
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu logu
Hezký den přeji, počítač po spuštění samovolně otevírá firefox, Comodo nic nenalezlo.
Logfile of random's system information tool 1.10 (written by random/random)
Run by Lada at 2015-09-14 12:19:10
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 454 GB (48%) free of 946 GB
Total RAM: 7882 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:19:35, on 14.9.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18015)
Boot mode: Normal
Running processes:
C:\Program Files\daugava\Ejemidvlf.exe
C:\Windows\PixArt\PAC207\Monitor.exe
C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Common Files\Spigot\Preferences Manager\PreferencesManager.exe
C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Lada.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nmd.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll
R3 - URLSearchHook: ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll
O2 - BHO: IB Updater Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ARO 2013 - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll
O2 - BHO: Ads Removal - {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} - C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O3 - Toolbar: ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll
O3 - Toolbar: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Preferences Manager\PreferencesManager.exe"
O4 - HKLM\..\Run: [tvncontrol] "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [AROReminder] C:\Program Files (x86)\ARO 2013\ARO.exe -rem
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [BingSvc] C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe
O4 - Global Startup: SolidWorks 2013 Rychlé spuštění.lnk = ?
O4 - Global Startup: SolidWorks Nástroj pro stahování na pozadí.lnk = ?
O4 - Global Startup: Start GeekBuddy.lnk = C:\Program Files (x86)\Comodo\GeekBuddy\launcher.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 65f825de-0adc-4791-a1e5-209aa6f7ea76 - Unknown owner - C:\Program Files\daugava\Upbgbeie.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
O23 - Service: COMODO LPS Launcher (CLPSLauncher) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: csrcc - Unknown owner - C:\Program Files\daugava\csrcc.exe
O23 - Service: daugava Updater - Unknown owner - C:\Program Files\daugava\Weekfqwb.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Comodo - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GeekBuddyRSP Server (GeekBuddyRSP) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: IB Updater - Unknown owner - C:\Program Files\IB Updater\ExtensionUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Program Manager - Spigot, Inc. - C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Realtek11nSU - Realtek - C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 15280 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\Explorer.EXE
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\daugava\Upbgbeie.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\daugava\Ejemidvlf.exe"
"C:\Program Files\daugava\Ejemidvlf64.exe"
"C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Program Files\daugava\csrcc.exe"
"C:\Program Files\daugava\Weekfqwb.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cistray.exe"
"C:\Windows\PixArt\PAC207\Monitor.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -service
"C:\Program Files\IB Updater\ExtensionUpdaterService.exe"
"C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe"
"C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" -tray
"C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWlan.exe" /H
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe"
C:\Windows\system32\viakaraokesrv.exe
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Common Files\Spigot\Preferences Manager\PreferencesManager.exe"
"C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
"C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe"
"C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe" /launch_from 0
WLIDSvcM.exe 132
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Comodo\GeekBuddy\unit_manager.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d2c835f2-7321-42ae-b1ba-3b28f446fce5 -SystemEventPortName:HostProcess-9c7fe51e-8521-428c-aa4e-8e08a99e0dee -IoCancelEventPortName:HostProcess-c44977a4-b7b6-4cc1-8814-256205f65641 -NonStateChangingEventPortName:HostProcess-320f3525-277d-4c92-be69-4d0eace580fe -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:5b76a5ef-e2e1-497b-9c43-5c117a17bc69 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Comodo\GeekBuddy\unit" "\"C:/Program Files (x86)/Comodo/GeekBuddy/lps-cspm\""
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
{70C75686-92D9-4AB3-A6EC-3BABE970D30E}
{6AC7B42A-3DEC-42E0-988B-CBACCEFE9788}
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --mainUI
"C:\Program Files\COMODO\COMODO Internet Security\CIS.exe" --scanUI {A3FB5B2D-11F3-4613-986F-7D9BF6FE9312}
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvScanner -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --on-initialized-event-handle=28 --parent-handle=688
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1864.0.1431421357\402318655" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x0102 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.2696 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="1864.4.134853704\1098639912" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/*IntelligentSessionRestore/Disabled/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Disabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="1864.5.957980465\1407099812" --font-cache-shared-handle=4232 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/*IntelligentSessionRestore/Disabled/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Disabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="1864.6.1869816394\1042863014" --font-cache-shared-handle=3788 /prefetch:673131151
taskeng.exe {10471228-4004-41BE-80C3-AF5BDF400EA9}
C:\Windows\system32\sppsvc.exe
"C:\Users\Lada\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "keyword.URL" - "https://search.yahoo.com/search?fr=gree ... =198484&p="
"{336D0C35-8A85-403a-B9D2-65C292C39087}"=C:\Program Files\IB Updater\Firefox
"{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}"=C:\Program Files\IB Updater\Firefox
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\extensions\
adremoveext@adremoveext.net
bingsearch.full@microsoft.com
{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93}
{92e7bc9c-bc36-42d4-9013-65e387115066}
C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\
ask-web-search.xml
bingp.xml
conduit.xml
MyStart Search.xml
yahoo.xml
yahoo_ff.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
IB Updater - C:\Program Files\IB Updater\Extension64.dll [2013-01-29 215896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01 2133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-12 1154720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
IObit Apps Toolbar - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll [2015-08-11 1528432]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
IB Updater - C:\Program Files\IB Updater\Extension32.dll [2013-01-29 170840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-27 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92e7bc9c-bc36-42d4-9013-65e387115066}]
ARO 2013 Toolbar - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll [2013-07-17 226592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}]
Ads Removal - C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll [2014-06-11 464720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01 1724032]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-12 1431712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-27 172968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-12 1154720]
{03EB0E9C-7A91-4381-A220-9B52B641CDB1} - IObit Apps Toolbar - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE64.dll [2015-08-11 2242672]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{92e7bc9c-bc36-42d4-9013-65e387115066} - ARO 2013 Toolbar - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll [2013-07-17 226592]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-12 1431712]
{03EB0E9C-7A91-4381-A220-9B52B641CDB1} - IObit Apps Toolbar - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll [2015-08-11 1528432]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-03-19 170264]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-03-19 398616]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-03-19 439064]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-08-09 1427648]
"PAC207_Monitor"=C:\Windows\PixArt\PAC207\Monitor.exe [2007-12-10 323584]
"daugava"=C:\Program Files\daugava\Ejemidvlf.exe [2015-07-22 432288]
"daugava64"=C:\Program Files\daugava\Ejemidvlf64.exe [2015-07-22 463520]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-01-08 3674320]
"AROReminder"=C:\Program Files (x86)\ARO 2013\ARO.exe [2013-07-03 3157336]
"Sony PC Companion"=C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2015-07-24 457088]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-09-10 8455960]
"BingSvc"=C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe [2015-05-11 144008]
""= []
"NokiaSuite.exe"=C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2015-05-20 1092448]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-08-07 53735968]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-01-12 5028464]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
""= []
"SearchSettings"=C:\Program Files (x86)\Common Files\Spigot\Preferences Manager\PreferencesManager.exe [2015-08-17 1366640]
"tvncontrol"=C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2015-08-22 2327248]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe
SolidWorks 2013 Rychlé spuštění.lnk - C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SolidWorks Nástroj pro stahování na pozadí.lnk - C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
Start GeekBuddy.lnk - C:\Program Files (x86)\Comodo\GeekBuddy\launcher.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-03-19 434688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-09-14 12:19:14 ----D---- C:\Program Files\trend micro
2015-09-14 12:19:10 ----D---- C:\rsit
2015-09-09 17:26:39 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-09-09 17:26:39 ----A---- C:\Windows\system32\schedsvc.dll
2015-09-09 17:26:39 ----A---- C:\Windows\system32\jnwmon.dll
2015-09-09 17:26:39 ----A---- C:\Windows\system32\InkEd.dll
2015-09-09 17:26:37 ----A---- C:\Windows\SYSWOW64\tzres.dll
2015-09-09 17:26:37 ----A---- C:\Windows\system32\tzres.dll
2015-09-09 17:26:35 ----A---- C:\Windows\system32\dwmcore.dll
2015-09-09 17:26:34 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-09-09 17:26:34 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-09-09 17:26:34 ----A---- C:\Windows\system32\dwmapi.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-09-09 17:26:33 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-09-09 17:26:33 ----A---- C:\Windows\system32\iernonce.dll
2015-09-09 17:26:33 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-09-09 17:26:33 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-09-09 17:26:33 ----A---- C:\Windows\system32\ie4uinit.exe
2015-09-09 17:26:32 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-09-09 17:26:32 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-09-09 17:26:32 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-09-09 17:26:32 ----A---- C:\Windows\system32\urlmon.dll
2015-09-09 17:26:32 ----A---- C:\Windows\system32\iedkcs32.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-09-09 17:26:31 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-09-09 17:26:31 ----A---- C:\Windows\system32\msfeeds.dll
2015-09-09 17:26:31 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-09-09 17:26:31 ----A---- C:\Windows\system32\dxtrans.dll
2015-09-09 17:26:30 ----A---- C:\Windows\system32\iesetup.dll
2015-09-09 17:26:30 ----A---- C:\Windows\system32\iertutil.dll
2015-09-09 17:26:30 ----A---- C:\Windows\system32\ieapfltr.dll
2015-09-09 17:26:29 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-09-09 17:26:29 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-09-09 17:26:29 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-09-09 17:26:29 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-09-09 17:26:29 ----A---- C:\Windows\system32\vbscript.dll
2015-09-09 17:26:29 ----A---- C:\Windows\system32\jsproxy.dll
2015-09-09 17:26:29 ----A---- C:\Windows\system32\ieUnatt.exe
2015-09-09 17:26:28 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\mshtmled.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\jscript.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\ieui.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\ieframe.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\dxtmsft.dll
2015-09-09 17:26:27 ----A---- C:\Windows\system32\wininet.dll
2015-09-09 17:26:27 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-09-09 17:26:27 ----A---- C:\Windows\system32\jscript9diag.dll
2015-09-09 17:26:27 ----A---- C:\Windows\system32\jscript9.dll
2015-09-09 17:26:26 ----A---- C:\Windows\system32\msrating.dll
2015-09-09 17:26:26 ----A---- C:\Windows\system32\mshtml.dll
2015-09-09 17:26:19 ----A---- C:\Windows\system32\UtcResources.dll
2015-09-09 17:26:19 ----A---- C:\Windows\system32\diagtrack.dll
2015-09-09 17:26:18 ----A---- C:\Windows\system32\tdh.dll
2015-09-09 17:26:18 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-09-09 17:26:18 ----A---- C:\Windows\system32\ntdll.dll
2015-09-09 17:26:18 ----A---- C:\Windows\system32\kernel32.dll
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\wow64.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\rstrui.exe
2015-09-09 17:26:17 ----A---- C:\Windows\system32\rpcrt4.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\lsasrv.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\KernelBase.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\advapi32.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-09-09 17:26:16 ----A---- C:\Windows\system32\winsrv.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\wdigest.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\TSpkg.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\sspicli.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\srcore.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\srclient.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\smss.exe
2015-09-09 17:26:16 ----A---- C:\Windows\system32\schannel.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\secur32.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\ntvdm64.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\ncrypt.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\msv1_0.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\lsass.exe
2015-09-09 17:26:16 ----A---- C:\Windows\system32\kerberos.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-09-09 17:26:16 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-09-09 17:26:16 ----A---- C:\Windows\system32\csrsrv.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\cryptbase.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\conhost.exe
2015-09-09 17:26:16 ----A---- C:\Windows\system32\auditpol.exe
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\wow64win.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\wow64cpu.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\sspisrv.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-09-09 17:26:15 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-09-09 17:26:15 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-09-09 17:26:15 ----A---- C:\Windows\system32\credssp.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\apisetschema.dll
2015-09-09 17:26:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-09-09 17:26:14 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-09-09 17:26:14 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-09-09 17:26:14 ----A---- C:\Windows\SYSWOW64\user.exe
2015-09-09 17:26:14 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-09-09 17:26:14 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-09-09 17:26:14 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-09-09 17:26:14 ----A---- C:\Windows\system32\msobjs.dll
2015-09-09 17:26:14 ----A---- C:\Windows\system32\msaudite.dll
2015-09-09 17:26:14 ----A---- C:\Windows\system32\adtschema.dll
2015-09-09 17:25:57 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-09-09 17:25:57 ----A---- C:\Windows\system32\consent.exe
2015-09-09 17:25:57 ----A---- C:\Windows\system32\authui.dll
2015-09-09 17:25:57 ----A---- C:\Windows\system32\appinfo.dll
2015-09-09 17:25:55 ----A---- C:\Windows\system32\msxml6.dll
2015-09-09 17:25:55 ----A---- C:\Windows\system32\msxml3.dll
2015-09-09 17:25:54 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-09-09 17:25:54 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-09-09 17:25:53 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-09-09 17:25:53 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-09-09 17:25:53 ----A---- C:\Windows\system32\msxml6r.dll
2015-09-09 17:25:53 ----A---- C:\Windows\system32\msxml3r.dll
2015-09-09 17:25:45 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-09-09 17:25:45 ----A---- C:\Windows\system32\appidsvc.dll
2015-09-09 17:25:45 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-09-09 17:25:45 ----A---- C:\Windows\system32\appidapi.dll
2015-09-09 17:25:44 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-09-09 17:25:44 ----A---- C:\Windows\system32\drivers\appid.sys
2015-09-09 17:25:44 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-09-09 17:25:35 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-09-09 17:25:35 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-09-09 17:25:35 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-09-09 17:25:35 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\win32k.sys
2015-09-09 17:25:35 ----A---- C:\Windows\system32\lpk.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\fontsub.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\dciman32.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\atmlib.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\atmfd.dll
2015-09-09 17:25:34 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-09-09 17:25:24 ----A---- C:\Windows\system32\wuaueng.dll
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wuwebv.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wups2.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wups.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wudriver.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wucltux.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wuauclt.exe
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wuapp.exe
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wuapi.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-09-05 15:24:38 ----D---- C:\Program Files\McAfee Security Scan
2015-08-30 21:16:45 ----D---- C:\Program Files (x86)\GUM5EB0.tmp
2015-08-30 21:16:45 ----A---- C:\Program Files (x86)\GUT5EB1.tmp
2015-08-30 09:29:22 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-17 20:27:36 ----D---- C:\Program Files (x86)\Application Updater
2015-08-17 20:27:35 ----D---- C:\Program Files (x86)\IObit Apps Toolbar
======List of files/folders modified in the last 1 month======
2015-09-14 12:19:14 ----RD---- C:\Program Files
2015-09-14 12:07:30 ----D---- C:\Windows\Temp
2015-09-14 11:31:47 ----D---- C:\Windows\system32\config
2015-09-14 11:27:33 ----D---- C:\Windows
2015-09-13 13:44:27 ----D---- C:\Windows\Prefetch
2015-09-13 13:40:37 ----D---- C:\Users\Lada\AppData\Roaming\Skype
2015-09-10 08:19:42 ----D---- C:\Windows\Microsoft.NET
2015-09-10 08:12:07 ----RSD---- C:\Windows\assembly
2015-09-10 07:32:20 ----D---- C:\Program Files\CCleaner
2015-09-10 07:27:03 ----D---- C:\Windows\System32
2015-09-10 07:27:03 ----D---- C:\Windows\inf
2015-09-10 07:27:03 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-09-10 07:25:44 ----D---- C:\Windows\SoftwareDistribution
2015-09-10 07:25:29 ----D---- C:\Windows\debug
2015-09-10 07:21:14 ----D---- C:\Windows\winsxs
2015-09-10 07:18:58 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-09-10 07:18:58 ----D---- C:\Windows\SysWOW64
2015-09-10 07:18:58 ----D---- C:\Windows\system32\cs-CZ
2015-09-10 07:18:58 ----D---- C:\Windows\ehome
2015-09-10 07:18:58 ----D---- C:\Program Files\Windows Journal
2015-09-10 07:18:57 ----D---- C:\Windows\SYSWOW64\en-US
2015-09-10 07:18:57 ----D---- C:\Windows\system32\en-US
2015-09-10 07:18:57 ----D---- C:\Windows\PolicyDefinitions
2015-09-10 07:18:57 ----D---- C:\Program Files\Internet Explorer
2015-09-10 07:18:56 ----D---- C:\Program Files (x86)\Internet Explorer
2015-09-10 07:18:51 ----D---- C:\Windows\system32\drivers
2015-09-10 07:18:51 ----D---- C:\Windows\AppPatch
2015-09-10 07:18:47 ----D---- C:\Windows\system32\Boot
2015-09-09 22:47:00 ----SHD---- C:\Windows\Installer
2015-09-09 22:47:00 ----SHD---- C:\Config.Msi
2015-09-09 22:46:57 ----D---- C:\ProgramData\Microsoft Help
2015-09-09 22:45:41 ----D---- C:\Windows\system32\MRT
2015-09-09 22:36:15 ----SHD---- C:\System Volume Information
2015-09-09 22:34:37 ----A---- C:\Windows\win.ini
2015-09-09 18:33:37 ----HD---- C:\ProgramData
2015-09-09 17:24:00 ----D---- C:\Windows\system32\catroot2
2015-09-05 16:25:24 ----D---- C:\Users\Lada\AppData\Roaming\SolidWorks
2015-09-05 15:24:38 ----D---- C:\Windows\system32\drivers\etc
2015-09-03 13:52:03 ----A---- C:\Windows\SYSWOW64\guard32.dll
2015-09-03 13:52:00 ----A---- C:\Windows\system32\guard64.dll
2015-09-01 15:48:18 ----D---- C:\Users\Lada\AppData\Roaming\vlc
2015-09-01 15:03:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-31 19:55:00 ----RD---- C:\Program Files (x86)
2015-08-31 19:54:57 ----D---- C:\Windows\Tasks
2015-08-26 18:37:02 ----A---- C:\Windows\system32\MRT.exe
2015-08-22 08:50:34 ----D---- C:\Program Files (x86)\Common Files
2015-08-21 20:45:44 ----RD---- C:\Program Files (x86)\Skype
2015-08-21 20:45:35 ----D---- C:\ProgramData\Skype
2015-08-21 18:36:09 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-08-17 20:27:46 ----D---- C:\Windows\system32\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2012-02-01 568600]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2015-08-05 21184]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2015-08-05 806032]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2015-08-05 45856]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-01-11 283200]
R1 cherimoya;cherimoya; C:\Windows\system32\drivers\cherimoya.sys [2015-06-18 61336]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2015-08-05 105096]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 66304]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-09-23 359552]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-03-19 14745600]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-02 62784]
R3 PAC207;Eye 110; C:\Windows\system32\DRIVERS\PFC027.SYS [2009-06-25 686592]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2012-01-10 2184816]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 187904]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 95232]
S1 CFRMD;CFRMD; C:\Windows\system32\DRIVERS\CFRMD.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2014-01-04 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2014-01-04 27760]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2013-01-23 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2013-01-23 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys [2009-11-12 676864]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2012-08-23 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]
S3 WinUsb;Sony so0103 ADB Interface; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 65f825de-0adc-4791-a1e5-209aa6f7ea76;65f825de-0adc-4791-a1e5-209aa6f7ea76; C:\Program Files\daugava\Upbgbeie.exe [2015-07-22 284320]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-17 82128]
R2 Application Updater;Application Updater; C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe [2015-08-17 946352]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-08-21 1394816]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-08-21 1772672]
R2 CLPSLauncher;COMODO LPS Launcher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [2015-08-22 70848]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2015-09-09 5542472]
R2 csrcc;csrcc; C:\Program Files\daugava\csrcc.exe [2015-07-22 1447584]
R2 daugava Updater;daugava Updater; C:\Program Files\daugava\Weekfqwb.exe [2015-07-22 173216]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DragonUpdater;COMODO Dragon Update Service; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2015-06-27 1994936]
R2 GeekBuddyRSP;GeekBuddyRSP Server; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2015-08-22 2327248]
R2 IB Updater;IB Updater; C:\Program Files\IB Updater\ExtensionUpdaterService.exe [2013-01-29 188760]
R2 Realtek11nSU;Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [2009-12-07 40960]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2012-01-10 27760]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe [2014-03-12 247968]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S2 BBSvc;BingBar Service; C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.exe [2014-03-12 193696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2015-08-09 2265792]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2012-09-28 76904]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2012-03-19 276248]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-02-13 1431888]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2013-02-13 1044816]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-09-09 114688]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [2015-09-05 289256]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-30 149160]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Program Manager;Program Manager; C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe [2015-08-15 951448]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2013-02-13 79360]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2015-06-10 155520]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-09 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Lada at 2015-09-14 12:19:10
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 454 GB (48%) free of 946 GB
Total RAM: 7882 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:19:35, on 14.9.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18015)
Boot mode: Normal
Running processes:
C:\Program Files\daugava\Ejemidvlf.exe
C:\Windows\PixArt\PAC207\Monitor.exe
C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe
C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Common Files\Spigot\Preferences Manager\PreferencesManager.exe
C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Lada.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nmd.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll
R3 - URLSearchHook: ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 0.0.0.1 mssplus.mcafee.com
O2 - BHO: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll
O2 - BHO: IB Updater Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension32.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ARO 2013 - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll
O2 - BHO: Ads Removal - {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} - C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
O3 - Toolbar: ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll
O3 - Toolbar: IObit Apps Toolbar - {03EB0E9C-7A91-4381-A220-9B52B641CDB1} - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Preferences Manager\PreferencesManager.exe"
O4 - HKLM\..\Run: [tvncontrol] "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [AROReminder] C:\Program Files (x86)\ARO 2013\ARO.exe -rem
O4 - HKCU\..\Run: [Sony PC Companion] "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [BingSvc] C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe
O4 - HKCU\..\Run: [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Advanced SystemCare 7] "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe
O4 - Global Startup: SolidWorks 2013 Rychlé spuštění.lnk = ?
O4 - Global Startup: SolidWorks Nástroj pro stahování na pozadí.lnk = ?
O4 - Global Startup: Start GeekBuddy.lnk = C:\Program Files (x86)\Comodo\GeekBuddy\launcher.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: 65f825de-0adc-4791-a1e5-209aa6f7ea76 - Unknown owner - C:\Program Files\daugava\Upbgbeie.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
O23 - Service: COMODO LPS Launcher (CLPSLauncher) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: csrcc - Unknown owner - C:\Program Files\daugava\csrcc.exe
O23 - Service: daugava Updater - Unknown owner - C:\Program Files\daugava\Weekfqwb.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Comodo - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GeekBuddyRSP Server (GeekBuddyRSP) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: IB Updater - Unknown owner - C:\Program Files\IB Updater\ExtensionUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Program Manager - Spigot, Inc. - C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Realtek11nSU - Realtek - C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Sony PC Companion - Avanquest Software - C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 15280 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
"C:\Windows\system32\Dwm.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\Explorer.EXE
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\daugava\Upbgbeie.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\daugava\Ejemidvlf.exe"
"C:\Program Files\daugava\Ejemidvlf64.exe"
"C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"C:\Program Files\daugava\csrcc.exe"
"C:\Program Files\daugava\Weekfqwb.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cistray.exe"
"C:\Windows\PixArt\PAC207\Monitor.exe"
"C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -service
"C:\Program Files\IB Updater\ExtensionUpdaterService.exe"
"C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe"
"C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe" -tray
"C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWlan.exe" /H
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe"
C:\Windows\system32\viakaraokesrv.exe
"C:\Windows\system32\GWX\GWX.exe"
"C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Common Files\Spigot\Preferences Manager\PreferencesManager.exe"
"C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
"C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe"
"C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe" /launch_from 0
WLIDSvcM.exe 132
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Comodo\GeekBuddy\unit_manager.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d2c835f2-7321-42ae-b1ba-3b28f446fce5 -SystemEventPortName:HostProcess-9c7fe51e-8521-428c-aa4e-8e08a99e0dee -IoCancelEventPortName:HostProcess-c44977a4-b7b6-4cc1-8814-256205f65641 -NonStateChangingEventPortName:HostProcess-320f3525-277d-4c92-be69-4d0eace580fe -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:5b76a5ef-e2e1-497b-9c43-5c117a17bc69 -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Comodo\GeekBuddy\unit" "\"C:/Program Files (x86)/Comodo/GeekBuddy/lps-cspm\""
"C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe"
{70C75686-92D9-4AB3-A6EC-3BABE970D30E}
{6AC7B42A-3DEC-42E0-988B-CBACCEFE9788}
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --mainUI
"C:\Program Files\COMODO\COMODO Internet Security\CIS.exe" --scanUI {A3FB5B2D-11F3-4613-986F-7D9BF6FE9312}
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvScanner -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --on-initialized-event-handle=28 --parent-handle=688
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="1864.0.1431421357\402318655" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=2,8,20,45 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x0102 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.2696 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="1864.4.134853704\1098639912" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/*IntelligentSessionRestore/Disabled/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Disabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="1864.5.957980465\1407099812" --font-cache-shared-handle=4232 /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="AffiliationBasedMatching/Enabled/AudioProcessing48kHzSupport/Default/AutofillEnabled/Default/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Default/*ClientSideDetectionModel/Model0/*DomRel-Enable/enable/*EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Disabled/*EnhancedBookmarks/Default/*ExtensionContentVerification/Enforce/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GoogleNow/Enable/*IconNTP/Default/InstanceID/Enabled/*IntelligentSessionRestore/Disabled/*NetworkQualityEstimator/Enabled/*NewProfileManagement/Enabled/NewVideoRendererTrial/Enabled/*OmniboxBundledExperimentV1/Unused_1/*PasswordGeneration/Disabled/PasswordLinkInSettings/Enabled/*PluginPowerSaver/Disabled/*PrerenderFromOmnibox/OmniboxPrerenderEnabled/*QUIC/EnabledNoIdForLargePopulation/RefreshTokenDeviceId/Enabled/RememberCertificateErrorDecisions/Default/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingSocialEngineeringStrings/Enabled/*SdchPersistence/Default/SessionRestoreBackgroundLoading/Restore/*SettingsEnforcement/enforce_always_with_extensions_and_dse/*SlimmingPaint/EnableSlimmingPaint/SyncBackingDatabase32K/Enabled/*UMA-Dynamic-Binary-Uniformity-Trial/default/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/default/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/default/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/VoiceTrigger/Install/WebRTC-UDPSocketNonBlockingIO/Default/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=1 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --channel="1864.6.1869816394\1042863014" --font-cache-shared-handle=3788 /prefetch:673131151
taskeng.exe {10471228-4004-41BE-80C3-AF5BDF400EA9}
C:\Windows\system32\sppsvc.exe
"C:\Users\Lada\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
=========Mozilla firefox=========
ProfilePath - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"
prefs.js - "keyword.URL" - "https://search.yahoo.com/search?fr=gree ... =198484&p="
"{336D0C35-8A85-403a-B9D2-65C292C39087}"=C:\Program Files\IB Updater\Firefox
"{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}"=C:\Program Files\IB Updater\Firefox
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.31.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nokia.com/EnablerPlugin]
"Description"=Nokia Suite Enabler Plugin
"Path"=C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\extensions\
adremoveext@adremoveext.net
bingsearch.full@microsoft.com
{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93}
{92e7bc9c-bc36-42d4-9013-65e387115066}
C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\
ask-web-search.xml
bingp.xml
conduit.xml
MyStart Search.xml
yahoo.xml
yahoo_ff.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
IB Updater - C:\Program Files\IB Updater\Extension64.dll [2013-01-29 215896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01 2133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-12 1154720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}]
IObit Apps Toolbar - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll [2015-08-11 1528432]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
IB Updater - C:\Program Files\IB Updater\Extension32.dll [2013-01-29 170840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-27 460712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92e7bc9c-bc36-42d4-9013-65e387115066}]
ARO 2013 Toolbar - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll [2013-07-17 226592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}]
Ads Removal - C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll [2014-06-11 464720]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01 1724032]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-12 1431712]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-27 172968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll [2014-03-12 1154720]
{03EB0E9C-7A91-4381-A220-9B52B641CDB1} - IObit Apps Toolbar - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE64.dll [2015-08-11 2242672]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{92e7bc9c-bc36-42d4-9013-65e387115066} - ARO 2013 Toolbar - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll [2013-07-17 226592]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll [2014-03-12 1431712]
{03EB0E9C-7A91-4381-A220-9B52B641CDB1} - IObit Apps Toolbar - C:\Program Files (x86)\IObit Apps Toolbar\IE\22.1\iobitappsToolbarIE.dll [2015-08-11 1528432]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2012-03-19 170264]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2012-03-19 398616]
"Persistence"=C:\Windows\system32\igfxpers.exe [2012-03-19 439064]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-08-09 1427648]
"PAC207_Monitor"=C:\Windows\PixArt\PAC207\Monitor.exe [2007-12-10 323584]
"daugava"=C:\Program Files\daugava\Ejemidvlf.exe [2015-07-22 432288]
"daugava64"=C:\Program Files\daugava\Ejemidvlf64.exe [2015-07-22 463520]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-01-08 3674320]
"AROReminder"=C:\Program Files (x86)\ARO 2013\ARO.exe [2013-07-03 3157336]
"Sony PC Companion"=C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [2015-07-24 457088]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-09-10 8455960]
"BingSvc"=C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe [2015-05-11 144008]
""= []
"NokiaSuite.exe"=C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [2015-05-20 1092448]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-08-07 53735968]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2012-01-12 5028464]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2012-11-05 89184]
""= []
"SearchSettings"=C:\Program Files (x86)\Common Files\Spigot\Preferences Manager\PreferencesManager.exe [2015-08-17 1366640]
"tvncontrol"=C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2015-08-22 2327248]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\3.11.163\SSScheduler.exe
SolidWorks 2013 Rychlé spuštění.lnk - C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
SolidWorks Nástroj pro stahování na pozadí.lnk - C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
Start GeekBuddy.lnk - C:\Program Files (x86)\Comodo\GeekBuddy\launcher.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2012-03-19 434688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-09-14 12:19:14 ----D---- C:\Program Files\trend micro
2015-09-14 12:19:10 ----D---- C:\rsit
2015-09-09 17:26:39 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-09-09 17:26:39 ----A---- C:\Windows\system32\schedsvc.dll
2015-09-09 17:26:39 ----A---- C:\Windows\system32\jnwmon.dll
2015-09-09 17:26:39 ----A---- C:\Windows\system32\InkEd.dll
2015-09-09 17:26:37 ----A---- C:\Windows\SYSWOW64\tzres.dll
2015-09-09 17:26:37 ----A---- C:\Windows\system32\tzres.dll
2015-09-09 17:26:35 ----A---- C:\Windows\system32\dwmcore.dll
2015-09-09 17:26:34 ----A---- C:\Windows\SYSWOW64\dwmcore.dll
2015-09-09 17:26:34 ----A---- C:\Windows\SYSWOW64\dwmapi.dll
2015-09-09 17:26:34 ----A---- C:\Windows\system32\dwmapi.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-09-09 17:26:33 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-09-09 17:26:33 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-09-09 17:26:33 ----A---- C:\Windows\system32\iernonce.dll
2015-09-09 17:26:33 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-09-09 17:26:33 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-09-09 17:26:33 ----A---- C:\Windows\system32\ie4uinit.exe
2015-09-09 17:26:32 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-09-09 17:26:32 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-09-09 17:26:32 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-09-09 17:26:32 ----A---- C:\Windows\system32\urlmon.dll
2015-09-09 17:26:32 ----A---- C:\Windows\system32\iedkcs32.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-09-09 17:26:31 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-09-09 17:26:31 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-09-09 17:26:31 ----A---- C:\Windows\system32\msfeeds.dll
2015-09-09 17:26:31 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-09-09 17:26:31 ----A---- C:\Windows\system32\dxtrans.dll
2015-09-09 17:26:30 ----A---- C:\Windows\system32\iesetup.dll
2015-09-09 17:26:30 ----A---- C:\Windows\system32\iertutil.dll
2015-09-09 17:26:30 ----A---- C:\Windows\system32\ieapfltr.dll
2015-09-09 17:26:29 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-09-09 17:26:29 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-09-09 17:26:29 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-09-09 17:26:29 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-09-09 17:26:29 ----A---- C:\Windows\system32\vbscript.dll
2015-09-09 17:26:29 ----A---- C:\Windows\system32\jsproxy.dll
2015-09-09 17:26:29 ----A---- C:\Windows\system32\ieUnatt.exe
2015-09-09 17:26:28 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\mshtmled.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\jscript.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\ieui.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\ieframe.dll
2015-09-09 17:26:28 ----A---- C:\Windows\system32\dxtmsft.dll
2015-09-09 17:26:27 ----A---- C:\Windows\system32\wininet.dll
2015-09-09 17:26:27 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-09-09 17:26:27 ----A---- C:\Windows\system32\jscript9diag.dll
2015-09-09 17:26:27 ----A---- C:\Windows\system32\jscript9.dll
2015-09-09 17:26:26 ----A---- C:\Windows\system32\msrating.dll
2015-09-09 17:26:26 ----A---- C:\Windows\system32\mshtml.dll
2015-09-09 17:26:19 ----A---- C:\Windows\system32\UtcResources.dll
2015-09-09 17:26:19 ----A---- C:\Windows\system32\diagtrack.dll
2015-09-09 17:26:18 ----A---- C:\Windows\system32\tdh.dll
2015-09-09 17:26:18 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-09-09 17:26:18 ----A---- C:\Windows\system32\ntdll.dll
2015-09-09 17:26:18 ----A---- C:\Windows\system32\kernel32.dll
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\tdh.dll
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-09-09 17:26:17 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\wow64.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\rstrui.exe
2015-09-09 17:26:17 ----A---- C:\Windows\system32\rpcrt4.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\lsasrv.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\KernelBase.dll
2015-09-09 17:26:17 ----A---- C:\Windows\system32\advapi32.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-09-09 17:26:16 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-09-09 17:26:16 ----A---- C:\Windows\system32\winsrv.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\wdigest.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\TSpkg.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\sspicli.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\srcore.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\srclient.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\smss.exe
2015-09-09 17:26:16 ----A---- C:\Windows\system32\schannel.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\secur32.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\ntvdm64.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\ncrypt.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\msv1_0.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\lsass.exe
2015-09-09 17:26:16 ----A---- C:\Windows\system32\kerberos.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-09-09 17:26:16 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-09-09 17:26:16 ----A---- C:\Windows\system32\csrsrv.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\cryptbase.dll
2015-09-09 17:26:16 ----A---- C:\Windows\system32\conhost.exe
2015-09-09 17:26:16 ----A---- C:\Windows\system32\auditpol.exe
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-09-09 17:26:15 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-09-09 17:26:15 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\wow64win.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\wow64cpu.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\sspisrv.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-09-09 17:26:15 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-09-09 17:26:15 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-09-09 17:26:15 ----A---- C:\Windows\system32\credssp.dll
2015-09-09 17:26:15 ----A---- C:\Windows\system32\apisetschema.dll
2015-09-09 17:26:14 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-09-09 17:26:14 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-09-09 17:26:14 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-09-09 17:26:14 ----A---- C:\Windows\SYSWOW64\user.exe
2015-09-09 17:26:14 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-09-09 17:26:14 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-09-09 17:26:14 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-09-09 17:26:14 ----A---- C:\Windows\system32\msobjs.dll
2015-09-09 17:26:14 ----A---- C:\Windows\system32\msaudite.dll
2015-09-09 17:26:14 ----A---- C:\Windows\system32\adtschema.dll
2015-09-09 17:25:57 ----A---- C:\Windows\SYSWOW64\authui.dll
2015-09-09 17:25:57 ----A---- C:\Windows\system32\consent.exe
2015-09-09 17:25:57 ----A---- C:\Windows\system32\authui.dll
2015-09-09 17:25:57 ----A---- C:\Windows\system32\appinfo.dll
2015-09-09 17:25:55 ----A---- C:\Windows\system32\msxml6.dll
2015-09-09 17:25:55 ----A---- C:\Windows\system32\msxml3.dll
2015-09-09 17:25:54 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2015-09-09 17:25:54 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2015-09-09 17:25:53 ----A---- C:\Windows\SYSWOW64\msxml6r.dll
2015-09-09 17:25:53 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2015-09-09 17:25:53 ----A---- C:\Windows\system32\msxml6r.dll
2015-09-09 17:25:53 ----A---- C:\Windows\system32\msxml3r.dll
2015-09-09 17:25:45 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-09-09 17:25:45 ----A---- C:\Windows\system32\appidsvc.dll
2015-09-09 17:25:45 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-09-09 17:25:45 ----A---- C:\Windows\system32\appidapi.dll
2015-09-09 17:25:44 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-09-09 17:25:44 ----A---- C:\Windows\system32\drivers\appid.sys
2015-09-09 17:25:44 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-09-09 17:25:35 ----A---- C:\Windows\SYSWOW64\fontsub.dll
2015-09-09 17:25:35 ----A---- C:\Windows\SYSWOW64\dciman32.dll
2015-09-09 17:25:35 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2015-09-09 17:25:35 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\win32k.sys
2015-09-09 17:25:35 ----A---- C:\Windows\system32\lpk.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\fontsub.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\dciman32.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\atmlib.dll
2015-09-09 17:25:35 ----A---- C:\Windows\system32\atmfd.dll
2015-09-09 17:25:34 ----A---- C:\Windows\SYSWOW64\lpk.dll
2015-09-09 17:25:24 ----A---- C:\Windows\system32\wuaueng.dll
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-09-09 17:25:23 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wuwebv.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wups2.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wups.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wudriver.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wucltux.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wuauclt.exe
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wuapp.exe
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wuapi.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-09-09 17:25:23 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-09-05 15:24:38 ----D---- C:\Program Files\McAfee Security Scan
2015-08-30 21:16:45 ----D---- C:\Program Files (x86)\GUM5EB0.tmp
2015-08-30 21:16:45 ----A---- C:\Program Files (x86)\GUT5EB1.tmp
2015-08-30 09:29:22 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-08-17 20:27:36 ----D---- C:\Program Files (x86)\Application Updater
2015-08-17 20:27:35 ----D---- C:\Program Files (x86)\IObit Apps Toolbar
======List of files/folders modified in the last 1 month======
2015-09-14 12:19:14 ----RD---- C:\Program Files
2015-09-14 12:07:30 ----D---- C:\Windows\Temp
2015-09-14 11:31:47 ----D---- C:\Windows\system32\config
2015-09-14 11:27:33 ----D---- C:\Windows
2015-09-13 13:44:27 ----D---- C:\Windows\Prefetch
2015-09-13 13:40:37 ----D---- C:\Users\Lada\AppData\Roaming\Skype
2015-09-10 08:19:42 ----D---- C:\Windows\Microsoft.NET
2015-09-10 08:12:07 ----RSD---- C:\Windows\assembly
2015-09-10 07:32:20 ----D---- C:\Program Files\CCleaner
2015-09-10 07:27:03 ----D---- C:\Windows\System32
2015-09-10 07:27:03 ----D---- C:\Windows\inf
2015-09-10 07:27:03 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-09-10 07:25:44 ----D---- C:\Windows\SoftwareDistribution
2015-09-10 07:25:29 ----D---- C:\Windows\debug
2015-09-10 07:21:14 ----D---- C:\Windows\winsxs
2015-09-10 07:18:58 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-09-10 07:18:58 ----D---- C:\Windows\SysWOW64
2015-09-10 07:18:58 ----D---- C:\Windows\system32\cs-CZ
2015-09-10 07:18:58 ----D---- C:\Windows\ehome
2015-09-10 07:18:58 ----D---- C:\Program Files\Windows Journal
2015-09-10 07:18:57 ----D---- C:\Windows\SYSWOW64\en-US
2015-09-10 07:18:57 ----D---- C:\Windows\system32\en-US
2015-09-10 07:18:57 ----D---- C:\Windows\PolicyDefinitions
2015-09-10 07:18:57 ----D---- C:\Program Files\Internet Explorer
2015-09-10 07:18:56 ----D---- C:\Program Files (x86)\Internet Explorer
2015-09-10 07:18:51 ----D---- C:\Windows\system32\drivers
2015-09-10 07:18:51 ----D---- C:\Windows\AppPatch
2015-09-10 07:18:47 ----D---- C:\Windows\system32\Boot
2015-09-09 22:47:00 ----SHD---- C:\Windows\Installer
2015-09-09 22:47:00 ----SHD---- C:\Config.Msi
2015-09-09 22:46:57 ----D---- C:\ProgramData\Microsoft Help
2015-09-09 22:45:41 ----D---- C:\Windows\system32\MRT
2015-09-09 22:36:15 ----SHD---- C:\System Volume Information
2015-09-09 22:34:37 ----A---- C:\Windows\win.ini
2015-09-09 18:33:37 ----HD---- C:\ProgramData
2015-09-09 17:24:00 ----D---- C:\Windows\system32\catroot2
2015-09-05 16:25:24 ----D---- C:\Users\Lada\AppData\Roaming\SolidWorks
2015-09-05 15:24:38 ----D---- C:\Windows\system32\drivers\etc
2015-09-03 13:52:03 ----A---- C:\Windows\SYSWOW64\guard32.dll
2015-09-03 13:52:00 ----A---- C:\Windows\system32\guard64.dll
2015-09-01 15:48:18 ----D---- C:\Users\Lada\AppData\Roaming\vlc
2015-09-01 15:03:02 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-31 19:55:00 ----RD---- C:\Program Files (x86)
2015-08-31 19:54:57 ----D---- C:\Windows\Tasks
2015-08-26 18:37:02 ----A---- C:\Windows\system32\MRT.exe
2015-08-22 08:50:34 ----D---- C:\Program Files (x86)\Common Files
2015-08-21 20:45:44 ----RD---- C:\Program Files (x86)\Skype
2015-08-21 20:45:35 ----D---- C:\ProgramData\Skype
2015-08-21 18:36:09 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2015-08-17 20:27:46 ----D---- C:\Windows\system32\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iaStor.sys [2012-02-01 568600]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2015-08-05 21184]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2015-08-05 806032]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2015-08-05 45856]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-01-11 283200]
R1 cherimoya;cherimoya; C:\Windows\system32\drivers\cherimoya.sys [2015-06-18 61336]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2015-08-05 105096]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 66304]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-09-23 359552]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2012-03-19 14745600]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2012-07-02 62784]
R3 PAC207;Eye 110; C:\Windows\system32\DRIVERS\PFC027.SYS [2009-06-25 686592]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2012-01-10 2184816]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 187904]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 95232]
S1 CFRMD;CFRMD; C:\Windows\system32\DRIVERS\CFRMD.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2014-01-04 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2014-01-04 27760]
S3 nmwcd;Nokia USB Phone Parent Driver; C:\Windows\system32\drivers\ccdcmbx64.sys [2013-01-23 19968]
S3 nmwcdc;Nokia USB Communication Driver; C:\Windows\system32\drivers\ccdcmbox64.sys [2013-01-23 27136]
S3 nmwcdnsucx64;Nokia USB Flashing Generic; C:\Windows\system32\drivers\nmwcdnsucx64.sys [2013-01-23 12800]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2013-01-23 171008]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter; C:\Windows\system32\DRIVERS\RTL8192su.sys [2009-11-12 676864]
S3 terminpt;Microsoft Remote Desktop Input Driver; C:\Windows\system32\drivers\terminpt.sys [2012-08-23 29696]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys [2013-01-23 9216]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 UsbserFilt;UsbserFilt; C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys [2013-01-23 9216]
S3 WinUsb;Sony so0103 ADB Interface; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 65f825de-0adc-4791-a1e5-209aa6f7ea76;65f825de-0adc-4791-a1e5-209aa6f7ea76; C:\Program Files\daugava\Upbgbeie.exe [2015-07-22 284320]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-07-17 82128]
R2 Application Updater;Application Updater; C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe [2015-08-17 946352]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2015-08-21 1394816]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2015-08-21 1772672]
R2 CLPSLauncher;COMODO LPS Launcher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [2015-08-22 70848]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2015-09-09 5542472]
R2 csrcc;csrcc; C:\Program Files\daugava\csrcc.exe [2015-07-22 1447584]
R2 daugava Updater;daugava Updater; C:\Program Files\daugava\Weekfqwb.exe [2015-07-22 173216]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DragonUpdater;COMODO Dragon Update Service; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2015-06-27 1994936]
R2 GeekBuddyRSP;GeekBuddyRSP Server; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2015-08-22 2327248]
R2 IB Updater;IB Updater; C:\Program Files\IB Updater\ExtensionUpdaterService.exe [2013-01-29 188760]
R2 Realtek11nSU;Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [2009-12-07 40960]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2012-01-10 27760]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\SeaPort.exe [2014-03-12 247968]
R3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S2 BBSvc;BingBar Service; C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BBSvc.exe [2014-03-12 193696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2015-08-09 2265792]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2012-09-28 76904]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2012-03-19 276248]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2013-02-13 1431888]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2013-02-13 1044816]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-09-09 114688]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files\McAfee Security Scan\3.11.163\McCHSvc.exe [2015-09-05 289256]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-08-30 149160]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Program Manager;Program Manager; C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe [2015-08-15 951448]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2013-02-13 79360]
S3 Sony PC Companion;Sony PC Companion; C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe [2015-06-10 155520]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-01-09 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
-----------------EOF-----------------
Re: Prosím o kontrolu logu
Krasny den Vam preju 
Odinstalujte
V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).
Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
- McAfee Security Scan - adware z instalace Adobe Flash Playeru http://forum.viry.cz/viewtopic.php?p=1374437#p1374437
- Skype Click to Call - adware z instalace Skypu http://forum.viry.cz/viewtopic.php?p=1374439#p1374439
- Bing Bar - pokud nepouzivate
- Advanced System Care a dale i ostatni produkty od IObitu. Jsou to cinske smejdy, ktere svou karieru zapocaly kradezi databaze spolecnosti Malwarebytes a navic pri nekterych "opravach" timto produktem nekolikrat doslo k nakopnuti operacniho systemu takovym zpusobem, ze vse zcela vyresil az kompletni reinstall. Obecne jsem proti vsem zrychlovacum a optimizerum krome nekolik let odzkouseneho CCleaneru, ktery je v defaultnim nastaveni neskodny.
- ukoncete vsechny programy
- kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
- kliknete na Scan, pote na Cleaning
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner[Cx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Hezky den, vše odstraněno dle návodu, ale nic od IObitu sem v PC nenašel.
# AdwCleaner v5.007 - Logfile created 15/09/2015 at 09:46:20
# Updated 08/09/2015 by Xplode
# Database : 2015-09-10.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Lada - LADA-PC
# Running from : C:\Users\Lada\Desktop\adwcleaner_5.007.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
[-] Service Deleted : cherimoya
[-] Service Deleted : csrcc
[-] Service Deleted : IB Updater
[-] Service Deleted : Program Manager
[-] Service Deleted : daugava Updater
[-] Service Deleted : 65f825de-0adc-4791-a1e5-209aa6f7ea76
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files\IB Updater
[-] Folder Deleted : C:\Program Files\daugava
[-] Folder Deleted : C:\Program Files (x86)\Conduit
[-] Folder Deleted : C:\Program Files (x86)\goforfiles
[-] Folder Deleted : C:\Program Files (x86)\SimilarSites
[-] Folder Deleted : C:\Program Files (x86)\VideoDownloadConverter_4zEI
[-] Folder Deleted : C:\Program Files (x86)\Common Files\Spigot
[-] Folder Deleted : C:\Program Files (x86)\Common Files\ProgramManager
[-] Folder Deleted : C:\ProgramData\Ask
[-] Folder Deleted : C:\ProgramData\Babylon
[-] Folder Deleted : C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
[-] Folder Deleted : C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
[-] Folder Deleted : C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\goforfiles
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Conduit
[-] Folder Deleted : C:\Users\Lada\AppData\Local\NativeMessaging
[-] Folder Deleted : C:\Users\Lada\AppData\Local\TBHostSupport
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] Folder Deleted : C:\Users\Lada\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\Lada\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\Babylon
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\goforfiles
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserProtect
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\adremoveext@adremoveext.net
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93}
[-] Folder Deleted : C:\Windows\Sysnative\ARFC
[-] Folder Deleted : C:\Windows\Sysnative\ljkb
[-] Folder Deleted : C:\Windows\SysWOW64\ARFC
[-] Folder Deleted : C:\Windows\SysWOW64\jmdp
[-] Folder Deleted : C:\Windows\SysWOW64\WNLT
***** [ Files ] *****
[-] File Deleted : C:\user.js
[-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\nsprotector.js
[-] File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[-] File Deleted : C:\Users\Lada\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_cmaiofennmphjldldcpphcechfnnohja_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mhkaekfpcppmmioggniknbnbdbcigpkk
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pfndaklgolladniicklehhancnlgocpp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jddgoigfhpjafhnbgndmoeaokikjfomp_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_jddgoigfhpjafhnbgndmoeaokikjfomp_0
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pfndaklgolladniicklehhancnlgocpp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mhkaekfpcppmmioggniknbnbdbcigpkk
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pfndaklgolladniicklehhancnlgocpp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jddgoigfhpjafhnbgndmoeaokikjfomp_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_jddgoigfhpjafhnbgndmoeaokikjfomp_0
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\bprotector web data
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
[-] File Deleted : C:\Users\Lada\AppData\LocalLow\SkwConfig.bin
[-] File Deleted : C:\Users\Lada\AppData\Roaming\BabMaint.exe
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Check PC for Errors.lnk
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\ask-web-search.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\bingp.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\Conduit.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\MyStart Search.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\yahoo_ff.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\user.js
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\yahoo.xml
[-] File Deleted : C:\Users\Lada\Desktop\Check PC for Errors.lnk
[-] File Deleted : C:\Users\Public\Desktop\GeekBuddy.lnk
[-] File Deleted : C:\Windows\Sysnative\dmwu.exe
[-] File Deleted : C:\Windows\Sysnative\ImhxxpComm.dll
[-] File Deleted : C:\Windows\Sysnative\drivers\cherimoya.sys
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
[-] Task Deleted : EPUpdater
[-] Task Deleted : Cawlez
***** [ Registry ] *****
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
[-] Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
[-] Key Deleted : HKCU\Software\5b57dd88b168ea43
[-] Key Deleted : HKLM\SOFTWARE\5b57dd88b168ea43
[-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3302239
[-] Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{0F827075-B026-42F3-885D-98981EE7B1AE}]
[-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
[-] Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
[-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}]
[-] Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}]
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
[-] Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
[-] Key Deleted : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fgfdfcbeamjnjdejakdidpniblllnbpg
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
[-] Key Deleted : HKCU\Software\Google\Chrome\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
[!] Key Not Deleted : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[!] Key Not Deleted : HKCU\Software\Google\Chrome\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{14EF423E-3EE8-44AE-9337-07AC3F27B744}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
[-] Key Deleted : HKU\.DEFAULT\Software\IM
[-] Key Deleted : HKU\.DEFAULT\Software\ImInstaller
[-] Key Deleted : HKU\.DEFAULT\Software\WNLT
[-] Key Deleted : HKCU\Software\BabylonToolbar
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\DataMngr
[-] Key Deleted : HKCU\Software\GoforFiles
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKCU\Software\ImInstaller
[-] Key Deleted : HKCU\Software\InstallCore
[-] Key Deleted : HKCU\Software\SearchProtect
[-] Key Deleted : HKCU\Software\SweetIM
[-] Key Deleted : HKCU\Software\WNLT
[-] Key Deleted : HKCU\Software\AppDataLow\Toolbar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
[-] Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
[-] Key Deleted : HKCU\Software\AppDataLow\Software\IObit Apps
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\DataMngr
[-] Key Deleted : HKLM\SOFTWARE\GoforFiles
[-] Key Deleted : HKLM\SOFTWARE\IB Updater
[-] Key Deleted : HKLM\SOFTWARE\SearchProtect
[-] Key Deleted : HKLM\SOFTWARE\GeekBuddyRSP
[-] Key Deleted : HKLM\SOFTWARE\VideoDownloadConverter_4zEI
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WNLT
[!] Key Not Deleted : [x64] HKCU\Software\BabylonToolbar
[!] Key Not Deleted : [x64] HKCU\Software\Conduit
[!] Key Not Deleted : [x64] HKCU\Software\DataMngr
[!] Key Not Deleted : [x64] HKCU\Software\GoforFiles
[!] Key Not Deleted : [x64] HKCU\Software\IM
[!] Key Not Deleted : [x64] HKCU\Software\ImInstaller
[!] Key Not Deleted : [x64] HKCU\Software\InstallCore
[!] Key Not Deleted : [x64] HKCU\Software\SearchProtect
[!] Key Not Deleted : [x64] HKCU\Software\SweetIM
[!] Key Not Deleted : [x64] HKCU\Software\WNLT
[-] Key Deleted : [x64] HKLM\SOFTWARE\IB Updater
[-] Key Deleted : [x64] HKLM\SOFTWARE\SweetIM
[-] Key Deleted : [x64] HKLM\SOFTWARE\systweak
[-] Key Deleted : [x64] HKLM\SOFTWARE\WNLT
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}_is1
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\AppDataLow\Software\Conduit
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\AppDataLow\Software\ConduitSearchScopes
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\AppDataLow\Software\IObit Apps
[!] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{346BD868-C594-4D08-9408-87ED6F1D1BE8}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{61FEA30C-78B9-41BE-A316-8E1AEB12A0AF}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{7238486F-C8CB-448E-8FB7-07C4331DF5C5}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}
[!] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{346BD868-C594-4D08-9408-87ED6F1D1BE8}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{61FEA30C-78B9-41BE-A316-8E1AEB12A0AF}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{7238486F-C8CB-448E-8FB7-07C4331DF5C5}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{346BD868-C594-4D08-9408-87ED6F1D1BE8}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{61FEA30C-78B9-41BE-A316-8E1AEB12A0AF}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{7238486F-C8CB-448E-8FB7-07C4331DF5C5}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
***** [ Web browsers ] *****
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1423406529560");
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : search.conduit.com
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : delta-search.com
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mystart.incredibar.com
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mystart.incredibar.com/
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ejpbbhjlbipncjklfjjaedaieimbmdda
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ejpbbhjlbipncjklfjjaedaieimbmdda
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : fcfenmboojpjinhpgggodefccipikbpd
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : hbcennhacfaagdopikcegfcobcadeocj
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : hbcennhacfaagdopikcegfcobcadeocj
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : icdlfehblmklkikfigmjhbmmpmkmpooj
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : icdlfehblmklkikfigmjhbmmpmkmpooj
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : jddgoigfhpjafhnbgndmoeaokikjfomp
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : jddgoigfhpjafhnbgndmoeaokikjfomp
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mhkaekfpcppmmioggniknbnbdbcigpkk
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mhkaekfpcppmmioggniknbnbdbcigpkk
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pfndaklgolladniicklehhancnlgocpp
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pfndaklgolladniicklehhancnlgocpp
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pfndaklgolladniicklehhancnlgocpp
*************************
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [24274 bytes] ##########
# AdwCleaner v5.007 - Logfile created 15/09/2015 at 09:46:20
# Updated 08/09/2015 by Xplode
# Database : 2015-09-10.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Lada - LADA-PC
# Running from : C:\Users\Lada\Desktop\adwcleaner_5.007.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
[-] Service Deleted : cherimoya
[-] Service Deleted : csrcc
[-] Service Deleted : IB Updater
[-] Service Deleted : Program Manager
[-] Service Deleted : daugava Updater
[-] Service Deleted : 65f825de-0adc-4791-a1e5-209aa6f7ea76
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files\IB Updater
[-] Folder Deleted : C:\Program Files\daugava
[-] Folder Deleted : C:\Program Files (x86)\Conduit
[-] Folder Deleted : C:\Program Files (x86)\goforfiles
[-] Folder Deleted : C:\Program Files (x86)\SimilarSites
[-] Folder Deleted : C:\Program Files (x86)\VideoDownloadConverter_4zEI
[-] Folder Deleted : C:\Program Files (x86)\Common Files\Spigot
[-] Folder Deleted : C:\Program Files (x86)\Common Files\ProgramManager
[-] Folder Deleted : C:\ProgramData\Ask
[-] Folder Deleted : C:\ProgramData\Babylon
[-] Folder Deleted : C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
[-] Folder Deleted : C:\ProgramData\{BAF091CA-86C4-4627-ADA1-897E2621C1B0}
[-] Folder Deleted : C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\goforfiles
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Conduit
[-] Folder Deleted : C:\Users\Lada\AppData\Local\NativeMessaging
[-] Folder Deleted : C:\Users\Lada\AppData\Local\TBHostSupport
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd
[-] Folder Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfndaklgolladniicklehhancnlgocpp
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[!] Folder Not Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] Folder Deleted : C:\Users\Lada\AppData\LocalLow\Conduit
[-] Folder Deleted : C:\Users\Lada\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\Babylon
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\goforfiles
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserProtect
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\adremoveext@adremoveext.net
[-] Folder Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93}
[-] Folder Deleted : C:\Windows\Sysnative\ARFC
[-] Folder Deleted : C:\Windows\Sysnative\ljkb
[-] Folder Deleted : C:\Windows\SysWOW64\ARFC
[-] Folder Deleted : C:\Windows\SysWOW64\jmdp
[-] Folder Deleted : C:\Windows\SysWOW64\WNLT
***** [ Files ] *****
[-] File Deleted : C:\user.js
[-] File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\nsprotector.js
[-] File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
[-] File Deleted : C:\Users\Lada\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_cmaiofennmphjldldcpphcechfnnohja_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dlnembnfbcpjnepmfjmngjenhhajpdfd_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mhkaekfpcppmmioggniknbnbdbcigpkk
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pfndaklgolladniicklehhancnlgocpp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jddgoigfhpjafhnbgndmoeaokikjfomp_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_jddgoigfhpjafhnbgndmoeaokikjfomp_0
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pfndaklgolladniicklehhancnlgocpp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mhkaekfpcppmmioggniknbnbdbcigpkk
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pfndaklgolladniicklehhancnlgocpp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_ejpbbhjlbipncjklfjjaedaieimbmdda_0
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_jddgoigfhpjafhnbgndmoeaokikjfomp_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_jddgoigfhpjafhnbgndmoeaokikjfomp_0
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\bprotector web data
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage
[-] File Deleted : C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_pstatic.bestpriceninja.com_0.localstorage-journal
[-] File Deleted : C:\Users\Lada\AppData\LocalLow\SkwConfig.bin
[-] File Deleted : C:\Users\Lada\AppData\Roaming\BabMaint.exe
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Check PC for Errors.lnk
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\ask-web-search.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\bingp.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\Conduit.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\MyStart Search.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\yahoo_ff.xml
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\user.js
[-] File Deleted : C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\searchplugins\yahoo.xml
[-] File Deleted : C:\Users\Lada\Desktop\Check PC for Errors.lnk
[-] File Deleted : C:\Users\Public\Desktop\GeekBuddy.lnk
[-] File Deleted : C:\Windows\Sysnative\dmwu.exe
[-] File Deleted : C:\Windows\Sysnative\ImhxxpComm.dll
[-] File Deleted : C:\Windows\Sysnative\drivers\cherimoya.sys
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
[-] Task Deleted : EPUpdater
[-] Task Deleted : Cawlez
***** [ Registry ] *****
[-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject
[-] Key Deleted : HKLM\SOFTWARE\Classes\Extension.ExtensionHelperObject.1
[-] Key Deleted : HKCU\Software\5b57dd88b168ea43
[-] Key Deleted : HKLM\SOFTWARE\5b57dd88b168ea43
[-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3302239
[-] Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{0F827075-B026-42F3-885D-98981EE7B1AE}]
[-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
[-] Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
[-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}]
[-] Value Deleted : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{FE1DEEEA-DB6D-44B8-83F0-34FC0F9D1052}]
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
[-] Key Deleted : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
[-] Key Deleted : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fgfdfcbeamjnjdejakdidpniblllnbpg
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
[-] Key Deleted : HKCU\Software\Google\Chrome\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hbcennhacfaagdopikcegfcobcadeocj
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\icdlfehblmklkikfigmjhbmmpmkmpooj
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhkaekfpcppmmioggniknbnbdbcigpkk
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pfndaklgolladniicklehhancnlgocpp
[!] Key Not Deleted : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
[!] Key Not Deleted : HKCU\Software\Google\Chrome\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[!] Key Not Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jddgoigfhpjafhnbgndmoeaokikjfomp
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{14EF423E-3EE8-44AE-9337-07AC3F27B744}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10921475-03CE-4E04-90CE-E2E7EF20C814}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A9582D7B-F24A-441D-9D26-450D58F3CD17}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
[-] Key Deleted : HKU\.DEFAULT\Software\IM
[-] Key Deleted : HKU\.DEFAULT\Software\ImInstaller
[-] Key Deleted : HKU\.DEFAULT\Software\WNLT
[-] Key Deleted : HKCU\Software\BabylonToolbar
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\DataMngr
[-] Key Deleted : HKCU\Software\GoforFiles
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKCU\Software\ImInstaller
[-] Key Deleted : HKCU\Software\InstallCore
[-] Key Deleted : HKCU\Software\SearchProtect
[-] Key Deleted : HKCU\Software\SweetIM
[-] Key Deleted : HKCU\Software\WNLT
[-] Key Deleted : HKCU\Software\AppDataLow\Toolbar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
[-] Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
[-] Key Deleted : HKCU\Software\AppDataLow\Software\IObit Apps
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\DataMngr
[-] Key Deleted : HKLM\SOFTWARE\GoforFiles
[-] Key Deleted : HKLM\SOFTWARE\IB Updater
[-] Key Deleted : HKLM\SOFTWARE\SearchProtect
[-] Key Deleted : HKLM\SOFTWARE\GeekBuddyRSP
[-] Key Deleted : HKLM\SOFTWARE\VideoDownloadConverter_4zEI
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WNLT
[!] Key Not Deleted : [x64] HKCU\Software\BabylonToolbar
[!] Key Not Deleted : [x64] HKCU\Software\Conduit
[!] Key Not Deleted : [x64] HKCU\Software\DataMngr
[!] Key Not Deleted : [x64] HKCU\Software\GoforFiles
[!] Key Not Deleted : [x64] HKCU\Software\IM
[!] Key Not Deleted : [x64] HKCU\Software\ImInstaller
[!] Key Not Deleted : [x64] HKCU\Software\InstallCore
[!] Key Not Deleted : [x64] HKCU\Software\SearchProtect
[!] Key Not Deleted : [x64] HKCU\Software\SweetIM
[!] Key Not Deleted : [x64] HKCU\Software\WNLT
[-] Key Deleted : [x64] HKLM\SOFTWARE\IB Updater
[-] Key Deleted : [x64] HKLM\SOFTWARE\SweetIM
[-] Key Deleted : [x64] HKLM\SOFTWARE\systweak
[-] Key Deleted : [x64] HKLM\SOFTWARE\WNLT
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f179b4aa-3249-4e0e-a45a-8519d6bcd424}_is1
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\AppDataLow\Software\Conduit
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\AppDataLow\Software\ConduitSearchScopes
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\AppDataLow\Software\IObit Apps
[!] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{346BD868-C594-4D08-9408-87ED6F1D1BE8}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{61FEA30C-78B9-41BE-A316-8E1AEB12A0AF}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{7238486F-C8CB-448E-8FB7-07C4331DF5C5}
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}
[!] Key Not Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{346BD868-C594-4D08-9408-87ED6F1D1BE8}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{61FEA30C-78B9-41BE-A316-8E1AEB12A0AF}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{7238486F-C8CB-448E-8FB7-07C4331DF5C5}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{346BD868-C594-4D08-9408-87ED6F1D1BE8}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{61FEA30C-78B9-41BE-A316-8E1AEB12A0AF}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{7238486F-C8CB-448E-8FB7-07C4331DF5C5}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{8EEAC88A-079B-4b2c-80C1-7836F79EB40A}
[!] Key Not Deleted : HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
***** [ Web browsers ] *****
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.lastActivePing", "1423406529560");
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark._4zMembers_.weather.location", "10001");
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
[-] [C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\prefs.js] [Preference] Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "videodownloadconverter@mindspark.com");
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : search.conduit.com
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : delta-search.com
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mystart.incredibar.com
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mystart.incredibar.com/
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ejpbbhjlbipncjklfjjaedaieimbmdda
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ejpbbhjlbipncjklfjjaedaieimbmdda
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : fcfenmboojpjinhpgggodefccipikbpd
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : hbcennhacfaagdopikcegfcobcadeocj
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : hbcennhacfaagdopikcegfcobcadeocj
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : icdlfehblmklkikfigmjhbmmpmkmpooj
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : icdlfehblmklkikfigmjhbmmpmkmpooj
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : jddgoigfhpjafhnbgndmoeaokikjfomp
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : jddgoigfhpjafhnbgndmoeaokikjfomp
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mhkaekfpcppmmioggniknbnbdbcigpkk
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : mhkaekfpcppmmioggniknbnbdbcigpkk
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pfndaklgolladniicklehhancnlgocpp
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pfndaklgolladniicklehhancnlgocpp
[-] [C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : pfndaklgolladniicklehhancnlgocpp
*************************
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [24274 bytes] ##########
Re: Prosím o kontrolu logu
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:14-09-2015
Ran by Lada (administrator) on LADA-PC (15-09-2015 10:14:42)
Running from C:\Users\Lada\Desktop
Loaded Profiles: Lada (Available Profiles: Lada)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\PAC207\Monitor.exe
(© 2015 Microsoft Corporation) C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1427648 2015-08-09] (COMODO)
HKLM\...\Run: [PAC207_Monitor] => C:\Windows\PixArt\PAC207\Monitor.exe [323584 2007-12-10] (PixArt Imaging Incorporation)
HKLM\...\Run: [daugava] => C:\Program Files\daugava\Ejemidvlf.exe
HKLM\...\Run: [daugava64] => C:\Program Files\daugava\Ejemidvlf64.exe
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5028464 2012-01-12] (VIA)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-08-22] (Comodo Security Solutions, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [AROReminder] => C:\Program Files (x86)\ARO 2013\ARO.exe [3157336 2013-07-03] (Support.com, Inc.)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8202008 2015-05-13] (Piriform Ltd)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [BingSvc] => C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-05-11] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [] => [X]
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1092448 2015-05-20] (Nokia)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53735968 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-18\...\Run: [Advanced SystemCare 7] => "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks 2013 Rychlé spuštění.lnk [2013-02-13]
ShortcutTarget: SolidWorks 2013 Rychlé spuštění.lnk -> C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks Nástroj pro stahování na pozadí.lnk [2013-02-10]
ShortcutTarget: SolidWorks Nástroj pro stahování na pozadí.lnk -> C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 212.111.0.10 194.213.32.237
Tcpip\..\Interfaces\{47A8AFA2-D00F-4F0A-890B-2B997F163A99}: [DhcpNameServer] 212.111.0.10 194.213.32.237
Internet Explorer:
==================
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=UP22&ocid=UP22DHP&dt=012113
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://nmd.msn.com
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.atcomp.cz
URLSearchHook: HKLM-x32 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.)
URLSearchHook: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.)
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {7238486F-C8CB-448E-8FB7-07C4331DF5C5} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> DefaultScope {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M ... -SearchBox
SearchScopes: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M ... -SearchBox
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-27] (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: ARO 2013 Toolbar -> {92e7bc9c-bc36-42d4-9013-65e387115066} -> C:\Program Files (x86)\ARO_2013\prxtbARO_.dll [2013-07-17] (Conduit Ltd.)
BHO-x32: Ads Removal -> {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} -> C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll [2014-06-11] (Adblock)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-27] (Oracle Corporation)
Toolbar: HKLM-x32 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll [2013-07-17] (Conduit Ltd.)
Toolbar: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060
FF DefaultSearchEngine: Yahoo!
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Yahoo!
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2014-11-19] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2831377403-1237323822-844494322-1000: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll [2013-08-27] (Sony Network Entertainment International LLC)
FF Extension: Bing Search Engine - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\bingsearch.full@microsoft.com [2015-04-10]
FF Extension: ARO 2013 - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\{92e7bc9c-bc36-42d4-9013-65e387115066} [2015-02-15]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30]
FF Extension: No Name - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93} [not found]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2015-08-30] <==== ATTENTION
Chrome:
=======
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=chr-yo_gc&ei=utf-8&ilc=12&type=198484&p={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo.com search
CHR DefaultSuggestURL: Default -> hxxps://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll => No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File
CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
CHR Profile: C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bing) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2015-09-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-06]
CHR HKU\S-1-5-21-2831377403-1237323822-844494322-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70848 2015-08-22] (Comodo Security Solutions, Inc.)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5542472 2015-09-09] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-08-09] (COMODO)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [1994936 2015-06-27] (Comodo)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-08-22] (Comodo Security Solutions, Inc.)
R2 Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed]
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2013-02-13] (SolidWorks) [File not signed]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-01-10] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S1 CFRMD; C:\Windows\SysWOW64\DRIVERS\CFRMD.sys [37976 2012-09-03] (Windows (R) Win 7 DDK provider) [File not signed]
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [21184 2015-08-05] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [806032 2015-08-05] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45856 2015-08-05] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-01-11] (DT Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [105096 2015-08-05] (COMODO)
R3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [686592 2009-06-25] (PixArt Imaging Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-15 10:14 - 2015-09-15 10:15 - 00021301 _____ C:\Users\Lada\Desktop\FRST.txt
2015-09-15 10:14 - 2015-09-15 10:14 - 00000000 ____D C:\FRST
2015-09-15 10:11 - 2015-09-15 10:11 - 02190848 _____ (Farbar) C:\Users\Lada\Desktop\FRST64.exe
2015-09-15 09:45 - 2015-09-15 09:46 - 00000000 ____D C:\AdwCleaner
2015-09-15 09:44 - 2015-09-15 09:44 - 01660416 _____ C:\Users\Lada\Desktop\adwcleaner_5.007.exe
2015-09-14 12:19 - 2015-09-15 09:43 - 00000000 ____D C:\Program Files\trend micro
2015-09-14 12:19 - 2015-09-14 12:19 - 00000000 ____D C:\rsit
2015-09-01 15:44 - 2015-09-01 15:44 - 28849904 _____ C:\Users\Lada\Documents\vlc-2.2.1-win32.exe
2015-08-30 21:16 - 2015-08-30 21:16 - 06420480 _____ C:\Program Files (x86)\GUT5EB1.tmp
2015-08-30 21:16 - 2015-08-30 21:16 - 00000000 ____D C:\Program Files (x86)\GUM5EB0.tmp
2015-08-30 09:29 - 2015-09-01 15:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-22 08:50 - 2015-08-22 08:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo Security Solutions Inc
2015-08-21 20:45 - 2015-08-21 20:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-19 13:19 - 2015-08-11 03:20 - 25191936 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-19 13:19 - 2015-08-11 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-19 13:19 - 2015-08-11 02:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-08-19 13:19 - 2015-08-11 02:20 - 19871232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-15 10:07 - 2013-01-07 11:12 - 01474832 _____ C:\Windows\system32\Drivers\sfi.dat
2015-09-15 09:59 - 2013-02-12 23:04 - 01831969 _____ C:\Windows\WindowsUpdate.log
2015-09-15 09:59 - 2013-01-07 20:04 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-15 09:56 - 2009-07-14 06:45 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-15 09:56 - 2009-07-14 06:45 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-15 09:48 - 2013-01-07 20:04 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-15 09:47 - 2015-06-04 12:10 - 00013744 _____ C:\Windows\PFRO.log
2015-09-15 09:47 - 2015-06-03 13:04 - 00008748 _____ C:\Windows\setupact.log
2015-09-15 09:47 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-15 09:47 - 2009-07-14 06:45 - 00434304 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-15 09:43 - 2015-04-04 16:27 - 00000000 ___SD C:\Windows\system32\GWX
2015-09-15 09:43 - 2013-01-07 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-09-15 09:43 - 2013-01-07 11:20 - 00000000 ____D C:\Program Files\CCleaner
2015-09-15 09:43 - 2013-01-07 11:13 - 00000000 ____D C:\Windows\System32\Tasks\COMODO
2015-09-15 09:43 - 2012-12-24 16:07 - 00000000 ____D C:\Users\Lada
2015-09-15 09:43 - 2010-11-21 11:38 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-09-15 09:42 - 2013-01-21 22:18 - 00000000 ____D C:\Users\Lada\AppData\Roaming\Skype
2015-09-15 09:42 - 2013-01-10 06:29 - 00000000 ____D C:\Users\Lada\AppData\Local\Mozilla
2015-09-15 09:40 - 2013-10-27 09:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-09-15 09:40 - 2013-10-27 09:32 - 00000000 ____D C:\Program Files (x86)\Sony
2015-09-15 09:40 - 2012-12-15 10:22 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-15 09:39 - 2014-01-04 14:25 - 00000000 ____D C:\ProgramData\Sony Mobile
2015-09-15 09:39 - 2014-01-04 14:25 - 00000000 ____D C:\Program Files (x86)\Sony Mobile
2015-09-15 09:36 - 2013-01-07 20:04 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-15 09:30 - 2013-02-20 22:39 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-09-09 18:23 - 2015-02-08 10:22 - 00000000 ____D C:\Users\Lada\Desktop\Aleš
2015-09-09 17:55 - 2015-07-27 10:45 - 00000000 ____D C:\Users\Lada\Desktop\benatska noc 2015
2015-09-09 17:52 - 2010-11-21 11:27 - 00742398 _____ C:\Windows\system32\perfh005.dat
2015-09-09 17:52 - 2010-11-21 11:27 - 00195546 _____ C:\Windows\system32\perfc005.dat
2015-09-09 17:52 - 2009-07-14 07:13 - 01711684 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-05 17:46 - 2013-01-20 20:37 - 00000000 ____D C:\Users\Lada\AppData\Local\TempAdresářZálohySW
2015-09-05 16:25 - 2013-01-11 12:44 - 00000000 ____D C:\Users\Lada\AppData\Roaming\SolidWorks
2015-09-05 16:00 - 2013-01-07 20:05 - 00002201 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-03 13:52 - 2012-12-14 21:45 - 00579408 _____ (COMODO) C:\Windows\system32\guard64.dll
2015-09-03 13:52 - 2012-12-14 21:45 - 00445472 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll
2015-09-01 15:48 - 2013-03-24 01:37 - 00000000 ____D C:\Users\Lada\AppData\Roaming\vlc
2015-09-01 15:45 - 2013-03-24 01:37 - 00001082 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-09-01 15:03 - 2013-01-10 06:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-31 19:54 - 2013-01-07 20:04 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-31 19:54 - 2013-01-07 20:04 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-22 08:50 - 2013-01-07 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2015-08-21 20:45 - 2014-09-16 19:29 - 00002761 _____ C:\Users\Public\Desktop\Skype.lnk
2015-08-21 20:45 - 2013-01-21 22:18 - 00000000 ____D C:\ProgramData\Skype
2015-08-21 18:36 - 2015-07-10 15:22 - 00016930 _____ C:\Windows\DPINST.LOG
2015-08-17 20:27 - 2015-05-30 21:13 - 00003896 _____ C:\Windows\System32\Tasks\Program Manager
==================== Files in the root of some directories =======
2015-08-30 21:16 - 2015-08-30 21:16 - 6420480 _____ () C:\Program Files (x86)\GUT5EB1.tmp
2014-09-05 09:05 - 2014-09-05 09:05 - 0000000 _____ () C:\Users\Lada\AppData\Local\{49BCE388-C6BA-499E-B72B-74A26CC8713D}
Some files in TEMP:
====================
C:\Users\Lada\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Lada\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-03 21:23
Ran by Lada (administrator) on LADA-PC (15-09-2015 10:14:42)
Running from C:\Users\Lada\Desktop
Loaded Profiles: Lada (Available Profiles: Lada)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\PAC207\Monitor.exe
(© 2015 Microsoft Corporation) C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Nokia) C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1427648 2015-08-09] (COMODO)
HKLM\...\Run: [PAC207_Monitor] => C:\Windows\PixArt\PAC207\Monitor.exe [323584 2007-12-10] (PixArt Imaging Incorporation)
HKLM\...\Run: [daugava] => C:\Program Files\daugava\Ejemidvlf.exe
HKLM\...\Run: [daugava64] => C:\Program Files\daugava\Ejemidvlf64.exe
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5028464 2012-01-12] (VIA)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-08-22] (Comodo Security Solutions, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [AROReminder] => C:\Program Files (x86)\ARO 2013\ARO.exe [3157336 2013-07-03] (Support.com, Inc.)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8202008 2015-05-13] (Piriform Ltd)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [BingSvc] => C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-05-11] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [] => [X]
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1092448 2015-05-20] (Nokia)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53735968 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-18\...\Run: [Advanced SystemCare 7] => "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks 2013 Rychlé spuštění.lnk [2013-02-13]
ShortcutTarget: SolidWorks 2013 Rychlé spuštění.lnk -> C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks Nástroj pro stahování na pozadí.lnk [2013-02-10]
ShortcutTarget: SolidWorks Nástroj pro stahování na pozadí.lnk -> C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 212.111.0.10 194.213.32.237
Tcpip\..\Interfaces\{47A8AFA2-D00F-4F0A-890B-2B997F163A99}: [DhcpNameServer] 212.111.0.10 194.213.32.237
Internet Explorer:
==================
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=UP22&ocid=UP22DHP&dt=012113
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://nmd.msn.com
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.atcomp.cz
URLSearchHook: HKLM-x32 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.)
URLSearchHook: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.)
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {7238486F-C8CB-448E-8FB7-07C4331DF5C5} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> DefaultScope {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M ... -SearchBox
SearchScopes: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M ... -SearchBox
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-27] (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: ARO 2013 Toolbar -> {92e7bc9c-bc36-42d4-9013-65e387115066} -> C:\Program Files (x86)\ARO_2013\prxtbARO_.dll [2013-07-17] (Conduit Ltd.)
BHO-x32: Ads Removal -> {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} -> C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll [2014-06-11] (Adblock)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-27] (Oracle Corporation)
Toolbar: HKLM-x32 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll [2013-07-17] (Conduit Ltd.)
Toolbar: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060
FF DefaultSearchEngine: Yahoo!
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Yahoo!
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxps://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=198484&p=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2014-11-19] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2831377403-1237323822-844494322-1000: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll [2013-08-27] (Sony Network Entertainment International LLC)
FF Extension: Bing Search Engine - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\bingsearch.full@microsoft.com [2015-04-10]
FF Extension: ARO 2013 - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\{92e7bc9c-bc36-42d4-9013-65e387115066} [2015-02-15]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30]
FF Extension: No Name - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93} [not found]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2015-08-30] <==== ATTENTION
Chrome:
=======
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=chr-yo_gc&ei=utf-8&ilc=12&type=198484&p={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo.com search
CHR DefaultSuggestURL: Default -> hxxps://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll => No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File
CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
CHR Profile: C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bing) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2015-09-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-06]
CHR HKU\S-1-5-21-2831377403-1237323822-844494322-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70848 2015-08-22] (Comodo Security Solutions, Inc.)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5542472 2015-09-09] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-08-09] (COMODO)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [1994936 2015-06-27] (Comodo)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-08-22] (Comodo Security Solutions, Inc.)
R2 Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed]
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2013-02-13] (SolidWorks) [File not signed]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-01-10] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S1 CFRMD; C:\Windows\SysWOW64\DRIVERS\CFRMD.sys [37976 2012-09-03] (Windows (R) Win 7 DDK provider) [File not signed]
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [21184 2015-08-05] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [806032 2015-08-05] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45856 2015-08-05] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-01-11] (DT Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [105096 2015-08-05] (COMODO)
R3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [686592 2009-06-25] (PixArt Imaging Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-15 10:14 - 2015-09-15 10:15 - 00021301 _____ C:\Users\Lada\Desktop\FRST.txt
2015-09-15 10:14 - 2015-09-15 10:14 - 00000000 ____D C:\FRST
2015-09-15 10:11 - 2015-09-15 10:11 - 02190848 _____ (Farbar) C:\Users\Lada\Desktop\FRST64.exe
2015-09-15 09:45 - 2015-09-15 09:46 - 00000000 ____D C:\AdwCleaner
2015-09-15 09:44 - 2015-09-15 09:44 - 01660416 _____ C:\Users\Lada\Desktop\adwcleaner_5.007.exe
2015-09-14 12:19 - 2015-09-15 09:43 - 00000000 ____D C:\Program Files\trend micro
2015-09-14 12:19 - 2015-09-14 12:19 - 00000000 ____D C:\rsit
2015-09-01 15:44 - 2015-09-01 15:44 - 28849904 _____ C:\Users\Lada\Documents\vlc-2.2.1-win32.exe
2015-08-30 21:16 - 2015-08-30 21:16 - 06420480 _____ C:\Program Files (x86)\GUT5EB1.tmp
2015-08-30 21:16 - 2015-08-30 21:16 - 00000000 ____D C:\Program Files (x86)\GUM5EB0.tmp
2015-08-30 09:29 - 2015-09-01 15:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-22 08:50 - 2015-08-22 08:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo Security Solutions Inc
2015-08-21 20:45 - 2015-08-21 20:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-19 13:19 - 2015-08-11 03:20 - 25191936 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-19 13:19 - 2015-08-11 03:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-19 13:19 - 2015-08-11 02:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-08-19 13:19 - 2015-08-11 02:20 - 19871232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-15 10:07 - 2013-01-07 11:12 - 01474832 _____ C:\Windows\system32\Drivers\sfi.dat
2015-09-15 09:59 - 2013-02-12 23:04 - 01831969 _____ C:\Windows\WindowsUpdate.log
2015-09-15 09:59 - 2013-01-07 20:04 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-15 09:56 - 2009-07-14 06:45 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-15 09:56 - 2009-07-14 06:45 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-15 09:48 - 2013-01-07 20:04 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-15 09:47 - 2015-06-04 12:10 - 00013744 _____ C:\Windows\PFRO.log
2015-09-15 09:47 - 2015-06-03 13:04 - 00008748 _____ C:\Windows\setupact.log
2015-09-15 09:47 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-15 09:47 - 2009-07-14 06:45 - 00434304 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-15 09:43 - 2015-04-04 16:27 - 00000000 ___SD C:\Windows\system32\GWX
2015-09-15 09:43 - 2013-01-07 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-09-15 09:43 - 2013-01-07 11:20 - 00000000 ____D C:\Program Files\CCleaner
2015-09-15 09:43 - 2013-01-07 11:13 - 00000000 ____D C:\Windows\System32\Tasks\COMODO
2015-09-15 09:43 - 2012-12-24 16:07 - 00000000 ____D C:\Users\Lada
2015-09-15 09:43 - 2010-11-21 11:38 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-09-15 09:42 - 2013-01-21 22:18 - 00000000 ____D C:\Users\Lada\AppData\Roaming\Skype
2015-09-15 09:42 - 2013-01-10 06:29 - 00000000 ____D C:\Users\Lada\AppData\Local\Mozilla
2015-09-15 09:40 - 2013-10-27 09:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-09-15 09:40 - 2013-10-27 09:32 - 00000000 ____D C:\Program Files (x86)\Sony
2015-09-15 09:40 - 2012-12-15 10:22 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-15 09:39 - 2014-01-04 14:25 - 00000000 ____D C:\ProgramData\Sony Mobile
2015-09-15 09:39 - 2014-01-04 14:25 - 00000000 ____D C:\Program Files (x86)\Sony Mobile
2015-09-15 09:36 - 2013-01-07 20:04 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-15 09:30 - 2013-02-20 22:39 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-09-09 18:23 - 2015-02-08 10:22 - 00000000 ____D C:\Users\Lada\Desktop\Aleš
2015-09-09 17:55 - 2015-07-27 10:45 - 00000000 ____D C:\Users\Lada\Desktop\benatska noc 2015
2015-09-09 17:52 - 2010-11-21 11:27 - 00742398 _____ C:\Windows\system32\perfh005.dat
2015-09-09 17:52 - 2010-11-21 11:27 - 00195546 _____ C:\Windows\system32\perfc005.dat
2015-09-09 17:52 - 2009-07-14 07:13 - 01711684 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-05 17:46 - 2013-01-20 20:37 - 00000000 ____D C:\Users\Lada\AppData\Local\TempAdresářZálohySW
2015-09-05 16:25 - 2013-01-11 12:44 - 00000000 ____D C:\Users\Lada\AppData\Roaming\SolidWorks
2015-09-05 16:00 - 2013-01-07 20:05 - 00002201 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-03 13:52 - 2012-12-14 21:45 - 00579408 _____ (COMODO) C:\Windows\system32\guard64.dll
2015-09-03 13:52 - 2012-12-14 21:45 - 00445472 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll
2015-09-01 15:48 - 2013-03-24 01:37 - 00000000 ____D C:\Users\Lada\AppData\Roaming\vlc
2015-09-01 15:45 - 2013-03-24 01:37 - 00001082 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-09-01 15:03 - 2013-01-10 06:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-31 19:54 - 2013-01-07 20:04 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-31 19:54 - 2013-01-07 20:04 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-22 08:50 - 2013-01-07 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2015-08-21 20:45 - 2014-09-16 19:29 - 00002761 _____ C:\Users\Public\Desktop\Skype.lnk
2015-08-21 20:45 - 2013-01-21 22:18 - 00000000 ____D C:\ProgramData\Skype
2015-08-21 18:36 - 2015-07-10 15:22 - 00016930 _____ C:\Windows\DPINST.LOG
2015-08-17 20:27 - 2015-05-30 21:13 - 00003896 _____ C:\Windows\System32\Tasks\Program Manager
==================== Files in the root of some directories =======
2015-08-30 21:16 - 2015-08-30 21:16 - 6420480 _____ () C:\Program Files (x86)\GUT5EB1.tmp
2014-09-05 09:05 - 2014-09-05 09:05 - 0000000 _____ () C:\Users\Lada\AppData\Local\{49BCE388-C6BA-499E-B72B-74A26CC8713D}
Some files in TEMP:
====================
C:\Users\Lada\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Lada\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-03 21:23
Re: Prosím o kontrolu logu
Additional scan result of Farbar Recovery Scan Tool (x64) Version:14-09-2015
Ran by Lada (2015-09-15 10:15:21)
Running from C:\Users\Lada\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-12-24 14:07:56)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2831377403-1237323822-844494322-500 - Administrator - Disabled)
Guest (S-1-5-21-2831377403-1237323822-844494322-501 - Limited - Disabled)
Lada (S-1-5-21-2831377403-1237323822-844494322-1000 - Administrator - Enabled) => C:\Users\Lada
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: COMODO Antivirus (Enabled - Up to date) {F25D0092-CDBE-B303-ADB7-88DE8CDECCF5}
AS: Comodo Defense+ (Enabled - Up to date) {493CE176-EB84-BC8D-9707-B3ACF7598648}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: COMODO Firewall (Enabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKLM-x32\...\uTorrent) (Version: 3.1.0 - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
ARO 2013 (HKLM\...\ARO 2013_is1) (Version: 8.0 - Support.com)
ARO 2013 Toolbar (HKLM-x32\...\ARO_2013 Toolbar) (Version: 6.15.0.27 - ARO 2013)
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Battlefield 1942 (HKLM-x32\...\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}) (Version: - )
Battlefield 1942: Secret Weapons of WWII (HKLM-x32\...\{B73B4A99-4173-4747-BBEC-0F05E966F9D2}) (Version: - )
Battlefield 1942: The Road To Rome (HKLM-x32\...\{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 43.3.3.185 - Comodo)
COMODO Internet Security (HKLM\...\{0E9AFD45-C3BA-41D1-B54B-495A22CB3409}) (Version: 6.0.64131.2674 - COMODO Security Solutions Inc.)
CPUID CPU-Z 1.62 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0328 - DT Soft Ltd)
Eye 110 (HKLM-x32\...\{ED15D271-34AB-438C-BFDC-AE6F110ACCBB}) (Version: 1.0.4.20 - KYE)
GeekBuddy (HKLM-x32\...\{AA722B93-B5B3-48DE-912A-81C0926D22AE}) (Version: 4.21.144 - Comodo Security Solutions Inc)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2696 - Intel Corporation)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Media Go (HKLM-x32\...\{5C7025FD-6BD0-4E48-8948-696E26AF6F15}) (Version: 2.5.299 - Sony)
Media Go Video Playback Engine 1.120.101.05010 (HKLM-x32\...\{8227BCD8-AA43-B935-7134-2732A298364A}) (Version: 1.120.101.05010 - Sony)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2003 Web Components (HKLM-x32\...\{90120000-00A4-0409-0000-0000000FF1CE}) (Version: 12.0.6213.1000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (Czech) (HKLM-x32\...\{95120000-00AF-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (HKLM\...\Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU) (Version: - Microsoft Corporation)
Microsoft Visual Studio 2005 Tools for Applications - ENU (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Applications - ENU) (Version: - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 40.0.3 (x86 cs) (HKLM-x32\...\Mozilla Firefox 40.0.3 (x86 cs)) (Version: 40.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.3.5716 - Mozilla)
MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia)
Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.8.54.0 - Nokia)
Nokia Suite (x32 Version: 3.8.54.0 - Nokia) Hidden
Offroad (HKLM-x32\...\{29ED0BFC-FBC1-4498-AB5F-C63FCA6B736C}) (Version: - )
OnLine TV INTERNEXT 2000 2.0 (HKLM-x32\...\OnLine TV INTERNEXT 2000 2.0) (Version: 2.0 - INTERNEXT 2000 s.r.o.)
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
PCWheel (HKLM-x32\...\{B53FF0A4-886B-4193-A90A-C79B9A9BDC4F}) (Version: 1.0.0 - )
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.16.2.15545 - Sony Computer Entertainment Inc.)
PunkBuster for Battlefield 1942 (HKLM-x32\...\{127B684B-A002-44C8-99A7-6CF8F1E26873}) (Version: - )
REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0142 - REALTEK Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
SolidWorks 2013 x64 Czech Resources (Version: 21.100.5024 - SolidWorks Corporation) Hidden
SolidWorks 2013 x64 Edition SP0 (HKLM-x32\...\SolidWorks Installation Manager 20130-40000-1100-100) (Version: 21.0.0.5024 - SolidWorks Corporation)
SolidWorks 2013 x64 Edition SP0 (Version: 21.100.5024 - SolidWorks) Hidden
SolidWorks eDrawings 2013 x64 Edition SP0 (Version: 13.0.5016 - Společnost Dassault Systemes SolidWorks Corp) Hidden
SolidWorks Explorer 2013 SP0 x64 Edition (Version: 21.00.5024 - SolidWorks Corporation) Hidden
SolidWorks Plastics 2013 SP0 x64 Edition (Version: 21.00.5024 - SolidWorks Corporation) Hidden
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH)
Trust64 (HKLM\...\{26A9360B-837E-4E0F-9755-4D6F1038E718}) (Version: 1.00.0000 - Název společnosti:)
uTorrentControl_v2 Toolbar (HKLM-x32\...\uTorrentControl_v2 Toolbar) (Version: 6.9.0.16 - uTorrentControl_v2) <==== ATTENTION
VIA Platforma Ovladače zařízení (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
19-08-2015 13:19:00 Windows Update
03-09-2015 21:31:16 Naplánovaný kontrolní bod
09-09-2015 22:29:15 Windows Update
15-09-2015 09:19:04 Removed Skype Click to Call
15-09-2015 09:30:09 Removed Skype Click to Call
15-09-2015 09:34:55 Removed IObit Apps Toolbar v22.1.
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2015-09-15 09:18 - 00000828 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {146D3E41-6132-4EA5-B18D-8BDD5A901089} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-09] (COMODO)
Task: {18F020F0-C684-4362-8AE7-33045EAA49E5} - System32\Tasks\Program Manager => C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe
Task: {2C89ACAB-7C54-4AD2-82E2-FF200920D384} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {3909E9C6-66A8-429D-BA53-E0C708CBCBF6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {50A165B8-5EDA-46FA-8B1C-A46F838F4EEC} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {69E8E8E3-D62C-474F-BF90-06955304F690} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated)
Task: {6D13D3B8-DDC0-4B11-89AE-E1870BC2F9D0} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-09] (COMODO)
Task: {6FA89AE4-1A85-4FE8-9E0F-40BF22266654} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {73E5F409-5908-436E-A953-4BB4C129F6D1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-17] (Adobe Systems Incorporated)
Task: {9F943BEE-1B56-4827-98BB-941E3D2A6E1F} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {CBB04929-1717-4AEA-8848-5E7AA978DB7C} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-08-09] (COMODO)
Task: {CC8F7958-5B1F-4AE9-A987-FED97B7C4A89} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-09] (COMODO)
Task: {EFD9363C-171C-4EAE-82C3-E94986C74F51} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-13] (Piriform Ltd)
Task: {F56DB788-4103-4A6E-BC8A-3E79184D1518} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-09] (COMODO)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\office.odf
2012-12-15 09:55 - 2012-03-19 15:09 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-12-14 21:46 - 2015-01-09 00:02 - 00067808 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav
2015-04-08 21:53 - 2015-04-08 21:53 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2012-09-28 06:50 - 2012-09-28 06:50 - 00272488 _____ () C:\Program Files\SolidWorks Corp\SolidWorks\sldBodyDiffu.dll
2012-12-15 10:21 - 2012-01-12 15:21 - 00078448 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2012-12-15 10:21 - 2012-01-12 15:21 - 00386160 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2013-01-08 19:21 - 2009-12-09 22:20 - 00126976 _____ () C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 08507232 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtGui4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 02354016 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtCore4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 01014624 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtNetwork4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00364384 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtXml4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 02480992 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtDeclarative4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 01346912 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtScript4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00206176 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtSql4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 02653024 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtXmlPatterns4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00033120 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\imageformats\qgif4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00035680 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\imageformats\qico4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00207200 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\imageformats\qjpeg4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 11166560 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtWebKit4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00276832 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\phonon4.dll
2014-11-11 10:21 - 2014-11-11 10:21 - 00392552 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\ssoengine.dll
2014-11-11 10:21 - 2014-11-11 10:21 - 00059752 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\securestorage.dll
2014-11-19 12:47 - 2014-11-19 12:47 - 00438624 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\NService.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00446304 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00520544 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtMultimediaKit1.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00720736 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtOpenGL4.dll
2014-11-19 12:46 - 2014-11-19 12:46 - 00606560 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\CommonUpdateChecker.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00093024 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\qjson.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\office.odf
2015-09-05 16:00 - 2015-08-28 02:17 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libglesv2.dll
2015-09-05 16:00 - 2015-08-28 02:17 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Windows\notepad.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aaclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\acmigration.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\advapi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aelupsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aepdu.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\apisetschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\apphelp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidcertstorecheck.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidpolicyconverter.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\audiodg.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\auditpol.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\basesrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\blackbox.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\certcli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cewmdm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\clfs.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\comctl32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CompatTelRunner.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\conhost.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\consent.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\credssp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptbase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptnet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptsp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3d10warp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\davclnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dciman32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\diagtrack.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\diskperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\drmmgrtn.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\drmv2clt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\DWrite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxmasf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxtmsft.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\evr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\FntCache.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\fontsub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ie4uinit.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieapfltr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\iedkcs32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieetwcollector.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieetwcollectorres.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieetwproxystub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\iernonce.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\iesetup.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID
AlternateDataStreams: C:\Windows\system32\InkEd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\JavaScriptCollectionAgent.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jnwmon.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jscript9diag.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jsproxy.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\kernel32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\logman.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\lpk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mcupdate_GenuineIntel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mferror.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfplat.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfpmp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msdxm.ocx:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MshtmlDac.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mshtmlmedia.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msiexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msihnd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msimsg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msmmsp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msnetobj.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msobjs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msrating.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msscp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MsSpellCheckingFacility.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml3r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml6r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\notepad.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ole32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\oleaut32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcadm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcaevts.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcalua.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcasvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcawrk.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\perftrack.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\powertracker.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rdpcorets.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\RdpGroupPolicyExtension.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rdpudd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\relog.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rrinstaller.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\scesrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sdbinst.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sechost.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\setbcdlocale.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\shimeng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\spwmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sspisrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sysmain.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\To32Bits.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\To64Bits.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tracerpt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tsgqec.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\typeperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ubpm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\UtcResources.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wdi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WebClnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wininet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winload.efi:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winload.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wmdrmsdk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WMPhoto.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wow64cpu.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wow64win.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wu.upgrade.ps.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuapp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wucltux.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WUDFUpdate_01009.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wudriver.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuwebv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\aaclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\adtschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\advapi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ALFASVR.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\apisetschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\apphelp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\appidapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AshuDrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\atmfd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\atmlib.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AudioEng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\auditpol.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\blackbox.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\certcli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cewmdm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\credssp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptbase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptnet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptsp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3d10warp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\davclnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dciman32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\diskperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\drmmgrtn.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\drmv2clt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\DWrite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxmasf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxtmsft.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxtrans.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\evr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\fontsub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\gdi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieapfltr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\iedkcs32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieetwproxystub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieframe.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\iernonce.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\iertutil.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\iesetup.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\inetcpl.cpl:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\InkEd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\java.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\javaw.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\javaws.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jscript9.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jscript9diag.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jsproxy.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\kernel32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\logman.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\lpk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mferror.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mfplat.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mfpmp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msaudite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msdxm.ocx:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msfeeds.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\MshtmlDac.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mshtmled.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mshtmlmedia.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msiexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msihnd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msimsg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msnetobj.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msobjs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msrating.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msscp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml3r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml6r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\notepad.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntvdm64.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ole32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\oleaut32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\relog.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\rpcrt4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\rrinstaller.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\scesrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\sdbinst.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\sechost.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\secur32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\setup16.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\shimeng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\spwmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tracerpt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tsgqec.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\typeperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ubpm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\urlmon.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\vbscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wdi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wdigest.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WebClnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WindowsCodecs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wininet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wmdrmsdk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wmploc.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wpdshext.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wuapp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wudriver.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wuwebv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\appid.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\cng.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mountmgr.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\PEAuth.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\stream.sys:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Desktop\adwcleaner_5.007.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Desktop\adwcleaner_5.007.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Desktop\FRST64.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Desktop\FRST64.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Desktop\SKMBT_C22015030215110.pdf:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Desktop\SKMBT_C22015030215110.pdf:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\11353911_973205182711050_1214935084_o.jpg:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\11353911_973205182711050_1214935084_o.jpg:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\12933_07.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\12933_07.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\12933_08.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\12933_08.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\AC-DC---Rock-Or-Bust-(2014).rar:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\AC-DC---Rock-Or-Bust-(2014).rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\automatickevypnutipc2.0.0.zip:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\automatickevypnutipc2.0.0.zip:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\BF1942_16_CZ.rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup501.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup502.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup504.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup505.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup505.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\doc00143120150624222651.pdf:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Europe---War-of-Kings-(2015)-[Deluxe-Edition]---Rožmberský-rytíř.rar:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Europe---War-of-Kings-(2015)-[Deluxe-Edition]---Rožmberský-rytíř.rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Hvězdy-nám-nepřály-CZ.avi:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Hvězdy-nám-nepřály-CZ.avi:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Image4.bmp:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Image6.bmp:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Image6.bmp:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Kr_de__auta_an_ln_m_vzru_ovadlem.avi:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Kr_de__auta_an_ln_m_vzru_ovadlem.avi:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Movements.csv:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Movements.csv:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Nightwish---Elan-[2015]-[320].rar:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Nightwish---Elan-[2015]-[320].rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Serious-Black---As-Daylight-Breaks-2015-by-masterblaster4.rar:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Serious-Black---As-Daylight-Breaks-2015-by-masterblaster4.rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\STM_CZ6506000000000212688708_20140709_2014000006.PDF:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\STM_CZ6506000000000212688708_20140709_2014000006.PDF:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\tun234.zip:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\tun234.zip:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Documents\vlc-2.1.5-win32.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Documents\vlc-2.2.1-win32.exe:$CmdTcID
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\100sexlinks.com -> 100sexlinks.com
There are 4788 more restricted sites.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Pozadí plochy.bmp
DNS Servers: 212.111.0.10 - 194.213.32.237
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [{BE73C099-946C-49D6-952D-10E13F746E51}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3AB1AD7D-9837-409C-991E-5F1DBC43B2C9}] => (Allow) LPort=2869
FirewallRules: [{F49ED803-32E7-4E0B-AA8B-4E53B6CCAFE9}] => (Allow) LPort=1900
FirewallRules: [{8CEB1ADD-5609-476C-B211-00BB18D0E8B9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{9E0F55A6-2397-45C4-97F7-ABF0A18B013E}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{48CF776E-32D1-4799-BD77-7EC35DCF0B80}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
FirewallRules: [{537BB7BF-686D-42EB-BF2B-61C98D0D930C}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
FirewallRules: [{4F4436E7-8C1C-4B53-B29D-5383A4BA5E0F}] => (Allow) LPort=1542
FirewallRules: [{B183F768-7D7D-4AD5-8DCE-3818E3C9F1C3}] => (Allow) LPort=1542
FirewallRules: [{61060105-11BE-4B1D-9A89-6815776DC7C8}] => (Allow) LPort=53
FirewallRules: [{D173B0B5-AC4B-42A6-A348-4F4440518FB3}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{D09245C2-A090-4F3D-A63D-6DB036DA207D}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{4981A2DE-102B-4BD2-9CC7-6146A6F84B03}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{94811557-88CB-4261-8FC4-9470C078A733}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{D3B5D9F4-73CA-43F0-AE4E-CE63A78C9C8F}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{203060CC-E5CB-4CC5-A01F-2F1C152E42FF}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{91A749D6-1B70-46ED-9391-FD4D8C831949}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{07C1508A-B85E-4349-9AA7-90172F2F803F}] => (Allow) C:\Program Files (x86)\Common Files\Comodo\GeekBuddyRSP.exe
FirewallRules: [{B63065BC-E40C-40B6-B475-EAC74C4907E9}] => (Allow) C:\Program Files (x86)\Common Files\Comodo\GeekBuddyRSP.exe
FirewallRules: [{B985CA46-1C6B-4AC3-8F81-BB5354310C0E}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
FirewallRules: [{956FE67D-1D27-4253-82D4-A6EF71EEAAE2}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
FirewallRules: [{D9591710-541D-481C-9A56-99BA85BAE59F}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360.exe
FirewallRules: [{FF327AA3-A32A-45CE-8F3A-27CA988B49CC}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360.exe
FirewallRules: [{1863F1F1-C23E-4B29-8D4C-A487D6CE9059}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360_cl.exe
FirewallRules: [{28569471-1D31-4AD0-94C1-10F76EE00B38}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360_cl.exe
FirewallRules: [{39307D8F-A670-4875-AF00-25FF6D9D68C8}] => (Allow) C:\Program Files (x86)\nokia\nokia suite\nokiasuite.exe
FirewallRules: [{29F16449-4E68-4051-A03F-6FED6325208E}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe
FirewallRules: [{F10800EE-6756-42A1-90CE-E427CBF539D4}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe
FirewallRules: [{2A7DDAB2-DC52-4CDE-8F1E-986F1FDAE3DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe
FirewallRules: [{450E7BEE-4B21-4DC6-8DD0-9F3EB17E10DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe
FirewallRules: [{F3D9292D-B5CD-4C90-A555-8B868FC2B401}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe
FirewallRules: [{0963FFB1-B8F7-47D8-B0D9-63C4510994B7}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe
FirewallRules: [{12CCA574-1522-4A9D-8CFA-F316C5F803B4}] => (Allow) C:\Program Files (x86)\nokia\nokia suite\nokiasuite.exe
FirewallRules: [{49C238E6-DC14-4ADB-A24F-1DCBDDFF6A2A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{AFC7B2D0-2892-495A-B64B-88D6FE870AAE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0D50225C-8FFA-4569-8D66-0D0AA85CDC67}] => (Allow) C:\Program Files (x86)\nokia\nokia suite\nokiasuite.exe
FirewallRules: [{02157273-00E2-42AF-B8B2-5102BC11A76B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
Name: Microsoft ISATAP Adapter #2
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Microsoft ISATAP Adapter
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/15/2015 09:49:20 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/15/2015 09:40:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: setup.exe_Sony PC Companion, verze: 17.0.0.717, časové razítko: 0x4cab8cfa
Název chybujícího modulu: DownloadManager.dll_unloaded, verze: 0.0.0.0, časové razítko: 0x53be652d
Kód výjimky: 0xc0000005
Posun chyby: 0x6cf246f0
ID chybujícího procesu: 0x6d8
Čas spuštění chybující aplikace: 0xsetup.exe_Sony PC Companion0
Cesta k chybující aplikaci: setup.exe_Sony PC Companion1
Cesta k chybujícímu modulu: setup.exe_Sony PC Companion2
ID zprávy: setup.exe_Sony PC Companion3
Error: (09/15/2015 09:32:43 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program IEXPLORE.EXE verze 11.0.9600.17937 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: 1924
Čas spuštění: 01d0ef8896f2fec6
Čas ukončení: 19
Cesta k aplikaci: C:\Program Files\Internet Explorer\IEXPLORE.EXE
ID hlášení: e75eea46-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:29:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0x1aa0
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (09/15/2015 09:28:26 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Explorer.EXE verze 6.1.7601.17567 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: 7bc
Čas spuštění: 01d0ef857c503495
Čas ukončení: 0
Cesta k aplikaci: C:\Windows\Explorer.EXE
ID hlášení:
Error: (09/15/2015 09:28:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0x1320
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (09/15/2015 09:27:32 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Skype.exe verze 7.8.64.102 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: fcc
Čas spuštění: 01d0ef8589154113
Čas ukončení: 24
Cesta k aplikaci: C:\Program Files (x86)\Skype\Phone\Skype.exe
ID hlášení:
Error: (09/15/2015 09:27:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0xf64
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (09/15/2015 09:14:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0x17d8
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (09/15/2015 09:14:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0xbd8
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
System errors:
=============
Error: (09/15/2015 09:47:55 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
CFRMD
Error: (09/15/2015 09:46:49 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správce služeb se pokusil o opravnou akci (Restartovat službu) po nečekaném ukončení služby Windows Search, ale tato akce selhala kvůli následující chybě:
%%1056
Error: (09/15/2015 09:46:20 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Ochrana softwaru byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba modulů systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba ServiceLayer byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Live ID Sign-in Assistant byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba VIA Karaoke digital mixer Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Realtek11nSU byla neočekávaně ukončena. Tento stav nastal již 1krát.
Microsoft Office:
=========================
Error: (09/15/2015 09:49:20 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/15/2015 09:40:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: setup.exe_Sony PC Companion17.0.0.7174cab8cfaDownloadManager.dll_unloaded0.0.0.053be652dc00000056cf246f06d801d0ef89c12dad7bC:\Users\Lada\AppData\Local\Temp\{0692A097-3C39-49B6-8BF4-37F8B201995E}\setup.exeDownloadManager.dll189fcbce-5b7d-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:32:43 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17937192401d0ef8896f2fec619C:\Program Files\Internet Explorer\IEXPLORE.EXEe75eea46-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:29:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e2501aa001d0ef883025444bC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll76b89882-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:28:26 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Explorer.EXE6.1.7601.175677bc01d0ef857c5034950C:\Windows\Explorer.EXE
Error: (09/15/2015 09:28:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e250132001d0ef880719017dC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll4a8dcbf3-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:27:32 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Skype.exe7.8.64.102fcc01d0ef858915411324C:\Program Files (x86)\Skype\Phone\Skype.exe
Error: (09/15/2015 09:27:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e250f6401d0ef87e1f021f3C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll39c3c2a4-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:14:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e25017d801d0ef862691da22C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll6c0a1d44-5b79-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:14:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e250bd801d0ef8614a96451C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll56e13d53-5b79-11e5-a11b-50465d8c1eac
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) CPU G645 @ 2.90GHz
Percentage of memory in use: 28%
Total physical RAM: 7881.84 MB
Available physical RAM: 5603 MB
Total Virtual: 15761.89 MB
Available Virtual: 13137.96 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:923.69 GB) (Free:445.3 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Offroad) (CDROM) (Total:0.29 GB) (Free:0 GB) CDFS
Drive e: (CANON_DC) (Removable) (Total:1.89 GB) (Free:0.2 GB) FAT
Drive i: (SolidWorks1) (CDROM) (Total:6.2 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 5EDA6502)
Partition 1: (Active) - (Size=923.7 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=7.8 GB) - (Type=27)
========================================================
Disk: 1 (Size: 1.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
Ran by Lada (2015-09-15 10:15:21)
Running from C:\Users\Lada\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-12-24 14:07:56)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2831377403-1237323822-844494322-500 - Administrator - Disabled)
Guest (S-1-5-21-2831377403-1237323822-844494322-501 - Limited - Disabled)
Lada (S-1-5-21-2831377403-1237323822-844494322-1000 - Administrator - Enabled) => C:\Users\Lada
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: COMODO Antivirus (Enabled - Up to date) {F25D0092-CDBE-B303-ADB7-88DE8CDECCF5}
AS: Comodo Defense+ (Enabled - Up to date) {493CE176-EB84-BC8D-9707-B3ACF7598648}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: COMODO Firewall (Enabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKLM-x32\...\uTorrent) (Version: 3.1.0 - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
ARO 2013 (HKLM\...\ARO 2013_is1) (Version: 8.0 - Support.com)
ARO 2013 Toolbar (HKLM-x32\...\ARO_2013 Toolbar) (Version: 6.15.0.27 - ARO 2013)
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) (HKLM\...\62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F) (Version: 05/31/2012 7.1.2.0 - Nokia)
Battlefield 1942 (HKLM-x32\...\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}) (Version: - )
Battlefield 1942: Secret Weapons of WWII (HKLM-x32\...\{B73B4A99-4173-4747-BBEC-0F05E966F9D2}) (Version: - )
Battlefield 1942: The Road To Rome (HKLM-x32\...\{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Comodo Dragon (HKLM-x32\...\Comodo Dragon) (Version: 43.3.3.185 - Comodo)
COMODO Internet Security (HKLM\...\{0E9AFD45-C3BA-41D1-B54B-495A22CB3409}) (Version: 6.0.64131.2674 - COMODO Security Solutions Inc.)
CPUID CPU-Z 1.62 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0328 - DT Soft Ltd)
Eye 110 (HKLM-x32\...\{ED15D271-34AB-438C-BFDC-AE6F110ACCBB}) (Version: 1.0.4.20 - KYE)
GeekBuddy (HKLM-x32\...\{AA722B93-B5B3-48DE-912A-81C0926D22AE}) (Version: 4.21.144 - Comodo Security Solutions Inc)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2696 - Intel Corporation)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Media Go (HKLM-x32\...\{5C7025FD-6BD0-4E48-8948-696E26AF6F15}) (Version: 2.5.299 - Sony)
Media Go Video Playback Engine 1.120.101.05010 (HKLM-x32\...\{8227BCD8-AA43-B935-7134-2732A298364A}) (Version: 1.120.101.05010 - Sony)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office 2003 Web Components (HKLM-x32\...\{90120000-00A4-0409-0000-0000000FF1CE}) (Version: 12.0.6213.1000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (Czech) (HKLM-x32\...\{95120000-00AF-0405-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU (HKLM\...\Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU) (Version: - Microsoft Corporation)
Microsoft Visual Studio 2005 Tools for Applications - ENU (HKLM-x32\...\Microsoft Visual Studio 2005 Tools for Applications - ENU) (Version: - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 40.0.3 (x86 cs) (HKLM-x32\...\Mozilla Firefox 40.0.3 (x86 cs)) (Version: 40.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.3.5716 - Mozilla)
MSVC80_x64_v2 (Version: 1.0.3.0 - Nokia) Hidden
MSVC80_x86_v2 (x32 Version: 1.0.3.0 - Nokia) Hidden
MSVC90_x64 (Version: 1.0.1.2 - Nokia) Hidden
MSVC90_x86 (x32 Version: 1.0.1.2 - Nokia) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nokia Connectivity Cable Driver (HKLM-x32\...\{29373274-977E-413C-A4DE-DC0F8E80C429}) (Version: 7.1.172.0 - Nokia)
Nokia Suite (HKLM-x32\...\Nokia Suite) (Version: 3.8.54.0 - Nokia)
Nokia Suite (x32 Version: 3.8.54.0 - Nokia) Hidden
Offroad (HKLM-x32\...\{29ED0BFC-FBC1-4498-AB5F-C63FCA6B736C}) (Version: - )
OnLine TV INTERNEXT 2000 2.0 (HKLM-x32\...\OnLine TV INTERNEXT 2000 2.0) (Version: 2.0 - INTERNEXT 2000 s.r.o.)
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
PC Connectivity Solution (HKLM-x32\...\{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}) (Version: 12.0.109.0 - Nokia)
PCWheel (HKLM-x32\...\{B53FF0A4-886B-4193-A90A-C79B9A9BDC4F}) (Version: 1.0.0 - )
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
PlayStation(R)Store (HKLM-x32\...\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}) (Version: 4.16.2.15545 - Sony Computer Entertainment Inc.)
PunkBuster for Battlefield 1942 (HKLM-x32\...\{127B684B-A002-44C8-99A7-6CF8F1E26873}) (Version: - )
REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0142 - REALTEK Semiconductor Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
SolidWorks 2013 x64 Czech Resources (Version: 21.100.5024 - SolidWorks Corporation) Hidden
SolidWorks 2013 x64 Edition SP0 (HKLM-x32\...\SolidWorks Installation Manager 20130-40000-1100-100) (Version: 21.0.0.5024 - SolidWorks Corporation)
SolidWorks 2013 x64 Edition SP0 (Version: 21.100.5024 - SolidWorks) Hidden
SolidWorks eDrawings 2013 x64 Edition SP0 (Version: 13.0.5016 - Společnost Dassault Systemes SolidWorks Corp) Hidden
SolidWorks Explorer 2013 SP0 x64 Edition (Version: 21.00.5024 - SolidWorks Corporation) Hidden
SolidWorks Plastics 2013 SP0 x64 Edition (Version: 21.00.5024 - SolidWorks Corporation) Hidden
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH)
Trust64 (HKLM\...\{26A9360B-837E-4E0F-9755-4D6F1038E718}) (Version: 1.00.0000 - Název společnosti:)
uTorrentControl_v2 Toolbar (HKLM-x32\...\uTorrentControl_v2 Toolbar) (Version: 6.9.0.16 - uTorrentControl_v2) <==== ATTENTION
VIA Platforma Ovladače zařízení (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3502.0922 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
19-08-2015 13:19:00 Windows Update
03-09-2015 21:31:16 Naplánovaný kontrolní bod
09-09-2015 22:29:15 Windows Update
15-09-2015 09:19:04 Removed Skype Click to Call
15-09-2015 09:30:09 Removed Skype Click to Call
15-09-2015 09:34:55 Removed IObit Apps Toolbar v22.1.
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2015-09-15 09:18 - 00000828 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {146D3E41-6132-4EA5-B18D-8BDD5A901089} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-09] (COMODO)
Task: {18F020F0-C684-4362-8AE7-33045EAA49E5} - System32\Tasks\Program Manager => C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe
Task: {2C89ACAB-7C54-4AD2-82E2-FF200920D384} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {3909E9C6-66A8-429D-BA53-E0C708CBCBF6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {50A165B8-5EDA-46FA-8B1C-A46F838F4EEC} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {69E8E8E3-D62C-474F-BF90-06955304F690} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated)
Task: {6D13D3B8-DDC0-4B11-89AE-E1870BC2F9D0} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-09] (COMODO)
Task: {6FA89AE4-1A85-4FE8-9E0F-40BF22266654} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {73E5F409-5908-436E-A953-4BB4C129F6D1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-17] (Adobe Systems Incorporated)
Task: {9F943BEE-1B56-4827-98BB-941E3D2A6E1F} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {CBB04929-1717-4AEA-8848-5E7AA978DB7C} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-08-09] (COMODO)
Task: {CC8F7958-5B1F-4AE9-A987-FED97B7C4A89} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-09] (COMODO)
Task: {EFD9363C-171C-4EAE-82C3-E94986C74F51} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-13] (Piriform Ltd)
Task: {F56DB788-4103-4A6E-BC8A-3E79184D1518} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-09] (COMODO)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\office.odf
2012-12-15 09:55 - 2012-03-19 15:09 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2012-12-14 21:46 - 2015-01-09 00:02 - 00067808 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav
2015-04-08 21:53 - 2015-04-08 21:53 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2012-09-28 06:50 - 2012-09-28 06:50 - 00272488 _____ () C:\Program Files\SolidWorks Corp\SolidWorks\sldBodyDiffu.dll
2012-12-15 10:21 - 2012-01-12 15:21 - 00078448 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2012-12-15 10:21 - 2012-01-12 15:21 - 00386160 _____ () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2013-01-08 19:21 - 2009-12-09 22:20 - 00126976 _____ () C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 08507232 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtGui4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 02354016 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtCore4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 01014624 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtNetwork4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00364384 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtXml4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 02480992 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtDeclarative4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 01346912 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtScript4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00206176 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtSql4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 02653024 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtXmlPatterns4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00033120 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\imageformats\qgif4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00035680 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\imageformats\qico4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00207200 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\imageformats\qjpeg4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 11166560 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtWebKit4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00276832 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\phonon4.dll
2014-11-11 10:21 - 2014-11-11 10:21 - 00392552 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\ssoengine.dll
2014-11-11 10:21 - 2014-11-11 10:21 - 00059752 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\securestorage.dll
2014-11-19 12:47 - 2014-11-19 12:47 - 00438624 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\NService.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00446304 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\sqldrivers\qsqlite4.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00520544 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtMultimediaKit1.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00720736 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\QtOpenGL4.dll
2014-11-19 12:46 - 2014-11-19 12:46 - 00606560 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\CommonUpdateChecker.dll
2014-11-19 12:48 - 2014-11-19 12:48 - 00093024 _____ () C:\Program Files (x86)\Nokia\Nokia Suite\qjson.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\Cultures\office.odf
2015-09-05 16:00 - 2015-08-28 02:17 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libglesv2.dll
2015-09-05 16:00 - 2015-08-28 02:17 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Windows\notepad.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aaclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\acmigration.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\advapi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aelupsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aepdu.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\apisetschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\apphelp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidcertstorecheck.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidpolicyconverter.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appidsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appinfo.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\atmfd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\atmlib.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\audiodg.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\AudioEng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\AUDIOKSE.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\AudioSes.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\audiosrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\auditpol.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\authui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\basesrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\blackbox.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\certcli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cewmdm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\clfs.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\comctl32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\CompatTelRunner.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\conhost.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\consent.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\credssp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\crypt32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptbase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptnet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptsp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\cryptui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\d3d10warp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\davclnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dciman32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\diagtrack.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\diskperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\drmmgrtn.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\drmv2clt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\DWrite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxmasf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxtmsft.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\dxtrans.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\EncDump.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\evr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\FntCache.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\fontsub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ie4uinit.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieapfltr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\iedkcs32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieetwcollector.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieetwcollectorres.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieetwproxystub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieframe.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\iernonce.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\iertutil.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\iesetup.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\inetcpl.cpl:$CmdTcID
AlternateDataStreams: C:\Windows\system32\InkEd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\JavaScriptCollectionAgent.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jnwmon.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jscript9.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jscript9diag.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\jsproxy.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\kernel32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\logman.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\lpk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mcupdate_GenuineIntel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mferror.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfplat.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfpmp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mfps.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msctf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msdxm.ocx:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msfeeds.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MshtmlDac.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mshtmled.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mshtmlmedia.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msiexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msihnd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msimsg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msmmsp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msnetobj.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msobjs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msrating.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msscp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\MsSpellCheckingFacility.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\mstscax.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml3r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\msxml6r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\nlasvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\notepad.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ole32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\oleaut32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcadm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcaevts.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcalua.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcasvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\pcawrk.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\perftrack.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\powertracker.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\profsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\qdvd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\quartz.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rdpcorets.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\RdpGroupPolicyExtension.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rdpudd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\relog.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rpcrt4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rrinstaller.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\scesrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sdbinst.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sechost.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\services.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\setbcdlocale.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\shell32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\shimeng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\spwmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sspisrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\sysmain.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tdh.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\To32Bits.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\To64Bits.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tracerpt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\tsgqec.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\TSWbPrxy.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\typeperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\ubpm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\urlmon.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\UtcResources.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\vbscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wdi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WebClnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\win32k.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WindowsCodecs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wininet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winload.efi:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winload.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winresume.efi:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wintrust.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wmdrmsdk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WMPhoto.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wmploc.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wow64cpu.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wow64win.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wu.upgrade.ps.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuapp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wucltux.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\WUDFUpdate_01009.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wudriver.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\wuwebv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\aaclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\adtschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\advapi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ALFASVR.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\apisetschema.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\apphelp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\appidapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AshuDrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\atmfd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\atmlib.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AudioEng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AUDIOKSE.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\AudioSes.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\auditpol.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\authui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\blackbox.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\certcli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cewmdm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\comctl32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\credssp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\crypt32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptbase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptnet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptsp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptsvc.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\cryptui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\d3d10warp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\davclnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dciman32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\diskperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\drmmgrtn.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\drmv2clt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\DWrite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxmasf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxtmsft.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\dxtrans.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\evr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\FlashPlayerApp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\fontsub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\gdi32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieapfltr.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\iedkcs32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieetwproxystub.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieframe.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\iernonce.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\iertutil.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\iesetup.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieui.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ieUnatt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\inetcpl.cpl:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\InkEd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\java.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\javaw.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\javaws.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jscript9.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jscript9diag.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\jsproxy.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\kernel32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\logman.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\lpk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mferror.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mfplat.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mfpmp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mfps.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msaudite.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msctf.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msdxm.ocx:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msfeeds.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\MshtmlDac.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mshtmled.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mshtmlmedia.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msiexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msihnd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msimsg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msnetobj.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msobjs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msrating.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msscp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\mstscax.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml3r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml6.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\msxml6r.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ncsi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\nlaapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\notepad.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ntvdm64.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ole32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\oleaut32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\poqexec.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\qdvd.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\quartz.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\relog.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\rpcrt4.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\rrinstaller.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\scesrv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\sdbinst.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\sechost.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\secur32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\setup16.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\shell32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\shimeng.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\spwmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tdh.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tracerpt.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\tsgqec.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\typeperf.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\ubpm.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\urlmon.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\vbscript.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wdi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wdigest.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WebClnt.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WindowsCodecs.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wininet.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wintrust.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wmdrmsdk.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wmp.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\WMPhoto.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wmploc.DLL:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wpdshext.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wuapp.exe:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wudriver.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID
AlternateDataStreams: C:\Windows\SysWOW64\wuwebv.dll:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\appid.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\cng.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mountmgr.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxdav.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb10.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\mrxsmb20.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\PEAuth.sys:$CmdTcID
AlternateDataStreams: C:\Windows\system32\Drivers\stream.sys:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Desktop\adwcleaner_5.007.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Desktop\adwcleaner_5.007.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Desktop\FRST64.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Desktop\FRST64.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Desktop\SKMBT_C22015030215110.pdf:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Desktop\SKMBT_C22015030215110.pdf:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\11353911_973205182711050_1214935084_o.jpg:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\11353911_973205182711050_1214935084_o.jpg:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\12933_07.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\12933_07.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\12933_08.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\12933_08.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\AC-DC---Rock-Or-Bust-(2014).rar:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\AC-DC---Rock-Or-Bust-(2014).rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\automatickevypnutipc2.0.0.zip:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\automatickevypnutipc2.0.0.zip:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\BF1942_16_CZ.rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup501.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup502.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup504.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup505.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\ccsetup505.exe:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\doc00143120150624222651.pdf:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Europe---War-of-Kings-(2015)-[Deluxe-Edition]---Rožmberský-rytíř.rar:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Europe---War-of-Kings-(2015)-[Deluxe-Edition]---Rožmberský-rytíř.rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Hvězdy-nám-nepřály-CZ.avi:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Hvězdy-nám-nepřály-CZ.avi:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Image4.bmp:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Image6.bmp:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Image6.bmp:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Kr_de__auta_an_ln_m_vzru_ovadlem.avi:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Kr_de__auta_an_ln_m_vzru_ovadlem.avi:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Movements.csv:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Movements.csv:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Nightwish---Elan-[2015]-[320].rar:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Nightwish---Elan-[2015]-[320].rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\Serious-Black---As-Daylight-Breaks-2015-by-masterblaster4.rar:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\Serious-Black---As-Daylight-Breaks-2015-by-masterblaster4.rar:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\STM_CZ6506000000000212688708_20140709_2014000006.PDF:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\STM_CZ6506000000000212688708_20140709_2014000006.PDF:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Downloads\tun234.zip:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Downloads\tun234.zip:$CmdZnID
AlternateDataStreams: C:\Users\Lada\Documents\vlc-2.1.5-win32.exe:$CmdTcID
AlternateDataStreams: C:\Users\Lada\Documents\vlc-2.2.1-win32.exe:$CmdTcID
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\100sexlinks.com -> 100sexlinks.com
There are 4788 more restricted sites.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Pozadí plochy.bmp
DNS Servers: 212.111.0.10 - 194.213.32.237
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [VirtualPC-In-UDP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-UDP-2] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [VirtualPC-In-TCP-1] => (Allow) %SystemRoot%\System32\vpc.exe
FirewallRules: [{BE73C099-946C-49D6-952D-10E13F746E51}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3AB1AD7D-9837-409C-991E-5F1DBC43B2C9}] => (Allow) LPort=2869
FirewallRules: [{F49ED803-32E7-4E0B-AA8B-4E53B6CCAFE9}] => (Allow) LPort=1900
FirewallRules: [{8CEB1ADD-5609-476C-B211-00BB18D0E8B9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{9E0F55A6-2397-45C4-97F7-ABF0A18B013E}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{48CF776E-32D1-4799-BD77-7EC35DCF0B80}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
FirewallRules: [{537BB7BF-686D-42EB-BF2B-61C98D0D930C}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
FirewallRules: [{4F4436E7-8C1C-4B53-B29D-5383A4BA5E0F}] => (Allow) LPort=1542
FirewallRules: [{B183F768-7D7D-4AD5-8DCE-3818E3C9F1C3}] => (Allow) LPort=1542
FirewallRules: [{61060105-11BE-4B1D-9A89-6815776DC7C8}] => (Allow) LPort=53
FirewallRules: [{D173B0B5-AC4B-42A6-A348-4F4440518FB3}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{D09245C2-A090-4F3D-A63D-6DB036DA207D}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{4981A2DE-102B-4BD2-9CC7-6146A6F84B03}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{94811557-88CB-4261-8FC4-9470C078A733}] => (Allow) C:\Windows\System32\dmwu.exe
FirewallRules: [{D3B5D9F4-73CA-43F0-AE4E-CE63A78C9C8F}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{203060CC-E5CB-4CC5-A01F-2F1C152E42FF}] => (Allow) C:\Windows\System32\ARFC\wrtc.exe
FirewallRules: [{91A749D6-1B70-46ED-9391-FD4D8C831949}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{07C1508A-B85E-4349-9AA7-90172F2F803F}] => (Allow) C:\Program Files (x86)\Common Files\Comodo\GeekBuddyRSP.exe
FirewallRules: [{B63065BC-E40C-40B6-B475-EAC74C4907E9}] => (Allow) C:\Program Files (x86)\Common Files\Comodo\GeekBuddyRSP.exe
FirewallRules: [{B985CA46-1C6B-4AC3-8F81-BB5354310C0E}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
FirewallRules: [{956FE67D-1D27-4253-82D4-A6EF71EEAAE2}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
FirewallRules: [{D9591710-541D-481C-9A56-99BA85BAE59F}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360.exe
FirewallRules: [{FF327AA3-A32A-45CE-8F3A-27CA988B49CC}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360.exe
FirewallRules: [{1863F1F1-C23E-4B29-8D4C-A487D6CE9059}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360_cl.exe
FirewallRules: [{28569471-1D31-4AD0-94C1-10F76EE00B38}] => (Allow) C:\Program Files\SolidWorks Corp\SolidWorks\photoview\photoview360_cl.exe
FirewallRules: [{39307D8F-A670-4875-AF00-25FF6D9D68C8}] => (Allow) C:\Program Files (x86)\nokia\nokia suite\nokiasuite.exe
FirewallRules: [{29F16449-4E68-4051-A03F-6FED6325208E}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe
FirewallRules: [{F10800EE-6756-42A1-90CE-E427CBF539D4}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe
FirewallRules: [{2A7DDAB2-DC52-4CDE-8F1E-986F1FDAE3DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe
FirewallRules: [{450E7BEE-4B21-4DC6-8DD0-9F3EB17E10DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe
FirewallRules: [{F3D9292D-B5CD-4C90-A555-8B868FC2B401}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe
FirewallRules: [{0963FFB1-B8F7-47D8-B0D9-63C4510994B7}] => (Allow) C:\Windows\SysWOW64\ARFC\wrtc.exe
FirewallRules: [{12CCA574-1522-4A9D-8CFA-F316C5F803B4}] => (Allow) C:\Program Files (x86)\nokia\nokia suite\nokiasuite.exe
FirewallRules: [{49C238E6-DC14-4ADB-A24F-1DCBDDFF6A2A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{AFC7B2D0-2892-495A-B64B-88D6FE870AAE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{0D50225C-8FFA-4569-8D66-0D0AA85CDC67}] => (Allow) C:\Program Files (x86)\nokia\nokia suite\nokiasuite.exe
FirewallRules: [{02157273-00E2-42AF-B8B2-5102BC11A76B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
Name: Microsoft ISATAP Adapter #2
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Microsoft ISATAP Adapter
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/15/2015 09:49:20 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/15/2015 09:40:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: setup.exe_Sony PC Companion, verze: 17.0.0.717, časové razítko: 0x4cab8cfa
Název chybujícího modulu: DownloadManager.dll_unloaded, verze: 0.0.0.0, časové razítko: 0x53be652d
Kód výjimky: 0xc0000005
Posun chyby: 0x6cf246f0
ID chybujícího procesu: 0x6d8
Čas spuštění chybující aplikace: 0xsetup.exe_Sony PC Companion0
Cesta k chybující aplikaci: setup.exe_Sony PC Companion1
Cesta k chybujícímu modulu: setup.exe_Sony PC Companion2
ID zprávy: setup.exe_Sony PC Companion3
Error: (09/15/2015 09:32:43 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program IEXPLORE.EXE verze 11.0.9600.17937 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: 1924
Čas spuštění: 01d0ef8896f2fec6
Čas ukončení: 19
Cesta k aplikaci: C:\Program Files\Internet Explorer\IEXPLORE.EXE
ID hlášení: e75eea46-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:29:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0x1aa0
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (09/15/2015 09:28:26 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Explorer.EXE verze 6.1.7601.17567 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: 7bc
Čas spuštění: 01d0ef857c503495
Čas ukončení: 0
Cesta k aplikaci: C:\Windows\Explorer.EXE
ID hlášení:
Error: (09/15/2015 09:28:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0x1320
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (09/15/2015 09:27:32 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Skype.exe verze 7.8.64.102 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Centrum akcí.
ID procesu: fcc
Čas spuštění: 01d0ef8589154113
Čas ukončení: 24
Cesta k aplikaci: C:\Program Files (x86)\Skype\Phone\Skype.exe
ID hlášení:
Error: (09/15/2015 09:27:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0xf64
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (09/15/2015 09:14:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0x17d8
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Error: (09/15/2015 09:14:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 40.0.3.5716, časové razítko: 0x55ddb213
Název chybujícího modulu: mozglue.dll, verze: 40.0.3.5716, časové razítko: 0x55dda062
Kód výjimky: 0x80000003
Posun chyby: 0x0000e250
ID chybujícího procesu: 0xbd8
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
System errors:
=============
Error: (09/15/2015 09:47:55 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
CFRMD
Error: (09/15/2015 09:46:49 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správce služeb se pokusil o opravnou akci (Restartovat službu) po nečekaném ukončení služby Windows Search, ale tato akce selhala kvůli následující chybě:
%%1056
Error: (09/15/2015 09:46:20 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Ochrana softwaru byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba modulů systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba ServiceLayer byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Live ID Sign-in Assistant byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba VIA Karaoke digital mixer Service byla neočekávaně ukončena. Tento stav nastal již 1krát.
Error: (09/15/2015 09:46:19 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Realtek11nSU byla neočekávaně ukončena. Tento stav nastal již 1krát.
Microsoft Office:
=========================
Error: (09/15/2015 09:49:20 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (09/15/2015 09:40:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: setup.exe_Sony PC Companion17.0.0.7174cab8cfaDownloadManager.dll_unloaded0.0.0.053be652dc00000056cf246f06d801d0ef89c12dad7bC:\Users\Lada\AppData\Local\Temp\{0692A097-3C39-49B6-8BF4-37F8B201995E}\setup.exeDownloadManager.dll189fcbce-5b7d-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:32:43 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: IEXPLORE.EXE11.0.9600.17937192401d0ef8896f2fec619C:\Program Files\Internet Explorer\IEXPLORE.EXEe75eea46-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:29:14 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e2501aa001d0ef883025444bC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll76b89882-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:28:26 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Explorer.EXE6.1.7601.175677bc01d0ef857c5034950C:\Windows\Explorer.EXE
Error: (09/15/2015 09:28:00 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e250132001d0ef880719017dC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll4a8dcbf3-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:27:32 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Skype.exe7.8.64.102fcc01d0ef858915411324C:\Program Files (x86)\Skype\Phone\Skype.exe
Error: (09/15/2015 09:27:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e250f6401d0ef87e1f021f3C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll39c3c2a4-5b7b-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:14:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e25017d801d0ef862691da22C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll6c0a1d44-5b79-11e5-a11b-50465d8c1eac
Error: (09/15/2015 09:14:02 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe40.0.3.571655ddb213mozglue.dll40.0.3.571655dda062800000030000e250bd801d0ef8614a96451C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozglue.dll56e13d53-5b79-11e5-a11b-50465d8c1eac
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) CPU G645 @ 2.90GHz
Percentage of memory in use: 28%
Total physical RAM: 7881.84 MB
Available physical RAM: 5603 MB
Total Virtual: 15761.89 MB
Available Virtual: 13137.96 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:923.69 GB) (Free:445.3 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Offroad) (CDROM) (Total:0.29 GB) (Free:0 GB) CDFS
Drive e: (CANON_DC) (Removable) (Total:1.89 GB) (Free:0.2 GB) FAT
Drive i: (SolidWorks1) (CDROM) (Total:6.2 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 5EDA6502)
Partition 1: (Active) - (Size=923.7 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=7.8 GB) - (Type=27)
========================================================
Disk: 1 (Size: 1.9 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
Re: Prosím o kontrolu logu
Addition.txt se mi nepodařilo zabalit, tak sem ho zkopíroval do dalšího příspěvku.
Re: Prosím o kontrolu logu
- Java 8 Update 31
- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu bude na plose ulozen fixlog, jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CreateRestorePoint: CloseProcesses: File: C:\Program Files (x86)\GoforFiles\GoforFiles.exe File: C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe File: C:\Program Files (x86)\GUT5EB1.tmp Folder: C:\Program Files\daugava File: C:\Program Files\daugava\Ejemidvlf.exe File: C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe HKLM\...\Run: [daugava] => C:\Program Files\daugava\Ejemidvlf.exe HKLM\...\Run: [daugava64] => C:\Program Files\daugava\Ejemidvlf64.exe HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd) HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8202008 2015-05-13] (Piriform Ltd) HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [] => [X] HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1092448 2015-05-20] (Nokia) HKU\S-1-5-18\...\Run: [Advanced SystemCare 7] => "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION URLSearchHook: HKLM-x32 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.) URLSearchHook: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.) SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MNMTDF&pc=MANM&src=IE-SearchBox SearchScopes: HKLM-x32 -> DefaultScope {7238486F-C8CB-448E-8FB7-07C4331DF5C5} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: Ads Removal -> {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} -> C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll [2014-06-11] (Adblock) FF DefaultSearchEngine: Yahoo! FF SearchEngineOrder.3: Bing FF SelectedSearchEngine: Yahoo! FF Keyword.URL: hxxps://search.yahoo.com/search?fr=gree ... =198484&p= FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30] FF Extension: No Name - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93} [not found] CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=_ ... smkt=en-us CHR StartupUrls: Default -> "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP" CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=chr- ... =198484&p={searchTerms} CHR DefaultSearchKeyword: Default -> yahoo.com search CHR DefaultSuggestURL: Default -> hxxps://ff.search.yahoo.com/gossip?outp ... n&command={searchTerms} CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll => No File CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll => No File CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File 2015-09-15 09:45 - 2015-09-15 09:46 - 00000000 ____D C:\AdwCleaner 2015-09-15 09:44 - 2015-09-15 09:44 - 01660416 _____ C:\Users\Lada\Desktop\adwcleaner_5.007.exe 2015-09-14 12:19 - 2015-09-15 09:43 - 00000000 ____D C:\Program Files\trend micro 2015-09-14 12:19 - 2015-09-14 12:19 - 00000000 ____D C:\rsit CMD: del "C:\Program Files (x86)\GU*.tmp" 2015-08-30 21:16 - 2015-08-30 21:16 - 06420480 _____ C:\Program Files (x86)\GUT5EB1.tmp 2015-08-30 21:16 - 2015-08-30 21:16 - 00000000 ____D C:\Program Files (x86)\GUM5EB0.tmp Task: {50A165B8-5EDA-46FA-8B1C-A46F838F4EEC} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe Task: {9F943BEE-1B56-4827-98BB-941E3D2A6E1F} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe C:\Program Files (x86)\IObit Hosts: EmptyTemp: End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Fix result of Farbar Recovery Scan Tool (x64) Version:14-09-2015
Ran by Lada (2015-09-15 10:49:10) Run:1
Running from C:\Users\Lada\Desktop
Loaded Profiles: Lada (Available Profiles: Lada)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
File: C:\Program Files (x86)\GoforFiles\GoforFiles.exe
File: C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe
File: C:\Program Files (x86)\GUT5EB1.tmp
Folder: C:\Program Files\daugava
File: C:\Program Files\daugava\Ejemidvlf.exe
File: C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
HKLM\...\Run: [daugava] => C:\Program Files\daugava\Ejemidvlf.exe
HKLM\...\Run: [daugava64] => C:\Program Files\daugava\Ejemidvlf64.exe
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8202008 2015-05-13] (Piriform Ltd)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [] => [X]
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1092448 2015-05-20] (Nokia)
HKU\S-1-5-18\...\Run: [Advanced SystemCare 7] => "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
URLSearchHook: HKLM-x32 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.)
URLSearchHook: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.)
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {7238486F-C8CB-448E-8FB7-07C4331DF5C5} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Ads Removal -> {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} -> C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll [2014-06-11] (Adblock)
FF DefaultSearchEngine: Yahoo!
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Yahoo!
FF Keyword.URL: hxxps://search.yahoo.com/search?fr=gree ... =198484&p=
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30]
FF Extension: No Name - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93} [not found]
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=_ ... smkt=en-us
CHR StartupUrls: Default -> "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=chr- ... =198484&p={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo.com search
CHR DefaultSuggestURL: Default -> hxxps://ff.search.yahoo.com/gossip?outp ... n&command={searchTerms}
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll => No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File
CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
2015-09-15 09:45 - 2015-09-15 09:46 - 00000000 ____D C:\AdwCleaner
2015-09-15 09:44 - 2015-09-15 09:44 - 01660416 _____ C:\Users\Lada\Desktop\adwcleaner_5.007.exe
2015-09-14 12:19 - 2015-09-15 09:43 - 00000000 ____D C:\Program Files\trend micro
2015-09-14 12:19 - 2015-09-14 12:19 - 00000000 ____D C:\rsit
CMD: del "C:\Program Files (x86)\GU*.tmp"
2015-08-30 21:16 - 2015-08-30 21:16 - 06420480 _____ C:\Program Files (x86)\GUT5EB1.tmp
2015-08-30 21:16 - 2015-08-30 21:16 - 00000000 ____D C:\Program Files (x86)\GUM5EB0.tmp
Task: {50A165B8-5EDA-46FA-8B1C-A46F838F4EEC} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {9F943BEE-1B56-4827-98BB-941E3D2A6E1F} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\IObit
Hosts:
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
========================= File: C:\Program Files (x86)\GoforFiles\GoforFiles.exe ========================
"C:\Program Files (x86)\GoforFiles\GoforFiles.exe" => not found.
====== End of File: ======
========================= File: C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe ========================
"C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe" => not found.
====== End of File: ======
========================= File: C:\Program Files (x86)\GUT5EB1.tmp ========================
File not signed
MD5: AD64F295675338F4E702EDD9190DEE3C
Creation and modification date: 2015-08-30 21:16 - 2015-08-30 21:16
Size: 6420480
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
========================= Folder: C:\Program Files\daugava ========================
not found.
====== End of Folder: ======
========================= File: C:\Program Files\daugava\Ejemidvlf.exe ========================
"C:\Program Files\daugava\Ejemidvlf.exe" => not found.
====== End of File: ======
========================= File: C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe ========================
File not signed
MD5: 016D5E2189CDE4D35E69D6CFA04EA3AB
Creation and modification date: 2013-02-13 13:52 - 2013-02-13 13:52
Size: 0335872
Attributes: ---RA
Company Name: Flexera Software, Inc.
Internal Name: _IsIcoRes.exe
Original Name: _IsIcoRes.exe
Product: InstallShield
Description: InstallShield
File Version: 17.0.714
Product Version: 17.0
Copyright: Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc. All Rights Reserved.
====== End of File: ======
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\daugava => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\daugava64 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NokiaSuite.exe => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 7 => value removed successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{92e7bc9c-bc36-42d4-9013-65e387115066} => value removed successfully
"HKCR\Wow6432Node\CLSID\{92e7bc9c-bc36-42d4-9013-65e387115066}" => key removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{92e7bc9c-bc36-42d4-9013-65e387115066} => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9E203922-4DCC-49AA-A0B4-558C0F0E3E81}" => key removed successfully
HKCR\CLSID\{9E203922-4DCC-49AA-A0B4-558C0F0E3E81} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}" => key removed successfully
Firefox DefaultSearchEngine removed successfully
Firefox SearchEngineOrder.3 removed successfully
Firefox SelectedSearchEngine removed successfully
Firefox "Keyword.URL" removed successfully
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => moved successfully
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => moved successfully
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => path removed successfully
C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93} => path removed successfully
Chrome HomePage removed successfully
Chrome StartupUrls removed successfully
Chrome DefaultSearchURL removed successfully
Chrome DefaultSearchKeyword removed successfully
Chrome DefaultSuggestURL removed successfully
C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll => not found.
C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => not found.
C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => not found.
C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => not found.
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => not found.
C:\Windows\SysWOW64\npDeployJava1.dll => not found.
c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => not found.
C:\AdwCleaner => moved successfully
C:\Users\Lada\Desktop\adwcleaner_5.007.exe => moved successfully
C:\Program Files\trend micro => moved successfully
C:\rsit => moved successfully
========= del "C:\Program Files (x86)\GU*.tmp" =========
========= End of CMD: =========
"C:\Program Files (x86)\GUT5EB1.tmp" => File/Folder not found.
C:\Program Files (x86)\GUM5EB0.tmp => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{50A165B8-5EDA-46FA-8B1C-A46F838F4EEC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50A165B8-5EDA-46FA-8B1C-A46F838F4EEC}" => key removed successfully
C:\Windows\System32\Tasks\Uninstaller_SkipUac_Administrator => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Administrator" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F943BEE-1B56-4827-98BB-941E3D2A6E1F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F943BEE-1B56-4827-98BB-941E3D2A6E1F}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster SkipUAC (SYSTEM) => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (SYSTEM)" => key removed successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\Program Files (x86)\IObit => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 167.4 MB temporary data Removed.
The system needed a reboot..
==== End of Fixlog 10:49:29 ====
Ran by Lada (2015-09-15 10:49:10) Run:1
Running from C:\Users\Lada\Desktop
Loaded Profiles: Lada (Available Profiles: Lada)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
File: C:\Program Files (x86)\GoforFiles\GoforFiles.exe
File: C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe
File: C:\Program Files (x86)\GUT5EB1.tmp
Folder: C:\Program Files\daugava
File: C:\Program Files\daugava\Ejemidvlf.exe
File: C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe
HKLM\...\Run: [daugava] => C:\Program Files\daugava\Ejemidvlf.exe
HKLM\...\Run: [daugava64] => C:\Program Files\daugava\Ejemidvlf64.exe
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3674320 2013-01-08] (DT Soft Ltd)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8202008 2015-05-13] (Piriform Ltd)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [] => [X]
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [NokiaSuite.exe] => C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe [1092448 2015-05-20] (Nokia)
HKU\S-1-5-18\...\Run: [Advanced SystemCare 7] => "C:\Program Files (x86)\IObit\Advanced SystemCare 7\ASCTray.exe" /Auto
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
URLSearchHook: HKLM-x32 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.)
URLSearchHook: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 - ARO 2013 Toolbar - {92e7bc9c-bc36-42d4-9013-65e387115066} - C:\Program Files (x86)\ARO_2013\prxtbARO_.dll (Conduit Ltd.)
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {7238486F-C8CB-448E-8FB7-07C4331DF5C5} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: Ads Removal -> {9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F} -> C:\Program Files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\Adblock.dll [2014-06-11] (Adblock)
FF DefaultSearchEngine: Yahoo!
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Yahoo!
FF Keyword.URL: hxxps://search.yahoo.com/search?fr=gree ... =198484&p=
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-08-30]
FF Extension: No Name - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93} [not found]
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=_ ... smkt=en-us
CHR StartupUrls: Default -> "hxxp://www.msn.com/?pc=UP97&ocid=UP97DHP"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=chr- ... =198484&p={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo.com search
CHR DefaultSuggestURL: Default -> hxxps://ff.search.yahoo.com/gossip?outp ... n&command={searchTerms}
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll => No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File
CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
2015-09-15 09:45 - 2015-09-15 09:46 - 00000000 ____D C:\AdwCleaner
2015-09-15 09:44 - 2015-09-15 09:44 - 01660416 _____ C:\Users\Lada\Desktop\adwcleaner_5.007.exe
2015-09-14 12:19 - 2015-09-15 09:43 - 00000000 ____D C:\Program Files\trend micro
2015-09-14 12:19 - 2015-09-14 12:19 - 00000000 ____D C:\rsit
CMD: del "C:\Program Files (x86)\GU*.tmp"
2015-08-30 21:16 - 2015-08-30 21:16 - 06420480 _____ C:\Program Files (x86)\GUT5EB1.tmp
2015-08-30 21:16 - 2015-08-30 21:16 - 00000000 ____D C:\Program Files (x86)\GUM5EB0.tmp
Task: {50A165B8-5EDA-46FA-8B1C-A46F838F4EEC} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe
Task: {9F943BEE-1B56-4827-98BB-941E3D2A6E1F} - System32\Tasks\Driver Booster SkipUAC (SYSTEM) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\IObit
Hosts:
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
========================= File: C:\Program Files (x86)\GoforFiles\GoforFiles.exe ========================
"C:\Program Files (x86)\GoforFiles\GoforFiles.exe" => not found.
====== End of File: ======
========================= File: C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe ========================
"C:\Program Files (x86)\Common Files\ProgramManager\ProgramManager.exe" => not found.
====== End of File: ======
========================= File: C:\Program Files (x86)\GUT5EB1.tmp ========================
File not signed
MD5: AD64F295675338F4E702EDD9190DEE3C
Creation and modification date: 2015-08-30 21:16 - 2015-08-30 21:16
Size: 6420480
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
========================= Folder: C:\Program Files\daugava ========================
not found.
====== End of Folder: ======
========================= File: C:\Program Files\daugava\Ejemidvlf.exe ========================
"C:\Program Files\daugava\Ejemidvlf.exe" => not found.
====== End of File: ======
========================= File: C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe ========================
File not signed
MD5: 016D5E2189CDE4D35E69D6CFA04EA3AB
Creation and modification date: 2013-02-13 13:52 - 2013-02-13 13:52
Size: 0335872
Attributes: ---RA
Company Name: Flexera Software, Inc.
Internal Name: _IsIcoRes.exe
Original Name: _IsIcoRes.exe
Product: InstallShield
Description: InstallShield
File Version: 17.0.714
Product Version: 17.0
Copyright: Copyright (C) 2010 Flexera Software, Inc. and/or InstallShield Co. Inc. All Rights Reserved.
====== End of File: ======
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\daugava => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\daugava64 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\NokiaSuite.exe => value removed successfully
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare 7 => value removed successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\{92e7bc9c-bc36-42d4-9013-65e387115066} => value removed successfully
"HKCR\Wow6432Node\CLSID\{92e7bc9c-bc36-42d4-9013-65e387115066}" => key removed successfully
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{92e7bc9c-bc36-42d4-9013-65e387115066} => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9E203922-4DCC-49AA-A0B4-558C0F0E3E81}" => key removed successfully
HKCR\CLSID\{9E203922-4DCC-49AA-A0B4-558C0F0E3E81} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}" => key removed successfully
Firefox DefaultSearchEngine removed successfully
Firefox SearchEngineOrder.3 removed successfully
Firefox SelectedSearchEngine removed successfully
Firefox "Keyword.URL" removed successfully
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => moved successfully
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => moved successfully
C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => path removed successfully
C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\extensions\{4D6A6C8E-1EB2-46e1-8CAA-40DAFDE3ED93} => path removed successfully
Chrome HomePage removed successfully
Chrome StartupUrls removed successfully
Chrome DefaultSearchURL removed successfully
Chrome DefaultSearchKeyword removed successfully
Chrome DefaultSuggestURL removed successfully
C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\ppGoogleNaClPluginChrome.dll => not found.
C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\pdf.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => not found.
C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => not found.
C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => not found.
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => not found.
C:\Windows\SysWOW64\npDeployJava1.dll => not found.
c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => not found.
C:\AdwCleaner => moved successfully
C:\Users\Lada\Desktop\adwcleaner_5.007.exe => moved successfully
C:\Program Files\trend micro => moved successfully
C:\rsit => moved successfully
========= del "C:\Program Files (x86)\GU*.tmp" =========
========= End of CMD: =========
"C:\Program Files (x86)\GUT5EB1.tmp" => File/Folder not found.
C:\Program Files (x86)\GUM5EB0.tmp => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{50A165B8-5EDA-46FA-8B1C-A46F838F4EEC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{50A165B8-5EDA-46FA-8B1C-A46F838F4EEC}" => key removed successfully
C:\Windows\System32\Tasks\Uninstaller_SkipUac_Administrator => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Administrator" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F943BEE-1B56-4827-98BB-941E3D2A6E1F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F943BEE-1B56-4827-98BB-941E3D2A6E1F}" => key removed successfully
C:\Windows\System32\Tasks\Driver Booster SkipUAC (SYSTEM) => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (SYSTEM)" => key removed successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\Program Files (x86)\IObit => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 167.4 MB temporary data Removed.
The system needed a reboot..
==== End of Fixlog 10:49:29 ====
Re: Prosím o kontrolu logu
- Upozorneni: tento sken zabere od 30 minut po nekolik hodin
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Log z mbam byl moc dlouhý do příspěvku, proto v příloze.
- Přílohy
-
- mbamlog.zip
- (9.14 KiB) Staženo 76 x
Re: Prosím o kontrolu logu
Vsechny nalezy smazte/presunte do karanteny, pote dejte aktualni logy z FRST (FRST.txt i Addition.txt).
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by Lada (administrator) on LADA-PC (16-09-2015 10:02:52)
Running from C:\Users\Lada\Desktop
Loaded Profiles: Lada (Available Profiles: Lada)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe
(Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\PAC207\Monitor.exe
(© 2015 Microsoft Corporation) C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
(Microsoft Corporation) C:\Windows\System32\makecab.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1427648 2015-08-09] (COMODO)
HKLM\...\Run: [PAC207_Monitor] => C:\Windows\PixArt\PAC207\Monitor.exe [323584 2007-12-10] (PixArt Imaging Incorporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5028464 2012-01-12] (VIA)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-08-22] (Comodo Security Solutions, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-09-15] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [AROReminder] => C:\Program Files (x86)\ARO 2013\ARO.exe [3157336 2013-07-03] (Support.com, Inc.)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [BingSvc] => C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-05-11] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53735968 2015-08-07] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks 2013 Rychlé spuštění.lnk [2013-02-13]
ShortcutTarget: SolidWorks 2013 Rychlé spuštění.lnk -> C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks Nástroj pro stahování na pozadí.lnk [2013-02-10]
ShortcutTarget: SolidWorks Nástroj pro stahování na pozadí.lnk -> C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 212.111.0.10 194.213.32.237
Tcpip\..\Interfaces\{47A8AFA2-D00F-4F0A-890B-2B997F163A99}: [DhcpNameServer] 212.111.0.10 194.213.32.237
Internet Explorer:
==================
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=UP22&ocid=UP22DHP&dt=012113
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://nmd.msn.com
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.atcomp.cz
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> DefaultScope {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M ... -SearchBox
SearchScopes: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M ... -SearchBox
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-15] (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: No Name -> {92e7bc9c-bc36-42d4-9013-65e387115066} -> No File
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-15] (Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {92e7bc9c-bc36-42d4-9013-65e387115066} - No File
Toolbar: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-15] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-15] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2014-11-19] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2831377403-1237323822-844494322-1000: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll [2013-08-27] (Sony Network Entertainment International LLC)
FF Extension: Bing Search Engine - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\bingsearch.full@microsoft.com [2015-04-10]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2015-08-30] <==== ATTENTION
Chrome:
=======
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC ... earchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.93\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.93\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.93\pdf.dll => No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File
CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
CHR Profile: C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bing) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2015-09-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-06]
CHR HKU\S-1-5-21-2831377403-1237323822-844494322-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70848 2015-08-22] (Comodo Security Solutions, Inc.)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5542472 2015-09-09] (COMODO)
R3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-08-09] (COMODO)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [1994936 2015-06-27] (Comodo)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-08-22] (Comodo Security Solutions, Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-09-15] (Malwarebytes Corporation)
R2 Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed]
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2013-02-13] (SolidWorks) [File not signed]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-01-10] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S1 CFRMD; C:\Windows\SysWOW64\DRIVERS\CFRMD.sys [37976 2012-09-03] (Windows (R) Win 7 DDK provider) [File not signed]
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [21184 2015-08-05] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [806032 2015-08-05] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45856 2015-08-05] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-01-11] (DT Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [105096 2015-08-05] (COMODO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-09-15] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-09-15] (Malwarebytes Corporation)
R3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [686592 2009-06-25] (PixArt Imaging Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-16 10:02 - 2015-09-16 10:03 - 00018517 _____ C:\Users\Lada\Desktop\FRST.txt
2015-09-16 10:02 - 2015-09-16 10:02 - 00000000 ____D C:\Users\Lada\Desktop\FRST-OlderVersion
2015-09-15 11:05 - 2015-09-15 11:08 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-15 11:05 - 2015-09-15 11:05 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-15 11:05 - 2015-09-15 11:05 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-15 11:05 - 2015-09-15 11:05 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-15 11:05 - 2015-09-15 11:05 - 00001134 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-15 11:05 - 2015-09-15 11:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-15 11:05 - 2015-09-15 11:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-15 11:05 - 2015-09-15 11:05 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-09-15 10:46 - 2015-09-15 10:46 - 00000000 ____D C:\Users\Lada\AppData\Roaming\Sun
2015-09-15 10:46 - 2015-09-15 10:46 - 00000000 ____D C:\Users\Lada\.oracle_jre_usage
2015-09-15 10:45 - 2015-09-15 10:45 - 00584288 _____ (Oracle Corporation) C:\Users\Lada\Downloads\chromeinstall-8u60.exe
2015-09-15 10:45 - 2015-09-15 10:45 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-09-15 10:45 - 2015-09-15 10:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-09-15 10:14 - 2015-09-16 10:03 - 00000000 ____D C:\FRST
2015-09-15 10:11 - 2015-09-16 10:02 - 02191360 _____ (Farbar) C:\Users\Lada\Desktop\FRST64.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 25190400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 19856896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 14451712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 12857344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-15 09:26 - 2015-09-15 09:26 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-09-15 09:26 - 2015-09-15 09:26 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00393304 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00344168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-09-15 09:26 - 2015-08-15 08:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-09-15 09:26 - 2015-08-15 08:17 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-09-15 09:26 - 2015-08-15 07:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-09-15 09:26 - 2015-08-15 07:39 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-09-15 09:26 - 2015-08-05 19:56 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-15 09:26 - 2015-08-05 19:56 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-09-15 09:26 - 2015-08-05 19:56 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-09-15 09:26 - 2015-08-05 19:40 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 05568960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 03989952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 03934656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 02004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00692672 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-09-15 09:25 - 2015-09-15 09:25 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-09-15 09:25 - 2015-09-15 09:25 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00115136 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 03209216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-15 09:22 - 2015-09-15 09:22 - 03165696 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-09-15 09:22 - 2015-09-15 09:22 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-09-15 09:22 - 2015-09-15 09:22 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-09-15 09:22 - 2015-09-15 09:22 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-09-01 15:44 - 2015-09-01 15:44 - 28849904 _____ C:\Users\Lada\Documents\vlc-2.2.1-win32.exe
2015-08-30 09:29 - 2015-09-01 15:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-22 08:50 - 2015-08-22 08:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo Security Solutions Inc
2015-08-21 20:45 - 2015-08-21 20:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-16 10:02 - 2013-02-12 23:04 - 01151995 _____ C:\Windows\WindowsUpdate.log
2015-09-16 10:02 - 2013-01-30 00:24 - 00070638 _____ C:\Windows\system32\Drivers\fvstore.dat
2015-09-16 09:58 - 2015-06-03 13:04 - 00008972 _____ C:\Windows\setupact.log
2015-09-16 09:58 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-16 05:08 - 2013-01-07 11:12 - 01474832 _____ C:\Windows\system32\Drivers\sfi.dat
2015-09-16 05:08 - 2009-07-14 06:45 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-16 05:08 - 2009-07-14 06:45 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-16 05:02 - 2009-07-14 06:45 - 00434304 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-16 05:00 - 2015-06-04 12:10 - 00125508 _____ C:\Windows\PFRO.log
2015-09-16 05:00 - 2010-11-21 11:38 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-16 05:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-15 23:21 - 2013-01-11 12:47 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-15 23:20 - 2013-08-06 19:51 - 00000000 ____D C:\Windows\system32\MRT
2015-09-15 23:10 - 2009-07-14 04:34 - 00000478 _____ C:\Windows\win.ini
2015-09-15 22:36 - 2013-01-07 20:04 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-15 22:29 - 2013-01-21 22:18 - 00000000 ____D C:\Users\Lada\AppData\Roaming\Skype
2015-09-15 22:21 - 2013-08-25 07:49 - 00000000 ____D C:\Program Files (x86)\ARO_2013
2015-09-15 22:19 - 2013-01-07 20:05 - 00002201 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-15 13:09 - 2015-02-08 10:22 - 00000000 ____D C:\Users\Lada\Desktop\Aleš
2015-09-15 10:46 - 2012-12-24 16:07 - 00000000 ____D C:\Users\Lada
2015-09-15 10:45 - 2013-03-05 11:32 - 00000000 ____D C:\Program Files (x86)\Java
2015-09-15 09:43 - 2015-04-04 16:27 - 00000000 ___SD C:\Windows\system32\GWX
2015-09-15 09:43 - 2013-01-07 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-09-15 09:43 - 2013-01-07 11:20 - 00000000 ____D C:\Program Files\CCleaner
2015-09-15 09:43 - 2013-01-07 11:13 - 00000000 ____D C:\Windows\System32\Tasks\COMODO
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-09-15 09:42 - 2013-01-10 06:29 - 00000000 ____D C:\Users\Lada\AppData\Local\Mozilla
2015-09-15 09:40 - 2013-10-27 09:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-09-15 09:40 - 2013-10-27 09:32 - 00000000 ____D C:\Program Files (x86)\Sony
2015-09-15 09:40 - 2012-12-15 10:22 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-15 09:39 - 2014-01-04 14:25 - 00000000 ____D C:\ProgramData\Sony Mobile
2015-09-15 09:39 - 2014-01-04 14:25 - 00000000 ____D C:\Program Files (x86)\Sony Mobile
2015-09-15 09:30 - 2013-02-20 22:39 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-09-09 17:55 - 2015-07-27 10:45 - 00000000 ____D C:\Users\Lada\Desktop\benatska noc 2015
2015-09-09 17:52 - 2010-11-21 11:27 - 00742398 _____ C:\Windows\system32\perfh005.dat
2015-09-09 17:52 - 2010-11-21 11:27 - 00195546 _____ C:\Windows\system32\perfc005.dat
2015-09-09 17:52 - 2009-07-14 07:13 - 01711684 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-05 17:46 - 2013-01-20 20:37 - 00000000 ____D C:\Users\Lada\AppData\Local\TempAdresářZálohySW
2015-09-05 16:25 - 2013-01-11 12:44 - 00000000 ____D C:\Users\Lada\AppData\Roaming\SolidWorks
2015-09-03 13:52 - 2012-12-14 21:45 - 00579408 _____ (COMODO) C:\Windows\system32\guard64.dll
2015-09-03 13:52 - 2012-12-14 21:45 - 00445472 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll
2015-09-01 15:48 - 2013-03-24 01:37 - 00000000 ____D C:\Users\Lada\AppData\Roaming\vlc
2015-09-01 15:45 - 2013-03-24 01:37 - 00001082 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-09-01 15:03 - 2013-01-10 06:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-31 19:54 - 2013-01-07 20:04 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-31 19:54 - 2013-01-07 20:04 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-26 18:37 - 2013-01-25 22:06 - 134753440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-22 08:50 - 2013-01-07 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2015-08-21 20:45 - 2014-09-16 19:29 - 00002761 _____ C:\Users\Public\Desktop\Skype.lnk
2015-08-21 20:45 - 2013-01-21 22:18 - 00000000 ____D C:\ProgramData\Skype
2015-08-21 18:36 - 2015-07-10 15:22 - 00016930 _____ C:\Windows\DPINST.LOG
2015-08-17 20:27 - 2015-05-30 21:13 - 00003896 _____ C:\Windows\System32\Tasks\Program Manager
==================== Files in the root of some directories =======
2014-09-05 09:05 - 2014-09-05 09:05 - 0000000 _____ () C:\Users\Lada\AppData\Local\{49BCE388-C6BA-499E-B72B-74A26CC8713D}
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-15 13:29
==================== End of FRST.txt ============================
Ran by Lada (administrator) on LADA-PC (16-09-2015 10:02:52)
Running from C:\Users\Lada\Desktop
Loaded Profiles: Lada (Available Profiles: Lada)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Comodo) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler.exe
(Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.13\GoogleCrashHandler64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(PixArt Imaging Incorporation) C:\Windows\PixArt\PAC207\Monitor.exe
(© 2015 Microsoft Corporation) C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files\SolidWorks Corp\SolidWorks\sldworks_fs.exe
(Dassault Systèmes SolidWorks Corp.) C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
(Microsoft Corporation) C:\Windows\System32\makecab.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1427648 2015-08-09] (COMODO)
HKLM\...\Run: [PAC207_Monitor] => C:\Windows\PixArt\PAC207\Monitor.exe [323584 2007-12-10] (PixArt Imaging Incorporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5028464 2012-01-12] (VIA)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-08-22] (Comodo Security Solutions, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-09-15] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [AROReminder] => C:\Program Files (x86)\ARO 2013\ARO.exe [3157336 2013-07-03] (Support.com, Inc.)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [BingSvc] => C:\Users\Lada\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-05-11] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53735968 2015-08-07] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks 2013 Rychlé spuštění.lnk [2013-02-13]
ShortcutTarget: SolidWorks 2013 Rychlé spuštění.lnk -> C:\Windows\Installer\{B6B5EA7E-B91F-443D-A958-B0062FB53804}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (Flexera Software, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks Nástroj pro stahování na pozadí.lnk [2013-02-10]
ShortcutTarget: SolidWorks Nástroj pro stahování na pozadí.lnk -> C:\Program Files (x86)\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 212.111.0.10 194.213.32.237
Tcpip\..\Interfaces\{47A8AFA2-D00F-4F0A-890B-2B997F163A99}: [DhcpNameServer] 212.111.0.10 194.213.32.237
Internet Explorer:
==================
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=UP22&ocid=UP22DHP&dt=012113
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://nmd.msn.com
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.atcomp.cz
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> DefaultScope {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M ... -SearchBox
SearchScopes: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> {9E203922-4DCC-49AA-A0B4-558C0F0E3E81} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M ... -SearchBox
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-15] (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: No Name -> {92e7bc9c-bc36-42d4-9013-65e387115066} -> No File
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-09-23] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-15] (Oracle Corporation)
Toolbar: HKLM-x32 - No Name - {92e7bc9c-bc36-42d4-9013-65e387115066} - No File
Toolbar: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
FireFox:
========
FF ProfilePath: C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-15] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-15] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll [2014-11-19] ( )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-31] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2831377403-1237323822-844494322-1000: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll [2013-08-27] (Sony Network Entertainment International LLC)
FF Extension: Bing Search Engine - C:\Users\Lada\AppData\Roaming\Mozilla\Firefox\Profiles\gtyu39zp.default-1375300025060\Extensions\bingsearch.full@microsoft.com [2015-04-10]
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2015-08-30] <==== ATTENTION
Chrome:
=======
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC ... earchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.93\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.93\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.93\pdf.dll => No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File
CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Nokia Suite Enabler Plugin) - C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
CHR Profile: C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bing) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2015-09-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-06]
CHR HKU\S-1-5-21-2831377403-1237323822-844494322-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70848 2015-08-22] (Comodo Security Solutions, Inc.)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5542472 2015-09-09] (COMODO)
R3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-08-09] (COMODO)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [1994936 2015-06-27] (Comodo)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-08-22] (Comodo Security Solutions, Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-09-15] (Malwarebytes Corporation)
R2 Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed]
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2013-02-13] (SolidWorks) [File not signed]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-01-10] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S1 CFRMD; C:\Windows\SysWOW64\DRIVERS\CFRMD.sys [37976 2012-09-03] (Windows (R) Win 7 DDK provider) [File not signed]
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [21184 2015-08-05] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [806032 2015-08-05] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45856 2015-08-05] (COMODO)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-01-11] (DT Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [105096 2015-08-05] (COMODO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-09-15] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-09-15] (Malwarebytes Corporation)
R3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [686592 2009-06-25] (PixArt Imaging Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-16 10:02 - 2015-09-16 10:03 - 00018517 _____ C:\Users\Lada\Desktop\FRST.txt
2015-09-16 10:02 - 2015-09-16 10:02 - 00000000 ____D C:\Users\Lada\Desktop\FRST-OlderVersion
2015-09-15 11:05 - 2015-09-15 11:08 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-15 11:05 - 2015-09-15 11:05 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-15 11:05 - 2015-09-15 11:05 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-15 11:05 - 2015-09-15 11:05 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-15 11:05 - 2015-09-15 11:05 - 00001134 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-15 11:05 - 2015-09-15 11:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-15 11:05 - 2015-09-15 11:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-15 11:05 - 2015-09-15 11:05 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-09-15 10:46 - 2015-09-15 10:46 - 00000000 ____D C:\Users\Lada\AppData\Roaming\Sun
2015-09-15 10:46 - 2015-09-15 10:46 - 00000000 ____D C:\Users\Lada\.oracle_jre_usage
2015-09-15 10:45 - 2015-09-15 10:45 - 00584288 _____ (Oracle Corporation) C:\Users\Lada\Downloads\chromeinstall-8u60.exe
2015-09-15 10:45 - 2015-09-15 10:45 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-09-15 10:45 - 2015-09-15 10:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-09-15 10:14 - 2015-09-16 10:03 - 00000000 ____D C:\FRST
2015-09-15 10:11 - 2015-09-16 10:02 - 02191360 _____ (Farbar) C:\Users\Lada\Desktop\FRST64.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 25190400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 19856896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 14451712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 12857344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-15 09:26 - 2015-09-15 09:26 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-09-15 09:26 - 2015-09-15 09:26 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00393304 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00344168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-09-15 09:26 - 2015-09-15 09:26 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-09-15 09:26 - 2015-09-15 09:26 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-09-15 09:26 - 2015-08-15 08:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-09-15 09:26 - 2015-08-15 08:17 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-09-15 09:26 - 2015-08-15 07:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-09-15 09:26 - 2015-08-15 07:39 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-09-15 09:26 - 2015-08-05 19:56 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-15 09:26 - 2015-08-05 19:56 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-09-15 09:26 - 2015-08-05 19:56 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-09-15 09:26 - 2015-08-05 19:40 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 05568960 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 03989952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 03934656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 02004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01730496 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01390592 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01311768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01216512 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00692672 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-09-15 09:25 - 2015-09-15 09:25 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00616360 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-09-15 09:25 - 2015-09-15 09:25 - 00552960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00115136 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-09-15 09:25 - 2015-09-15 09:25 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-09-15 09:25 - 2015-09-15 09:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 03209216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-15 09:22 - 2015-09-15 09:22 - 03165696 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-09-15 09:22 - 2015-09-15 09:22 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-09-15 09:22 - 2015-09-15 09:22 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-09-15 09:22 - 2015-09-15 09:22 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-09-15 09:22 - 2015-09-15 09:22 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-09-01 15:44 - 2015-09-01 15:44 - 28849904 _____ C:\Users\Lada\Documents\vlc-2.2.1-win32.exe
2015-08-30 09:29 - 2015-09-01 15:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-22 08:50 - 2015-08-22 08:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo Security Solutions Inc
2015-08-21 20:45 - 2015-08-21 20:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-16 10:02 - 2013-02-12 23:04 - 01151995 _____ C:\Windows\WindowsUpdate.log
2015-09-16 10:02 - 2013-01-30 00:24 - 00070638 _____ C:\Windows\system32\Drivers\fvstore.dat
2015-09-16 09:58 - 2015-06-03 13:04 - 00008972 _____ C:\Windows\setupact.log
2015-09-16 09:58 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-16 05:08 - 2013-01-07 11:12 - 01474832 _____ C:\Windows\system32\Drivers\sfi.dat
2015-09-16 05:08 - 2009-07-14 06:45 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-16 05:08 - 2009-07-14 06:45 - 00024800 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-16 05:02 - 2009-07-14 06:45 - 00434304 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-16 05:00 - 2015-06-04 12:10 - 00125508 _____ C:\Windows\PFRO.log
2015-09-16 05:00 - 2010-11-21 11:38 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-16 05:00 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-15 23:21 - 2013-01-11 12:47 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-15 23:20 - 2013-08-06 19:51 - 00000000 ____D C:\Windows\system32\MRT
2015-09-15 23:10 - 2009-07-14 04:34 - 00000478 _____ C:\Windows\win.ini
2015-09-15 22:36 - 2013-01-07 20:04 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-15 22:29 - 2013-01-21 22:18 - 00000000 ____D C:\Users\Lada\AppData\Roaming\Skype
2015-09-15 22:21 - 2013-08-25 07:49 - 00000000 ____D C:\Program Files (x86)\ARO_2013
2015-09-15 22:19 - 2013-01-07 20:05 - 00002201 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-15 13:09 - 2015-02-08 10:22 - 00000000 ____D C:\Users\Lada\Desktop\Aleš
2015-09-15 10:46 - 2012-12-24 16:07 - 00000000 ____D C:\Users\Lada
2015-09-15 10:45 - 2013-03-05 11:32 - 00000000 ____D C:\Program Files (x86)\Java
2015-09-15 09:43 - 2015-04-04 16:27 - 00000000 ___SD C:\Windows\system32\GWX
2015-09-15 09:43 - 2013-01-07 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-09-15 09:43 - 2013-01-07 11:20 - 00000000 ____D C:\Program Files\CCleaner
2015-09-15 09:43 - 2013-01-07 11:13 - 00000000 ____D C:\Windows\System32\Tasks\COMODO
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\servicing
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2015-09-15 09:43 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-09-15 09:42 - 2013-01-10 06:29 - 00000000 ____D C:\Users\Lada\AppData\Local\Mozilla
2015-09-15 09:40 - 2013-10-27 09:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-09-15 09:40 - 2013-10-27 09:32 - 00000000 ____D C:\Program Files (x86)\Sony
2015-09-15 09:40 - 2012-12-15 10:22 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-15 09:39 - 2014-01-04 14:25 - 00000000 ____D C:\ProgramData\Sony Mobile
2015-09-15 09:39 - 2014-01-04 14:25 - 00000000 ____D C:\Program Files (x86)\Sony Mobile
2015-09-15 09:30 - 2013-02-20 22:39 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-09-09 17:55 - 2015-07-27 10:45 - 00000000 ____D C:\Users\Lada\Desktop\benatska noc 2015
2015-09-09 17:52 - 2010-11-21 11:27 - 00742398 _____ C:\Windows\system32\perfh005.dat
2015-09-09 17:52 - 2010-11-21 11:27 - 00195546 _____ C:\Windows\system32\perfc005.dat
2015-09-09 17:52 - 2009-07-14 07:13 - 01711684 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-05 17:46 - 2013-01-20 20:37 - 00000000 ____D C:\Users\Lada\AppData\Local\TempAdresářZálohySW
2015-09-05 16:25 - 2013-01-11 12:44 - 00000000 ____D C:\Users\Lada\AppData\Roaming\SolidWorks
2015-09-03 13:52 - 2012-12-14 21:45 - 00579408 _____ (COMODO) C:\Windows\system32\guard64.dll
2015-09-03 13:52 - 2012-12-14 21:45 - 00445472 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll
2015-09-01 15:48 - 2013-03-24 01:37 - 00000000 ____D C:\Users\Lada\AppData\Roaming\vlc
2015-09-01 15:45 - 2013-03-24 01:37 - 00001082 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-09-01 15:03 - 2013-01-10 06:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-31 19:54 - 2013-01-07 20:04 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-31 19:54 - 2013-01-07 20:04 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-26 18:37 - 2013-01-25 22:06 - 134753440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-22 08:50 - 2013-01-07 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2015-08-21 20:45 - 2014-09-16 19:29 - 00002761 _____ C:\Users\Public\Desktop\Skype.lnk
2015-08-21 20:45 - 2013-01-21 22:18 - 00000000 ____D C:\ProgramData\Skype
2015-08-21 18:36 - 2015-07-10 15:22 - 00016930 _____ C:\Windows\DPINST.LOG
2015-08-17 20:27 - 2015-05-30 21:13 - 00003896 _____ C:\Windows\System32\Tasks\Program Manager
==================== Files in the root of some directories =======
2014-09-05 09:05 - 2014-09-05 09:05 - 0000000 _____ () C:\Users\Lada\AppData\Local\{49BCE388-C6BA-499E-B72B-74A26CC8713D}
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-15 13:29
==================== End of FRST.txt ============================
- Přílohy
-
- Addition.zip
- (13.11 KiB) Staženo 63 x
Re: Prosím o kontrolu logu
- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu bude na plose ulozen fixlog, jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [AROReminder] => C:\Program Files (x86)\ARO 2013\ARO.exe [3157336 2013-07-03] (Support.com, Inc.) C:\Program Files (x86)\ARO 2013 HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-09-15] (Oracle Corporation) SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: No Name -> {92e7bc9c-bc36-42d4-9013-65e387115066} -> No File Toolbar: HKLM-x32 - No Name - {92e7bc9c-bc36-42d4-9013-65e387115066} - No File Toolbar: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File 2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057.exe 2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057 (1).exe FirewallRules: [{29F16449-4E68-4051-A03F-6FED6325208E}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe FirewallRules: [{F10800EE-6756-42A1-90CE-E427CBF539D4}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe FirewallRules: [{2A7DDAB2-DC52-4CDE-8F1E-986F1FDAE3DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe FirewallRules: [{450E7BEE-4B21-4DC6-8DD0-9F3EB17E10DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe C:\Users\Lada\AppData\Local\Temp End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o kontrolu logu
Fix result of Farbar Recovery Scan Tool (x64) Version:15-09-2015
Ran by Lada (2015-09-16 13:05:12) Run:2
Running from C:\Users\Lada\Desktop
Loaded Profiles: Lada (Available Profiles: Lada)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [AROReminder] => C:\Program Files (x86)\ARO 2013\ARO.exe [3157336 2013-07-03] (Support.com, Inc.)
C:\Program Files (x86)\ARO 2013
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-09-15] (Oracle Corporation)
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: No Name -> {92e7bc9c-bc36-42d4-9013-65e387115066} -> No File
Toolbar: HKLM-x32 - No Name - {92e7bc9c-bc36-42d4-9013-65e387115066} - No File
Toolbar: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File
CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057 (1).exe
FirewallRules: [{29F16449-4E68-4051-A03F-6FED6325208E}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe
FirewallRules: [{F10800EE-6756-42A1-90CE-E427CBF539D4}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe
FirewallRules: [{2A7DDAB2-DC52-4CDE-8F1E-986F1FDAE3DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe
FirewallRules: [{450E7BEE-4B21-4DC6-8DD0-9F3EB17E10DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe
C:\Users\Lada\AppData\Local\Temp
End
*****************
Processes closed successfully.
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AROReminder => value removed successfully
C:\Program Files (x86)\ARO 2013 => moved successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92e7bc9c-bc36-42d4-9013-65e387115066}" => key removed successfully
HKCR\Wow6432Node\CLSID\{92e7bc9c-bc36-42d4-9013-65e387115066} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{92e7bc9c-bc36-42d4-9013-65e387115066} => value removed successfully
HKCR\Wow6432Node\CLSID\{92e7bc9c-bc36-42d4-9013-65e387115066} => key not found.
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => not found.
C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => not found.
C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => not found.
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => not found.
C:\Windows\SysWOW64\npDeployJava1.dll => not found.
c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => not found.
C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057.exe => moved successfully
C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057 (1).exe => moved successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{29F16449-4E68-4051-A03F-6FED6325208E} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F10800EE-6756-42A1-90CE-E427CBF539D4} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2A7DDAB2-DC52-4CDE-8F1E-986F1FDAE3DA} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{450E7BEE-4B21-4DC6-8DD0-9F3EB17E10DA} => value removed successfully
"C:\Users\Lada\AppData\Local\Temp" folder move:
Could not move "C:\Users\Lada\AppData\Local\Temp" => Scheduled to move on reboot.
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-09-16 13:06:50)<=
C:\Users\Lada\AppData\Local\Temp => moved successfully
==== End of Fixlog 13:06:50 ====
Ran by Lada (2015-09-16 13:05:12) Run:2
Running from C:\Users\Lada\Desktop
Loaded Profiles: Lada (Available Profiles: Lada)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\...\Run: [AROReminder] => C:\Program Files (x86)\ARO 2013\ARO.exe [3157336 2013-07-03] (Support.com, Inc.)
C:\Program Files (x86)\ARO 2013
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-09-15] (Oracle Corporation)
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: No Name -> {92e7bc9c-bc36-42d4-9013-65e387115066} -> No File
Toolbar: HKLM-x32 - No Name - {92e7bc9c-bc36-42d4-9013-65e387115066} - No File
Toolbar: HKU\S-1-5-21-2831377403-1237323822-844494322-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
CHR Plugin: (Injovo Extension Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => No File
CHR Plugin: (Conduit Chrome Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => No File
CHR Plugin: (Conduit Radio Plugin) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => No File
CHR Plugin: (Delta Toolbar) - C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => No File
2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-15 11:03 - 2015-09-15 11:03 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057 (1).exe
FirewallRules: [{29F16449-4E68-4051-A03F-6FED6325208E}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe
FirewallRules: [{F10800EE-6756-42A1-90CE-E427CBF539D4}] => (Allow) C:\Program Files (x86)\GoforFiles\goforfilesdl.exe
FirewallRules: [{2A7DDAB2-DC52-4CDE-8F1E-986F1FDAE3DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe
FirewallRules: [{450E7BEE-4B21-4DC6-8DD0-9F3EB17E10DA}] => (Allow) C:\Program Files (x86)\GoforFiles\GoforFiles.exe
C:\Users\Lada\AppData\Local\Temp
End
*****************
Processes closed successfully.
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AROReminder => value removed successfully
C:\Program Files (x86)\ARO 2013 => moved successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92e7bc9c-bc36-42d4-9013-65e387115066}" => key removed successfully
HKCR\Wow6432Node\CLSID\{92e7bc9c-bc36-42d4-9013-65e387115066} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{92e7bc9c-bc36-42d4-9013-65e387115066} => value removed successfully
HKCR\Wow6432Node\CLSID\{92e7bc9c-bc36-42d4-9013-65e387115066} => key not found.
HKU\S-1-5-21-2831377403-1237323822-844494322-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.578_0\npbrowserext.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda\10.13.20.29_0\plugins/np-cwmp.dll => not found.
C:\Users\Lada\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde\1.1_0\DeltaChromeToolbar.dll => not found.
C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll => not found.
C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => not found.
C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll => not found.
C:\Windows\SysWOW64\npDeployJava1.dll => not found.
c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll => not found.
C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057.exe => moved successfully
C:\Users\Lada\Downloads\mbam-setup-2.1.8.1057 (1).exe => moved successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{29F16449-4E68-4051-A03F-6FED6325208E} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F10800EE-6756-42A1-90CE-E427CBF539D4} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2A7DDAB2-DC52-4CDE-8F1E-986F1FDAE3DA} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{450E7BEE-4B21-4DC6-8DD0-9F3EB17E10DA} => value removed successfully
"C:\Users\Lada\AppData\Local\Temp" folder move:
Could not move "C:\Users\Lada\AppData\Local\Temp" => Scheduled to move on reboot.
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-09-16 13:06:50)<=
C:\Users\Lada\AppData\Local\Temp => moved successfully
==== End of Fixlog 13:06:50 ====


Přispějete na provoz fóra?