS\nvmf6264.sys [2010-08-12 350952]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2009-07-14 11264]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-02-10 11856]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2010-05-15 1327520]
R3 XSplit_Dummy;XSplit Stream Audio Renderer; C:\Windows\system32\drivers\xspltspk.sys [2014-07-02 26200]
S3 amdiox64;AMD IO Driver; C:\Windows\system32\drivers\amdiox64.sys [2010-02-18 46136]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 48488]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-08-25 10611552]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys [2009-06-10 408960]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTL8167;Ovladač Realtek 8167 NT; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-06-10 187392]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 WinUsb;Android USB Driver; C:\Windows\system32\drivers\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-07 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-04-18 239616]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-04-17 344064]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2015-07-23 146600]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ForceWare Intelligent Application Manager (IAM);ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [2010-01-21 496232]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2015-07-14 2540904]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2015-07-14 417552]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-07-29 935208]
R2 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [2010-01-21 209000]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2010-03-16 159336]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-09-17 76152]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-12-08 2028864]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 2292096]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc []
S2 Razer Game Scanner Service;Razer Game Scanner; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [2014-08-26 177344]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-25 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-16 268976]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc []
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-05-22 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-07-03 148136]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2015-04-21 1931632]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2015-07-19 1001200]
S3 Program Manager;Program Manager; C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe [2015-07-23 926208]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2015-07-21 838336]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-09-05 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Mate tam toho spousty, zaliskane od sklepa az na pudu :arcisit:

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Po spusteni probehne stazeni databaze
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zellguras
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 02 srp 2015 17:59

Re: Kontrola logu

#3 Příspěvek od Zellguras »

Tady to je, snad je to ten správnej je tam ještě jeden AdwCleaner[R0]





# AdwCleaner v4.208 - Log vytvořen 03/08/2015 v 17:01:19
# Aktualizováno 09/07/2015 by Xplode
# Databáze : 2015-08-01.1 [Server]
# Operační system : Windows 7 Home Premium Service Pack 1 (x64)
# Uživatelské jméno : Dominik - MUJMILÁČEK
# Spuštěno z : C:\Users\Dominik\Desktop\adwcleaner_4.208.exe
# Nastavení : Čištění

***** [ Služby ] *****

[#] Služba Smazáno : Program Manager

***** [ Soubory / Složky ] *****

Složka Smazáno : C:\ProgramData\apn
Složka Smazáno : C:\ProgramData\Ask
Složka Smazáno : C:\ProgramData\ICQ\ICQToolbar
Složka Smazáno : C:\ProgramData\6960076357452959605
Složka Smazáno : C:\ProgramData\{5d2e0172-bea4-de59-5d2e-e0172bea05ca}
Složka Smazáno : C:\ProgramData\{8052f28d-d3b7-967d-8052-2f28dd3bca37}
Složka Smazáno : C:\ProgramData\{c9458b30-ed1b-8553-c945-58b30ed12cc3}
Složka Smazáno : C:\ProgramData\{dbdfc82f-3620-ac0d-dbdf-fc82f36220bc}
Složka Smazáno : C:\Program Files (x86)\Application Updater
Složka Smazáno : C:\Program Files (x86)\SearchMe Toolbar
Složka Smazáno : C:\Program Files (x86)\Vaudix
Složka Smazáno : C:\Program Files (x86)\bestadblocker
Složka Smazáno : C:\Program Files (x86)\couponight
Složka Smazáno : C:\Program Files (x86)\CeheaPMe
Složka Smazáno : C:\Program Files (x86)\CheAApMe
Složka Smazáno : C:\Program Files (x86)\CheApeMei
Složka Smazáno : C:\Program Files (x86)\ChEappMe
Složka Smazáno : C:\Program Files (x86)\CheeaPMe
Složka Smazáno : C:\Program Files (x86)\CiheapME
Složka Smazáno : C:\Program Files (x86)\HaaPPpuy2Siave
Složka Smazáno : C:\Program Files (x86)\Haappuy2Savie
Složka Smazáno : C:\Program Files (x86)\Haoppy2Save
Složka Smazáno : C:\Program Files (x86)\MinaimumPrice
Složka Smazáno : C:\Program Files (x86)\MinimuMPrice
Složka Smazáno : C:\Program Files (x86)\MinimumPruiuce
Složka Smazáno : C:\Program Files (x86)\RobaoSavver
Složka Smazáno : C:\Program Files (x86)\RobboSaver
Složka Smazáno : C:\Program Files (x86)\RobOSAVeer
Složka Smazáno : C:\Program Files (x86)\Vauudix
Složka Smazáno : C:\Program Files (x86)\WhIteOOffersApup
Složka Smazáno : C:\Program Files (x86)\Common Files\ProgramManager
Složka Smazáno : C:\Windows\System32\ljkb
Složka Smazáno : C:\Users\Dominik\AppData\Local\apn
Složka Smazáno : C:\Users\Dominik\AppData\Local\OpenCandy
Složka Smazáno : C:\Users\Dominik\AppData\Local\Slick Savings
Složka Smazáno : C:\Users\Dominik\AppData\LocalLow\Conduit
Složka Smazáno : C:\Users\Dominik\AppData\LocalLow\Minibar
Složka Smazáno : C:\Users\Dominik\AppData\LocalLow\SearchMe
Složka Smazáno : C:\Users\Dominik\AppData\Roaming\OpenCandy
Složka Smazáno : C:\Users\Dominik\AppData\Roaming\BrowserExtensions
Složka Smazáno : C:\Users\Dominik\Documents\PCSpeedUp
Složka Smazáno : C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Složka Smazáno : C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Soubor Smazáno : C:\Program Files (x86)\prefs.js
Soubor Smazáno : C:\Windows\SysWOW64\conduitEngine.tmp
Soubor Smazáno : C:\Users\Dominik\AppData\Local\Temp\Utils.dll
Soubor Smazáno : C:\Windows\System32\dmwu.exe
Soubor Smazáno : C:\Windows\System32\ImhxxpComm.dll
Soubor Smazáno : C:\Users\Dominik\AppData\LocalLow\SkwConfig.bin

***** [ Naplánované úlohy ] *****

Úloha Smazáno : Bidaily Synchronize Task

***** [ Zástupci ] *****


***** [ Registry ] *****

Hodnota Smazáno : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [sweetsearch@gmail.com]
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\bejbohlohkkgompgecdcbbglkpjfjgdj
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Klíč Smazáno : HKLM\SOFTWARE\Classes\Conduit.Engine
Klíč Smazáno : HKLM\SOFTWARE\Classes\Prod.cap
Hodnota Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Extensions]
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ask.com
Klíč Smazáno : HKLM\SOFTWARE\c3ca4e0f-e3b0-a301-6dea-f764ed6f09a2
Klíč Smazáno : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{1F831F60-05FB-474D-93A3-42DA68E7EB8F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{CBD6173B-4061-4104-BF2F-C8E81389DB27}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{EB559340-3A8F-4456-B24D-160098054EF0}
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{21FA44EF-376D-4D53-9B0F-8A89D3229068}]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{B9C767DD-F66A-40B4-8F12-4199A9A4393C}]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}]
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB9}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{71DA002B-09B3-4FA5-A9F0-3206D58C8566}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8172f457-818d-46db-941f-2bbe53e156af}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Klíč Smazáno : HKCU\Software\BI
Klíč Smazáno : HKCU\Software\Conduit
Klíč Smazáno : HKCU\Software\IM
Klíč Smazáno : HKCU\Software\Softonic
Klíč Smazáno : HKCU\Software\WNLT
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Browser Extensions
Klíč Smazáno : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Klíč Smazáno : HKLM\SOFTWARE\Application Updater
Klíč Smazáno : HKLM\SOFTWARE\Conduit
Klíč Smazáno : HKLM\SOFTWARE\ICQ\ICQToolbar
Klíč Smazáno : HKLM\SOFTWARE\Trymedia Systems
Klíč Smazáno : HKLM\SOFTWARE\Uniblue
Klíč Smazáno : HKLM\SOFTWARE\mystartsearchSoftware
Klíč Smazáno : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Klíč Smazáno : HKLM\SOFTWARE\FFPluginHp
Klíč Smazáno : HKU\.DEFAULT\Software\IM
Klíč Smazáno : HKU\.DEFAULT\Software\WNLT
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30C16B15B255BD349A1157B8A83E2AF9
Klíč Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED1CAE30F47D14B41B5FC8FA53658044
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\apnwidgets.ask.com
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mystartsearch.com
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.mystartsearch.com

***** [ Prohlížeče ] *****

-\\ Internet Explorer v11.0.9600.17840

Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Nastavení Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [First Home Page]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Nastavení Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Nastavení Obnoveno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Nastavení Obnoveno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Nastavení Obnoveno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Mozilla Firefox v39.0 (x86 cs)


-\\ Google Chrome v

[C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1408 ... earchTerms}
[C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1408 ... earchTerms}
[C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://www.istartsurf.com/web/?type=ds&ts=1408 ... earchTerms}
[C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Homepage] :
[C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Smazáno [Startup_URLs] : 557EAA1A0F0699588F1A2287D43ED4447A6E4DCB7C34C9B3ED2ECB6BD69815F2"},"software_reporter":{"prompt_reason":"3244792882524569AFCD2F620B80D24A13653BDC1750515A21C16FC145894AA0","prompt_seed":"287AFDA76596E4887D2E40CC3FD2316D3156458F6D3D0708CBD23E7C3DE4075A","prompt_version":"E4F919A0EE3CA849E27810215252514B72520EA50478121DDC303198E959742F"},"sync":{"remaining_rollback_tries":"118700FA3632E9D434FB0958E266D406F62E6E14BD08F0EF89D5A94B2138B0FD"}},"super_mac":"CB4CCC0D348D05FF693097C49ACFC35A7A70389288EF5A4BA89F3C43505F18F3"},"session":{"restore_on_startup":1,"startup_urls":["hxxp://search.gboxapp.com/

-\\ Chromium v


*************************

AdwCleaner[R0].txt - [18072 bytů] - [03/08/2015 16:59:35]
AdwCleaner[S0].txt - [10718 bytů] - [03/08/2015 17:01:19]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10777 bytů] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#4 Příspěvek od vyosek »

:arrow: Ano, tohle je OK

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zellguras
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 02 srp 2015 17:59

Re: Kontrola logu

#5 Příspěvek od Zellguras »

Tak tady to je :) :oops:


Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Dominik on po 03.08.2015 at 18:27:40,62.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Dominik\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

3.8.2015 18:30:05 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~2\Convar deleted successfully
C:\PROGRA~2\Digiarty deleted successfully
C:\PROGRA~2\ESET deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully
C:\PROGRA~3\BioWare deleted successfully
C:\PROGRA~3\Hi-Rez Studios deleted successfully
C:\Users\Dominik\AppData\Roaming\TP deleted successfully
C:\Users\Dominik\AppData\Roaming\Windows Live Writer deleted successfully
C:\Users\Dominik\AppData\Local\Application Data deleted successfully
C:\Users\Dominik\AppData\Local\WarThunder deleted successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\CrashDumps deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1862008024-4103658504-1558178943-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} deleted successfully
HKEY_USERS\S-1-5-21-1862008024-4103658504-1558178943-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{B9C767DD-F66A-40B4-8F12-4199A9A4393C} deleted successfully
HKEY_USERS\S-1-5-21-1862008024-4103658504-1558178943-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{91397D20-1446-11D4-8AF4-0040CA1127B6} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz");
user_pref("browser.search.defaulturl", "http://search.seznam.cz/?sourceid=quick ... earchTerms}&");
user_pref("browser.search.defaultengine", "Seznam");
user_pref("browser.search.defaultenginename", "Seznam");
user_pref("browser.search.selectedEngine", "Seznam");
user_pref("browser.search.order.1", "Seznam");
user_pref("keyword.URL", "http://search.seznam.cz/?sourceid=quick ... earchTerms}&");

Added to C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\q7n80u3x.default\prefs.js:

Added to C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\q7n80u3x.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563

user.js not found
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----

prefs_03.08.2015_1855_.backup

ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\q7n80u3x.default

user.js not found
---- FireFox user.js and prefs.js backups ----


==== Deleting Files \ Folders ======================

C:\PROGRA~2\AGEIA Technologies not found
C:\PROGRA~2\Convar not found
C:\PROGRA~2\Digiarty not found
C:\PROGRA~2\ESET not found
C:\PROGRA~2\K-Lite Codec Pack deleted
C:\PROGRA~2\Autofill IRCTC Tatkal FormPlugin Extension deleted
C:\PROGRA~2\EXIF Viewer deleted
C:\PROGRA~2\Hypothesis Web PDF Annotation deleted
C:\PROGRA~2\Movenote for Gmail deleted
C:\PROGRA~2\New Tab New Window deleted
C:\PROGRA~2\Tart Management deleted
C:\Users\Dominik\AppData\Roaming\appdataFr2.bin deleted
C:\PROGRA~3\ICQ deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Dominik\AppData\Local\CrashRpt deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\Windows\wininit.ini deleted
C:\Windows\tasks\LyricsXX.job deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Windows\Syswow64\mjcm deleted
C:\windows\SysNative\tprb deleted
C:\Windows\SysWow64\AI_RecycleBin deleted
C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\q7n80u3x.default\CT2786678 deleted
C:\Users\Dominik\Desktop\SoftonicDownloader_for_ace-of-spades.exe.part deleted
C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\q7n80u3x.default\conduitCommon deleted
"C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\q7n80u3x.default\extensions\searchme@mybrowserbar.com" deleted
"C:\Users\Dominik\AppData\Roaming\Yandex\ui" deleted
"C:\Users\Dominik\AppData\Roaming\Yandex" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\q7n80u3x.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [23.07.2015 17:28]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563
FD82108FD60B63010325D9AF6F00AF99 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll - Shockwave Flash


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx[23.07.2015 17:28]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[23.07.2015 17:28]

Seznam Lištička - Slovník - Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd
panda dumpling - Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaclfkfmcnlppkambfehbfhlekhpenf
Little Alchemy - Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd
Seznam Lištička - Rychlá volba - Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak

==== Chromium Startpages ======================

C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Preferences
NIN_STARTED":{"time":"With refresh token","value":"21.07.15 19:23:46"}},"signin_scoped_device_id":"F8A61177-9E81-4DE0-AA7C-8648613CD052","user_account_id":"101590254618746583856"}},"http_original_content_length":"23631474","http_received_content_length":"23631474","intl":{"accept_languages":"cs-CZ,cs"},"invalidation_service":{"use_gcm_channel":true},"invalidator":{"client_id":"vqX6Qgc2lDzHhzMR65R+9A==","invalidation_state":"CicKJQoGCgQIAxABEhIJeOvncv6HsZoRbUYSZNt+k9AaBwiCMhADGAESFEDAvMxmHjBF+vbitYsYGnjF+KPR","saved_invalidations":[{"invalidation-list":[],"name":"APP","source":"1004"},{"invalidation-list":[],"name":"APP_LIST","source":"1004"},{"invalidation-list":[],"name":"APP_SETTING","source":"1004"},{"invalidation-list":[],"name":"AUTOFILL","source":"1004"},{"invalidation-list":[],"name":"AUTOFILL_PROFILE","source":"1004"},{"invalidation-list":[],"name":"AUTOFILL_WALLET","source":"1004"},{"invalidation-list":[],"name":"BOOKMARK","source":"1004"},{"invalidation-list":[],"name":"DEVICE_INFO","source":"1004"},{"invalidation-list":[],"name":"DICTIONARY","source":"1004"},{"invalidation-list":[],"name":"EXPERIMENTS","source":"1004"},{"invalidation-list":[],"name":"EXTENSION","source":"1004"},{"invalidation-list":[],"name":"EXTENSION_SETTING","source":"1004"},{"invalidation-list":[],"name":"FAVICON_IMAGE","source":"1004"},{"invalidation-list":[],"name":"FAVICON_TRACKING","source":"1004"},{"invalidation-list":[],"name":"HISTORY_DELETE_DIRECTIVE","source":"1004"},{"invalidation-list":[],"name":"MANAGED_USER","source":"1004"},{"invalidation-list":[],"name":"MANAGED_USER_SHARED_SETTING","source":"1004"},{"invalidation-list":[],"name":"NIGORI","source":"1004"},{"invalidation-list":[],"name":"PASSWORD","source":"1004"},{"invalidation-list":[],"name":"PREFERENCE","source":"1004"},{"invalidation-list":[],"name":"PRIORITY_PREFERENCE","source":"1004"},{"invalidation-list":[],"name":"SEARCH_ENGINE","source":"1004"},{"invalidation-list":[],"name":"SESSION","source":"1004"},{"invalidation-list":[],"name":"THEME","source":"1004"},{"invalidation-list":[],"name":"TYPED_URL","source":"1004"}]},"media":{"device_id_salt":"rW6Gb/VDCkXE1ERN0p1n6w=="},"net":{"http_server_properties":{"servers":{"accounts.google.com:443":{"supports_spdy":true},"chrome.google.com:443":{"supports_spdy":true},"clients2.google.com:443":{"supports_spdy":true},"clients2.googleusercontent.com:443":{"supports_spdy":true},"easylist-downloads.adblockplus.org:443":{"supports_spdy":true},"notification.adblockplus.org:443":{"supports_spdy":true},"redirector.gvt1.com:443":{"supports_spdy":true},"ssl.gstatic.com:443":{"supports_spdy":true},"www.google-analytics.com:443":{"supports_spdy":true},"www.google.com:443":{"supports_spdy":true},"www.google.cz:443":{"supports_spdy":true},"www.googleadservices.com:443":{"supports_spdy":true},"www.googleapis.com:443":{"supports_spdy":true},"www.gstatic.com:443":{"supports_spdy":true}},"version":3}},"ntp":{"app_page_names":["Aplikace"]},"partition":{"per_host_zoom_levels":{"3155232537":{}}},"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"exceptions":{"app_banner":{},"auto_select_certificate":{},"automatic_downloads":{},"cookies":{},"fullscreen":{"[*.]www.youtube.com,*":{"setting":1},"[*.]youbo.iprima.cz,*":{"setting":1},"https://[*.]www.youtube.com:443,*":{"setting":1}},"geolocation":{},"images":{},"javascript":{},"media_stream":{},"media_stream_camera":{},"media_stream_mic":{},"metro_switch_to_desktop":{},"midi_sysex":{},"mixed_script":{},"mouselock":{},"notifications":{},"plugins":{},"popups":{},"ppapi_broker":{},"protocol_handlers":{},"push_messaging":{},"ssl_cert_decisions":{}},"pattern_pairs":{"[*.]www.youtube.com,*":{"fullscreen":1},"[*.]youbo.iprima.cz,*":{"fullscreen":1},"https://[*.]www.youtube.com:443,*":{"fullscreen":1}},"pref_version":1},"default_content_settings":{},"exit_type":"Normal","exited_cleanly":true,"gaia_info_picture_url":"https://lh3.googleusercontent.com/-XdUIqdMkCWA/AAAAAAAAAAI/AAAAAAAAAAA/4252rscbv5M/s256-c/photo.jpg","gaia_info_update_time":"13082138114525200","icon_version":3,"managed_user_id":"","managed_users":{},"migrated_content_settings_exceptions":true,"migrated_default_content_settings":true,"migrated_default_media_stream_content_settings":true,"name":"První uživatel","per_host_zoom_levels":{}},"protection":{"macs":{}},"reverse_autologin":{"enabled":false},"session":{"restore_on_startup_migrated":true,"startup_urls_migration_time":"13081936785860600"},"signin":{"signedin_time":"13081973027079000"},"sync":{"encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAA8tYmqSWH1k+RGdLCIRabJgAAAAACAAAAAAAQZgAAAAEAACAAAACFz5B14ClvY2g2S0ypBtX0bx7AP5baP0E2sEuibN7dxAAAAAAOgAAAAAIAACAAAABu2utCaCTb2qA8KQ/Ut70Lo6X+tUTlpDpTCrmpHlzoBEAAAAB5sdlyA8t5ZQFwPNFZVN0XUbGFPE20WGB/Fc6jkRShXAUZwENNCn4i8NS4XV4/A4mn/kYuvO5PAz/Y7xdTUZ2uQAAAAOAdwD67jqPhVrRt+hwlogVi1xqW74c3nUO/hFpte8mOoj8coI+vjftCH8ItoylIJSwdvoarRdTaT0DO2zDvAZs=","first_sync_time":"13081973027533000","has_setup_completed":true,"keystore_encryption_bootstrap_token":"AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAA8tYmqSWH1k+RGdLCIRabJgAAAAACAAAAAAAQZgAAAAEAACAAAAC/D+uPpXfQbkDFsXsbAR+RQpzotEMbLNKIrO1a23M0ZQAAAAAOgAAAAAIAACAAAADlh2Ll0q8z20U6Ng5X1Y9IgNKgpzgSd/4tygCF485q51AAAAC1WP93PaTR3EN/WKHUSR+EvZk/mejHrg8V0O6EaVNjaG/xe5QPCf/YdK5aHHF8u+S0p7lKLoD5TijJ6kDvdOFmzI58LCWV7U5eqCtalQHbvUAAAACvSYp4qEAMJhc+Qg5liSi0JEfqbMsOH1UsU/199lW/JxASTzI+wX8KgEUVZjihgHGMquo1GWMGQBYp6ETDgxwj","last_synced_time":"13082138389255200","memory_warning_count":0,"session_sync_guid":"session_syncSUkq0CjrJ6zFKBOvtBWXdg==","shutdown_cleanly":true,"suppress_start":false},"sync_promo":{"startup_count":2},"translate_accepted_count":{"de":0,"en":0,"sk":0},"translate_blocked_languages":["cs"],"translate_denied_count_for_language":{"en":1},"translate_last_denied_time_for_language":{"en":1437664787183.2},"translate_whitelists":{}}
49A","pinned_tabs":"1912F547FCCFB46F670E426D0E01CB4CC442445CF886EA59476AD31F299BAE76","prefs":{"preference_reset_time":"A7C7603C08B9CCE2F9E7DA0FF023F5FECDD10CEA30E9E61D9A42D8A7AC320569"},"profile":{"reset_prompt_memento":"CD9060C31D2CFE44C51A3CFB88D0EDF8A0152A91456C891D0CE5B19AE0CFAB6E"},"safebrowsing":{"incidents_sent":"F9EA6497DAA19E67D943AC44E8232A16E61F1DBCFF6513E45A3185E48DBF878E"},"search_provider_overrides":"A9D9A16F7EC8CD87B83E1940AC18E03B94363C6234FB85ABDE7E8F784F1A3CB4","session":{"restore_on_startup":"ADA49B9C7EB03911DFB55A011ED9446FED8186BE8B6641495638C7FCE2B1002E","startup_urls":,"http://www.istartsurf.com/?type=hp&ts=1 ... 1703217032"]},"sync":{"remaining_rollback_tries":0}}


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/?pc=MSSE"
"Default_Page_URL"="http://www.google.com"
"First Home Page"="http://www.google.com"
"ICQ Search"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Search Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"ICQ Search"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"First Home Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.msn.com/?pc=MSSE"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{399a1442-7377-49e7-8d77-6dc9ed5968c1} Zbozi Url="http://www.zbozi.cz/?q={searchTerms}&so ... earch_6826"
{5cf5d387-d87c-4408-9a6b-301b0713d62a} Mapy Url="http://www.mapy.cz/?query={searchTerms} ... earch_6826"
{D2AAC610-FF8D-4F73-93BB-47DC6C857A3C} Bing Url="http://www.bing.com/search?q={searchTer ... DF&pc=MSSE"
{eb97f7df-1773-4916-aae6-5af74da8c69d} Firmy Url="http://www.firmy.cz/phr/{searchTerms}"

==== Reset Google Chrome ======================

C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\weatherbugalert.exe deleted successfully
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Dominik\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1AD2EZ5W will be deleted at reboot
C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NQHUF4H will be deleted at reboot
C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8USNIJXF will be deleted at reboot
C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9TQF6PUZ will be deleted at reboot
C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KXT87EZO will be deleted at reboot
C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MLQMOGUH will be deleted at reboot
C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYVMNR9N will be deleted at reboot
C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XMN5Q3OW will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Dominik\AppData\Local\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=215 folders=86 64819303 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Dominik\AppData\Local\Temp will be emptied at reboot
C:\Users\hedev\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Dominik\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1AD2EZ5W" not found
"C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NQHUF4H" not found
"C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8USNIJXF" not found
"C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9TQF6PUZ" not found
"C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KXT87EZO" not found
"C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MLQMOGUH" not found
"C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MYVMNR9N" not found
"C:\Users\Dominik\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XMN5Q3OW" not found

==== EOF on po 03.08.2015 at 19:05:45,40 ======================

Zellguras
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 02 srp 2015 17:59

Re: Kontrola logu

#6 Příspěvek od Zellguras »

Je všechno v pořádku, dlouho jste mi neodpověděli, tak jestli už je hotovo ? :) :?:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#7 Příspěvek od vyosek »

Omlouvam se, nejak jsem nestihal...

Poprosim o FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zellguras
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 02 srp 2015 17:59

Re: Kontrola logu

#8 Příspěvek od Zellguras »

V pořádku, za to co tu děláte by jste měli dostávat zaplaceno :)


Jinak při otevření FRSTlauncheru a skenování mi to psalo něco, o omezení na 32bitovou verzi, ale log mi to dalo, tady je :

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-08-2015
Ran by Dominik (administrator) on MUJMILÁČEK (08-08-2015 13:51:18)
Running from C:\Users\Dominik\Desktop
Loaded Profiles: Dominik (Available Profiles: Dominik)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
() C:\Windows\SysWOW64\C2MP\TrayMenu.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(forum.viry.cz) C:\Users\Dominik\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2439072 2010-05-24] (VIA)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6109776 2015-07-23] (AVAST Software)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5579624 2015-08-03] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TrayMenu.lnk [2015-01-05]
ShortcutTarget: TrayMenu.lnk -> C:\Windows\SysWOW64\C2MP\TrayMenu.exe ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-23] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
URLSearchHook: HKLM-x32 -> Default = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1862008024-4103658504-1558178943-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1862008024-4103658504-1558178943-1001 -> {399a1442-7377-49e7-8d77-6dc9ed5968c1} URL = http://www.zbozi.cz/?q={searchTerms}&so ... earch_6826
SearchScopes: HKU\S-1-5-21-1862008024-4103658504-1558178943-1001 -> {5cf5d387-d87c-4408-9a6b-301b0713d62a} URL = http://www.mapy.cz/?query={searchTerms} ... earch_6826
SearchScopes: HKU\S-1-5-21-1862008024-4103658504-1558178943-1001 -> {D2AAC610-FF8D-4F73-93BB-47DC6C857A3C} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1862008024-4103658504-1558178943-1001 -> {eb97f7df-1773-4916-aae6-5af74da8c69d} URL = http://www.firmy.cz/phr/{searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-23] (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-07-23] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-23] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-23] (Oracle Corporation)
DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93}
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
DPF: HKLM-x32 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\..\Interfaces\{A28CDED4-33FC-45CA-B455-85160B67228E}: [DhcpNameServer] 46.23.128.4

FireFox:
========
FF ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563
FF DefaultSearchEngine: Seznam
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-16] ()
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll [2014-09-01] (EA Digital Illusions CE AB)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-16] ()
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll [2014-09-01] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-23] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-07-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-07-21] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563\searchplugins\seznam-avast.xml [2015-07-23]
FF Extension: Adblock Plus - C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\hcjlevge.default-1436374711563\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-07-22]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-07-23]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2015-08-07] <==== ATTENTION

Chrome:
=======
CHR Profile: C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-21]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2015-07-23]
CHR Extension: (YouTube) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-21]
CHR Extension: (panda dumpling) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaclfkfmcnlppkambfehbfhlekhpenf [2015-07-23]
CHR Extension: (Google Search) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-21]
CHR Extension: (Little Alchemy) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd [2015-07-23]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-07-23]
CHR Extension: (Gmail) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-21]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-07-23]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-23]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-07-23] (AVAST Software)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] ()
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-08-03] (LogMeIn, Inc.)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] ()
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-04-21] (Electronic Arts)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1001200 2015-07-19] (Overwolf LTD)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-09-17] ()
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [177344 2014-08-26] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2028864 2011-12-08] (TuneUp Software)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-07-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-07-23] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-07-23] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048856 2015-07-23] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-07-23] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150160 2015-07-23] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-07-23] (AVAST Software)
R3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [15416 2009-07-16] ()
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2014-08-26] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129856 2014-09-02] (Razer, Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-08-03] (Duplex Secure Ltd.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [11856 2011-02-10] (TuneUp Software)
U3 Winsock; no ImagePath
R3 XSplit_Dummy; C:\Windows\System32\drivers\xspltspk.sys [26200 2014-07-02] (SplitmediaLabs Limited)
S3 EverestDriver; \??\C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-08 13:51 - 2015-08-08 13:51 - 00016550 _____ C:\Users\Dominik\Desktop\FRST.txt
2015-08-08 13:50 - 2015-08-08 13:51 - 00000000 ____D C:\FRST
2015-08-08 13:46 - 2015-08-08 13:47 - 00112640 _____ (forum.viry.cz) C:\Users\Dominik\Desktop\FRSTLauncher.exe
2015-08-08 13:42 - 2015-08-08 13:42 - 02169856 _____ (Farbar) C:\Users\Dominik\Desktop\FRST64.exe
2015-08-07 10:17 - 2015-08-08 07:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-03 19:06 - 2015-08-03 19:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-08-03 19:05 - 2015-08-03 19:06 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi
2015-08-03 19:02 - 2015-08-03 18:27 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-08-03 18:29 - 2015-08-03 19:05 - 00022681 _____ C:\zoek-results.log
2015-08-03 18:27 - 2015-08-03 18:55 - 00000000 ____D C:\zoek_backup
2015-08-03 18:27 - 2015-08-03 18:27 - 01308672 _____ C:\Users\Dominik\Desktop\zoek.exe
2015-08-03 16:59 - 2015-08-03 17:01 - 00000000 ____D C:\AdwCleaner
2015-08-03 16:58 - 2015-08-03 16:58 - 02248704 _____ C:\Users\Dominik\Desktop\adwcleaner_4.208.exe
2015-08-03 16:13 - 2015-08-03 16:26 - 00000000 ____D C:\Program Files\trend micro
2015-08-03 16:13 - 2015-08-03 16:15 - 00000000 ____D C:\rsit
2015-08-03 16:06 - 2015-08-03 16:06 - 01222144 _____ C:\Users\Dominik\Downloads\RSITx64.exe
2015-08-02 13:21 - 2015-08-02 13:53 - 00000000 ____D C:\Users\Dominik\AppData\Local\Purplizer
2015-08-02 13:17 - 2015-08-02 13:17 - 00003728 _____ C:\Windows\System32\Tasks\Overwolf Updater Task
2015-08-02 13:17 - 2015-08-02 13:17 - 00001982 _____ C:\Users\Public\Desktop\Overwolf.lnk
2015-08-02 13:17 - 2015-08-02 13:17 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2015-08-02 13:17 - 2015-08-02 13:17 - 00000000 ____D C:\Program Files (x86)\Overwolf
2015-08-02 13:16 - 2015-08-02 13:17 - 00000000 ____D C:\ProgramData\Overwolf
2015-08-02 13:15 - 2015-08-08 13:48 - 00000000 ____D C:\Users\Dominik\AppData\Local\Overwolf
2015-08-02 13:14 - 2015-08-02 13:14 - 01600240 _____ (Overwolf) C:\Users\Dominik\Downloads\OverwolfInstaller.exe
2015-07-30 17:45 - 2015-07-30 18:32 - 840053902 _____ C:\Users\Dominik\Downloads\(2007)-Hostel-2-dab-cz.avi
2015-07-24 20:15 - 2015-07-24 20:21 - 00000000 ____D C:\Users\Dominik\AppData\Local\SkinSpotlightsReplays
2015-07-24 20:15 - 2015-07-22 10:08 - 02860032 _____ C:\Users\Dominik\Desktop\SkinSpotlightsReplays.RELEASE.exe
2015-07-24 20:14 - 2015-07-24 20:15 - 01657972 _____ C:\Users\Dominik\Downloads\SkinSpotlightsReplays-2.0.0.15a.zip
2015-07-23 17:33 - 2015-07-23 17:33 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\AVAST Software
2015-07-23 17:29 - 2015-08-07 09:51 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-07-23 17:29 - 2015-07-23 17:29 - 00001929 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-07-23 17:29 - 2015-07-23 17:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-07-23 17:28 - 2015-07-23 17:28 - 01048856 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-07-23 17:28 - 2015-07-23 17:28 - 00447944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-07-23 17:28 - 2015-07-23 17:28 - 00378880 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-07-23 17:28 - 2015-07-23 17:28 - 00274808 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-07-23 17:28 - 2015-07-23 17:28 - 00150160 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-07-23 17:28 - 2015-07-23 17:28 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-07-23 17:28 - 2015-07-23 17:28 - 00090968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-07-23 17:28 - 2015-07-23 17:28 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-07-23 17:28 - 2015-07-23 17:28 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-07-23 17:28 - 2015-07-23 17:28 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-07-23 17:27 - 2015-07-23 17:27 - 00000000 ____D C:\Program Files\AVAST Software
2015-07-23 17:23 - 2015-07-23 17:23 - 05500000 _____ (Avast Software s.r.o.) C:\Users\Public\Desktop\avast_free_antivirus_setup_online.exe
2015-07-23 17:23 - 2015-07-23 17:23 - 05500000 _____ (Avast Software s.r.o.) C:\Users\Dominik\Downloads\avast_free_antivirus_setup_online.exe
2015-07-23 17:23 - 2015-07-23 17:23 - 00000000 ____D C:\ProgramData\AVAST Software
2015-07-22 19:49 - 2015-07-22 19:49 - 00000000 ____D C:\Users\Dominik\AppData\Local\CEF
2015-07-22 08:50 - 2015-07-23 14:50 - 00000358 _____ C:\Windows\Tasks\RubyBuddy.job
2015-07-21 09:17 - 2015-07-23 17:22 - 00000000 ____D C:\Program Files (x86)\Google
2015-07-20 17:22 - 2015-07-20 17:22 - 00000000 ____D C:\Users\Dominik\Documents\Square Enix
2015-07-20 15:29 - 2015-07-20 15:30 - 00018549 _____ C:\Windows\DirectX.log
2015-07-09 13:25 - 2015-08-08 07:02 - 00001904 _____ C:\Windows\setupact.log
2015-07-09 13:24 - 2015-08-08 07:02 - 00005060 _____ C:\Windows\PFRO.log

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-08 13:48 - 2014-10-29 11:41 - 00000000 ____D C:\Users\Dominik\AppData\Local\Battle.net
2015-08-08 13:21 - 2012-11-16 17:26 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-08 13:04 - 2011-09-07 14:47 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\Skype
2015-08-08 08:45 - 2009-07-14 06:45 - 00023056 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-08 08:45 - 2009-07-14 06:45 - 00023056 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-08 07:05 - 2011-09-03 19:46 - 01187311 _____ C:\Windows\WindowsUpdate.log
2015-08-08 07:03 - 2011-10-22 14:41 - 00000000 ____D C:\Users\Dominik\AppData\Local\LogMeIn Hamachi
2015-08-08 07:02 - 2015-05-22 08:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-08 07:02 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-05 08:21 - 2011-09-07 14:47 - 00000000 ____D C:\ProgramData\Skype
2015-08-04 20:20 - 2011-09-05 18:40 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\vlc
2015-08-03 21:30 - 2014-10-29 11:41 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-08-03 12:12 - 2012-02-06 12:27 - 00033856 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2015-08-02 15:31 - 2014-10-30 22:42 - 00000000 ____D C:\Users\Dominik\AppData\Local\CrashDumps
2015-07-30 21:08 - 2009-07-14 17:18 - 00668866 _____ C:\Windows\system32\perfh005.dat
2015-07-30 21:08 - 2009-07-14 17:18 - 00141526 _____ C:\Windows\system32\perfc005.dat
2015-07-30 21:08 - 2009-07-14 07:13 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-30 20:54 - 2013-10-23 19:40 - 00670208 ___SH C:\Users\Dominik\Downloads\Thumbs.db
2015-07-30 10:15 - 2014-10-17 14:23 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2015-07-30 10:13 - 2015-03-16 20:40 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2015-07-29 09:18 - 2009-07-14 07:08 - 00032638 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-07-28 19:52 - 2011-09-09 18:57 - 00000000 ____D C:\Users\Dominik\Desktop\Fotky,Videa
2015-07-27 16:19 - 2013-12-02 15:56 - 00000404 _____ C:\Windows\Tasks\EasyShare Registration Task.job
2015-07-26 19:56 - 2011-11-18 20:23 - 00000000 ____D C:\Users\Dominik\Desktop\Dominik
2015-07-25 10:15 - 2013-02-11 00:06 - 00000000 ____D C:\Program Files (x86)\Steam
2015-07-25 10:07 - 2015-04-04 21:49 - 00000000 ___SD C:\Windows\system32\GWX
2015-07-24 13:46 - 2012-03-31 19:35 - 00003806 _____ C:\Windows\System32\Tasks\Java Update Scheduler
2015-07-23 22:50 - 2015-05-22 08:41 - 00001146 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-23 22:50 - 2015-05-22 08:41 - 00001146 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-23 22:47 - 2014-05-19 19:54 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-07-23 22:46 - 2014-05-19 19:54 - 00000000 ____D C:\Program Files (x86)\Java
2015-07-23 22:46 - 2011-09-06 16:02 - 00000000 ____D C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-07-23 22:46 - 2011-09-06 16:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-07-23 22:46 - 2011-09-05 19:38 - 00000000 ____D C:\Program Files (x86)\WinRAR
2015-07-23 17:22 - 2011-02-25 15:41 - 00001912 _____ C:\Windows\epplauncher.mif
2015-07-23 14:50 - 2015-06-04 14:50 - 00000358 _____ C:\Windows\Tasks\SystemReset.job
2015-07-21 22:44 - 2011-09-09 18:57 - 00000000 ____D C:\Users\Dominik\Desktop\Hudba
2015-07-21 09:19 - 2011-09-06 16:04 - 00000000 ____D C:\Users\Dominik\AppData\Local\Google
2015-07-20 16:05 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-07-17 09:29 - 2014-09-24 16:17 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-07-16 17:21 - 2012-11-16 17:26 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-16 17:21 - 2012-11-16 17:26 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-16 17:21 - 2011-09-05 14:23 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-16 15:47 - 2015-05-12 17:56 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-07-16 15:45 - 2015-05-12 17:57 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-07-13 21:44 - 2015-04-04 21:49 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-07-13 11:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF

==================== Files in the root of some directories =======

2011-09-05 21:39 - 2013-12-09 20:28 - 0000141 _____ () C:\Users\Dominik\AppData\Roaming\default.rss
2014-10-28 17:55 - 2014-12-03 18:48 - 0052224 _____ () C:\Users\Dominik\AppData\Roaming\RZR_0020d7df4d89b0017e02bfa126dc.db
2015-06-04 15:05 - 2015-06-04 15:05 - 0000000 _____ () C:\Users\Dominik\AppData\Local\Temp.dat
2013-09-18 18:57 - 2013-09-18 18:57 - 0000057 _____ () C:\ProgramData\Ament.ini

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\EasyShare Registration Task.job => C:\Windows\system32\rundll32.exeZC:\PROGRA~3\Kodak\EasyShareSetup\$REGIS~1\Registration_7.9.30.1.sxt
Task: C:\Windows\Tasks\RubyBuddy.job => c:\programdata\{5d2e0172-bea4-de59-5d2e-e0172bea05ca}\6870889780498486551b.exe <==== ATTENTION
Task: C:\Windows\Tasks\SystemReset.job => c:\programdata\{c9458b30-ed1b-8553-c945-58b30ed12cc3}\8954514573165499247b.exe <==== ATTENTION

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Dominik\Desktop" je 304134 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#9 Příspěvek od vyosek »

:arrow: Odinstalujte Spybot - Search & Destroy - ma uz nejlepsi leta za sebou a neni schopen celit aktualnim hrozbam...

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5579624 2015-08-03] (LogMeIn Inc.)
    HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
    HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TrayMenu.lnk [2015-01-05]
    
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
    HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
    URLSearchHook: HKLM-x32 -> Default = {855F3B16-6D32-4fe6-8A56-BBB695989046}
    SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
    SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93} 
    DPF: HKLM-x32 {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} 
    DPF: HKLM-x32 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} 
    
    FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
    FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2015-08-07] <==== ATTENTION
    
    CHR Extension: (panda dumpling) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaclfkfmcnlppkambfehbfhlekhpenf [2015-07-23]
    
    S3 EverestDriver; \??\C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X]
    
    2015-08-08 13:51 - 2015-08-08 13:51 - 00016550 _____ C:\Users\Dominik\Desktop\FRST.txt
    2015-08-08 13:46 - 2015-08-08 13:47 - 00112640 _____ (forum.viry.cz) C:\Users\Dominik\Desktop\FRSTLauncher.exe
    2015-08-03 19:02 - 2015-08-03 18:27 - 00024064 _____ C:\Windows\zoek-delete.exe
    2015-08-03 18:29 - 2015-08-03 19:05 - 00022681 _____ C:\zoek-results.log
    2015-08-03 18:27 - 2015-08-03 18:55 - 00000000 ____D C:\zoek_backup
    2015-08-03 18:27 - 2015-08-03 18:27 - 01308672 _____ C:\Users\Dominik\Desktop\zoek.exe
    2015-08-03 16:59 - 2015-08-03 17:01 - 00000000 ____D C:\AdwCleaner
    2015-08-03 16:58 - 2015-08-03 16:58 - 02248704 _____ C:\Users\Dominik\Desktop\adwcleaner_4.208.exe
    2015-08-03 16:13 - 2015-08-03 16:26 - 00000000 ____D C:\Program Files\trend micro
    2015-08-03 16:13 - 2015-08-03 16:15 - 00000000 ____D C:\rsit
    2015-08-03 16:06 - 2015-08-03 16:06 - 01222144 _____ C:\Users\Dominik\Downloads\RSITx64.exe
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\EasyShare Registration Task.job => C:\Windows\system32\rundll32.exeZC:\PROGRA~3\Kodak\EasyShareSetup\$REGIS~1\Registration_7.9.30.1.sxt
    Task: C:\Windows\Tasks\RubyBuddy.job => c:\programdata\{5d2e0172-bea4-de59-5d2e-e0172bea05ca}\6870889780498486551b.exe <==== ATTENTION
    Task: C:\Windows\Tasks\SystemReset.job => c:\programdata\{c9458b30-ed1b-8553-c945-58b30ed12cc3}\8954514573165499247b.exe <==== ATTENTION
    c:\programdata\{c9458b30-ed1b-8553-c945-58b30ed12cc3}
    c:\programdata\{5d2e0172-bea4-de59-5d2e-e0172bea05ca}
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zellguras
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 02 srp 2015 17:59

Re: Kontrola logu

#10 Příspěvek od Zellguras »

:arrow: Spustte znovu FRST.exe

Kliknete na Fix
Probehne oprava a vytvori log Fixlog.txt

Mohu se zeptat, nejsme si jistý, mám spusit FRST64 a nebo FRSTlauncher který jsem již jednou spuštěný měl?

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#11 Příspěvek od vyosek »

Spustte FRST64.exe
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zellguras
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 02 srp 2015 17:59

Re: Kontrola logu

#12 Příspěvek od Zellguras »

Hotovo :)

Fix result of Farbar Recovery Scan Tool (x64) Version:09-08-2015
Ran by Dominik (2015-08-10 10:16:50) Run:1
Running from C:\Users\Dominik\Desktop
Loaded Profiles: Dominik (Available Profiles: Dominik)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5579624 2015-08-03] (LogMeIn Inc.)
HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TrayMenu.lnk [2015-01-05]

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=MSSE
URLSearchHook: HKLM-x32 -> Default = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.bing.com/search?q={searchTer ... DF&pc=MSSE
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
DPF: HKLM-x32 {8AD9C840-044E-11D1-B3E9-00805F499D93}
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
DPF: HKLM-x32 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2015-08-07] <==== ATTENTION

CHR Extension: (panda dumpling) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaclfkfmcnlppkambfehbfhlekhpenf [2015-07-23]

S3 EverestDriver; \??\C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\kerneld.amd64 [X]

2015-08-08 13:51 - 2015-08-08 13:51 - 00016550 _____ C:\Users\Dominik\Desktop\FRST.txt
2015-08-08 13:46 - 2015-08-08 13:47 - 00112640 _____ (forum.viry.cz) C:\Users\Dominik\Desktop\FRSTLauncher.exe
2015-08-03 19:02 - 2015-08-03 18:27 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-08-03 18:29 - 2015-08-03 19:05 - 00022681 _____ C:\zoek-results.log
2015-08-03 18:27 - 2015-08-03 18:55 - 00000000 ____D C:\zoek_backup
2015-08-03 18:27 - 2015-08-03 18:27 - 01308672 _____ C:\Users\Dominik\Desktop\zoek.exe
2015-08-03 16:59 - 2015-08-03 17:01 - 00000000 ____D C:\AdwCleaner
2015-08-03 16:58 - 2015-08-03 16:58 - 02248704 _____ C:\Users\Dominik\Desktop\adwcleaner_4.208.exe
2015-08-03 16:13 - 2015-08-03 16:26 - 00000000 ____D C:\Program Files\trend micro
2015-08-03 16:13 - 2015-08-03 16:15 - 00000000 ____D C:\rsit
2015-08-03 16:06 - 2015-08-03 16:06 - 01222144 _____ C:\Users\Dominik\Downloads\RSITx64.exe

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\EasyShare Registration Task.job => C:\Windows\system32\rundll32.exeZC:\PROGRA~3\Kodak\EasyShareSetup\$REGIS~1\Registration_7.9.30.1.sxt
Task: C:\Windows\Tasks\RubyBuddy.job => c:\programdata\{5d2e0172-bea4-de59-5d2e-e0172bea05ca}\6870889780498486551b.exe <==== ATTENTION
Task: C:\Windows\Tasks\SystemReset.job => c:\programdata\{c9458b30-ed1b-8553-c945-58b30ed12cc3}\8954514573165499247b.exe <==== ATTENTION
c:\programdata\{c9458b30-ed1b-8553-c945-58b30ed12cc3}
c:\programdata\{5d2e0172-bea4-de59-5d2e-e0172bea05ca}

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\LogMeIn Hamachi Ui => value removed successfully
HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer => value not found.
HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => value removed successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TrayMenu.lnk => moved successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-1862008024-4103658504-1558178943-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => key removed successfully
HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\eplgTb@eset.com => value removed successfully
C:\Program Files (x86)\mozilla firefox\firefox.cfg => moved successfully.
C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\caaclfkfmcnlppkambfehbfhlekhpenf => moved successfully.
EverestDriver => service removed successfully
C:\Users\Dominik\Desktop\FRST.txt => moved successfully.
"C:\Users\Dominik\Desktop\FRSTLauncher.exe" => File/Folder not found.
C:\Windows\zoek-delete.exe => moved successfully.
C:\zoek-results.log => moved successfully.
C:\zoek_backup => moved successfully.
C:\Users\Dominik\Desktop\zoek.exe => moved successfully.
C:\AdwCleaner => moved successfully.
C:\Users\Dominik\Desktop\adwcleaner_4.208.exe => moved successfully.
C:\Program Files\trend micro => moved successfully.
C:\rsit => moved successfully.
C:\Users\Dominik\Downloads\RSITx64.exe => moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => moved successfully.
C:\Windows\Tasks\EasyShare Registration Task.job => moved successfully.
C:\Windows\Tasks\RubyBuddy.job => moved successfully.
C:\Windows\Tasks\SystemReset.job => moved successfully.
"c:\programdata\{c9458b30-ed1b-8553-c945-58b30ed12cc3}" => File/Folder not found.
"c:\programdata\{5d2e0172-bea4-de59-5d2e-e0172bea05ca}" => File/Folder not found.
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 1.1 GB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 10:18:23 ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#13 Příspěvek od vyosek »

Jak se chova PC??
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zellguras
Návštěvník
Návštěvník
Příspěvky: 9
Registrován: 02 srp 2015 17:59

Re: Kontrola logu

#14 Příspěvek od Zellguras »

Počítač vypadá v pořádku, jede plynule a neseká se. Moc děkuji za pomoc.
Chci se ale ještě zeptat, budu formátovat PC a následně si chci stáhnout Windows 10, mám si teda první nainstalovat W10 a pak formátovat a nebo první formátovat PC a pak nainstalovat W10? :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#15 Příspěvek od vyosek »

Tak proc jsme tu kontrolu delali, kdyz to budete formatovat :roll: :roll:

Ja delal update i bez formatu...ale pokud chcete, tak format a pak instal...nebo format pri instalaci :)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Zamčeno