Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu, děkuji

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu, děkuji

#31 Příspěvek od altrok »

:arrow: Slozka C:\Users\Lukáš Kilhof\AppData\Local\NetworkTiles je prazdna, takze ji smazte.



:arrow: Ulozte na plochu ESET Online Scanner kliknutim na esetsmartinstaller_csy.exe
  • ulozeny esetsmartinstaller_csy.exe dvojklikem spustte
  • zaskrtnete Ano, souhlasim s podminkami uziti a kliknete na Spustit
  • vyberte moznost Povolit detekci nechtenych aplikaci
  • rozkliknete moznost Rozsirene nastaveni a
    • zruste zatrzitko u volby Odstranit nalezene infiltrace
    • ponechte zatrhnutou moznost Pouzit technologii Anti-Stealth
  • kliknete na Kontrola, cimz se spusti az nekolikahodinovy sken
  • po dokonceni skenu kliknete na Seznam nalezenych infiltraci (v pripade zadneho nalezu log nevytvorite)
  • kliknete na Ulozit do textoveho souboru, log pojmenujte jako ESETlog a ulozte na plochu
  • obsah logu vlozte do pristi odpovedi
  • kliknete na << Zpet a zatrhnete moznost Odinstalovat
  • klikem na Dokoncit ESET Online Scanner zavrete.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

artmle9
Návštěvník
Návštěvník
Příspěvky: 108
Registrován: 27 úno 2009 11:21

Re: Prosím o kontrolu, děkuji

#32 Příspěvek od artmle9 »

Nebylo nalezeno nic, ovšem problém stále stejný.

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu, děkuji

#33 Příspěvek od altrok »

Udelejte vlastni sken vsech disku pomoci MBAMu (pred tim jste dal pouze custom scan) - http://forum.viry.cz/viewtopic.php?f=29&t=144868
Upozorneni: tento sken zabere od 30 minut po nekolik hodin.



Problem pozorujete jen v jednom prohlizeci?
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

artmle9
Návštěvník
Návštěvník
Příspěvky: 108
Registrován: 27 úno 2009 11:21

Re: Prosím o kontrolu, děkuji

#34 Příspěvek od artmle9 »

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 16.12.2015
Čas skenování: 18:59
Protokol: Výsledek.txt
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2015.12.16.04
Databáze rootkitů: v2015.12.07.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 10
CPU: x64
Souborový systém: NTFS
Uživatel: Lukáš Kilhof

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 674488
Uplynulý čas: 3 hod, 47 min, 25 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 0
(Nenalezeny žádné škodlivé položky)

Hodnoty registru: 0
(Nenalezeny žádné škodlivé položky)

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 7
Trojan.Agent, D:\Instalace\KOD2\call of duty 2 crack serial keygen multiplayer by kolmao\Call_of_Duty_2_KEYGEN-Jesus.rar, , [cdf7c5e06823e55182a841a7a25ff010],
PUP.Optional.ThinkTanks, C:\FRST\Quarantine\C\zoek_backup\zoek_backup\C_PROGRA~2_WinToFlash Suggestor\AddressBarInstance.dll, , [368ecbda1576d36373022c7c8a7a966a],
PUP.Optional.ThinkTanks, C:\FRST\Quarantine\C\zoek_backup\zoek_backup\C_PROGRA~2_WinToFlash Suggestor\RestartIE.exe, , [5173b6ef5239bc7ad0a521878d774db3],
PUP.Optional.ThinkTanks, C:\FRST\Quarantine\C\zoek_backup\zoek_backup\C_PROGRA~2_WinToFlash Suggestor\SMBarBroker.exe, , [477de6bf95f6b5812c495c4c897b30d0],
PUP.Optional.WinToFlashSuggestor, C:\FRST\Quarantine\C\zoek_backup\zoek_backup\C_PROGRA~2_WinToFlash Suggestor\Uninstall.exe, , [f3d1762f92f9122490b6cb68926ff709],
PUP.Optional.ThinkTanks, C:\FRST\Quarantine\C\zoek_backup\zoek_backup\C_PROGRA~2_WinToFlash Suggestor\WinToFlashSuggestor.dll, , [f2d27b2a7d0ece686c09c3e56b99b54b],
Trojan.Agent, C:\Wswin\WsWinAprs.exe, , [a81c2b7ae5a642f4cf63de77af5125db],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

artmle9
Návštěvník
Návštěvník
Příspěvky: 108
Registrován: 27 úno 2009 11:21

Re: Prosím o kontrolu, děkuji

#35 Příspěvek od artmle9 »

Včera jsem chvíli používal IE a zdá se, že tam se to nestává.

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu, děkuji

#36 Příspěvek od altrok »

  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    Folder: C:\Wswin
    C:\Wswin\WsWinAprs.exe
    End



:arrow: Dejte pak jeste prosim logy FRST.txt a Addition.txt - pri druhem a dalsim spusteni je pro vytvoreni logu Addition.txt nutne tuto volbu explicitne zatrhnout pred zacatkem skenu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

artmle9
Návštěvník
Návštěvník
Příspěvky: 108
Registrován: 27 úno 2009 11:21

Re: Prosím o kontrolu, děkuji

#37 Příspěvek od artmle9 »

Ještě otázečka, mám odstranit soubory co našel Malwarebytes Anti-Malware? viz. : Na základě rozhodnutí rádce, označte soubory, jež budou odstraněny ...

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu, děkuji

#38 Příspěvek od altrok »

:arrow: Neodstranujte - ty aktivni odstranuji v nasledujicim kroku (fixlistem).
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

artmle9
Návštěvník
Návštěvník
Příspěvky: 108
Registrován: 27 úno 2009 11:21

Re: Prosím o kontrolu, děkuji

#39 Příspěvek od artmle9 »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:19-12-2015
Ran by Lukáš Kilhof (administrator) on LK-PC (20-12-2015 12:48:51)
Running from C:\Users\Lukáš Kilhof\Desktop
Loaded Profiles: Lukáš Kilhof (Available Profiles: Lukáš Kilhof & DefaultAppPool)
Platform: Windows 10 Home (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files\ATKGFNEX\GFNEXSrv.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(ASUSTeK Computer Inc.) C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe
() C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\ASPG.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ASUS) C:\Windows\AsScrPro.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
() C:\Windows\vsnpstd3.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16565_none_1162030161f5c19b\TiWorker.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [3738344 2015-10-09] (ELAN Microelectronics Corp.)
HKLM\...\Run: [snpstd3] => C:\WINDOWS\vsnpstd3.exe [835584 2007-05-10] ()
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3738344 2015-10-09] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2244096 2009-07-13] (VIA)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe [8493624 2009-07-07] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe [159744 2009-04-20] (ASUS)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort12reminder] => C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe [328992 2010-02-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2011-04-20] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-07-20] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7004376 2015-11-28] (AVAST Software)
HKU\S-1-5-21-563694034-3119439484-3167028291-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-563694034-3119439484-3167028291-1000\...\RunOnce: [Uninstall C:\Users\Luk�a Kilhof\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Lukáš Kilhof\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-11-28] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{5f49ab4a-a68a-49eb-b047-79036642765b}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-563694034-3119439484-3167028291-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-28] (AVAST Software)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-28] (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-28] (Oracle Corporation)
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/CZ/Core/Player/2020PlayerAX_IKEA_Win32.cab

FireFox:
========
FF ProfilePath: C:\Users\Lukáš Kilhof\AppData\Roaming\Mozilla\Firefox\Profiles\eewe149m.default
FF NewTab: about:newtab
FF Homepage: hxxps://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-09] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2012-04-14] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-28] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Extension: Google Translator for Firefox - C:\Users\Lukáš Kilhof\AppData\Roaming\Mozilla\Firefox\Profiles\eewe149m.default\extensions\translator@zoli.bod.xpi [2015-11-29]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-28]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ATKGFNEXSrv; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [94208 2007-08-08] () [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [174416 2015-11-28] (AVAST Software)
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [File not signed]
R2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [402432 2009-07-30] (Red Bend Ltd.) [File not signed]
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144104 2015-10-09] (ELAN Microelectronics Corp.)
R2 FastBootAgent; C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe [306232 2009-07-24] (ASUSTeK Computer Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S2 MySql; C:\apache\mysql\bin\mysqld-nt.exe [1089536 2001-01-22] () [File not signed]
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.)
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-07-20] (Western Digital Technologies, Inc.)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [306552 2015-07-20] (Western Digital Technologies, Inc.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [1048576 2009-07-30] (Intel(R) Corporation) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S3 wxpSvc; C:\Program Files (x86)\webcamXP 5\wService.exe [5023744 2011-07-27] (Moonware Studios) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASMMAP64; C:\Program Files\ATKGFNEX\ASMMAP64.sys [14904 2007-07-24] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-11-28] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-11-28] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-11-28] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-11-28] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-28] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-28] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [154256 2015-11-28] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-11-28] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athwbx.sys [3837440 2013-08-14] (Qualcomm Atheros Communications, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2015-08-20] (DT Soft Ltd)
R1 eusk2par; C:\Windows\system32\Drivers\eusk2par-amd64.sys [32336 2008-12-18] (Aladdin Knowledge Systems Ltd.)
S3 HTCAND64; C:\Windows\System32\Drivers\ANDROIDUSB.sys [33736 2009-11-02] (HTC, Corporation) [File not signed]
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [15416 2009-07-20] ( )
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
S3 SNPSTD3; C:\Windows\system32\DRIVERS\snpstd3.sys [10916352 2009-07-03] (Sonix Co. Ltd.)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 whfltr2k; C:\Windows\System32\DRIVERS\whfltr2k.sys [9600 2007-01-26] () [File not signed]
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-20 12:47 - 2015-12-20 12:47 - 00016148 _____ C:\WINDOWS\system32\LK-PC_Lukáš Kilhof_HistoryPrediction.bin
2015-12-16 18:57 - 2015-12-16 18:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-14 21:32 - 2015-12-14 21:32 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Local\NetworkTiles
2015-12-13 11:51 - 2015-12-13 11:51 - 00001264 _____ C:\Users\Lukáš Kilhof\Desktop – zástupce.lnk
2015-12-12 16:19 - 2015-12-12 16:40 - 00263040 _____ C:\TDSSKiller.3.1.0.8_12.12.2015_16.19.48_log.txt
2015-12-12 14:51 - 2015-12-12 16:12 - 00000000 ____D C:\KVRT_Data
2015-12-10 19:08 - 2015-12-16 18:57 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-10 19:08 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-12-10 19:08 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-12-10 08:57 - 2015-12-10 08:57 - 00000000 ____D C:\Users\Luk▀▄ Kilhof\AppData\LocalLow\Sun
2015-12-09 08:07 - 2015-12-09 08:12 - 00000000 ____D C:\AdwCleaner
2015-12-08 19:57 - 2015-12-01 08:01 - 02115936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-12-08 19:57 - 2015-12-01 06:51 - 07523840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-12-08 19:57 - 2015-12-01 05:59 - 05455360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-12-08 19:57 - 2015-11-25 06:42 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-12-08 19:57 - 2015-11-25 06:41 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-12-08 19:57 - 2015-11-25 06:33 - 03622272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-12-08 19:57 - 2015-11-25 06:27 - 01366680 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2015-12-08 19:57 - 2015-11-25 06:12 - 04047288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-12-08 19:57 - 2015-11-25 06:11 - 01532984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-12-08 19:57 - 2015-11-25 06:09 - 01310880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2015-12-08 19:57 - 2015-11-25 06:01 - 02879024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-12-08 19:57 - 2015-11-25 05:49 - 01569280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.dll
2015-12-08 19:57 - 2015-11-25 05:48 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAMediaManager.dll
2015-12-08 19:57 - 2015-11-25 05:44 - 21872640 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-12-08 19:57 - 2015-11-25 05:42 - 24592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-12-08 19:57 - 2015-11-25 05:37 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-12-08 19:57 - 2015-11-25 05:36 - 01710592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2015-12-08 19:57 - 2015-11-25 05:35 - 00929792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-12-08 19:57 - 2015-11-25 05:35 - 00845824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Magnify.exe
2015-12-08 19:57 - 2015-11-25 05:34 - 12504576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-12-08 19:57 - 2015-11-25 05:31 - 00121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAMM.dll
2015-12-08 19:57 - 2015-11-25 05:30 - 00171008 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3mm.dll
2015-12-08 19:57 - 2015-11-25 05:30 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2015-12-08 19:57 - 2015-11-25 05:29 - 01649152 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2015-12-08 19:57 - 2015-11-25 05:29 - 00355328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ninput.dll
2015-12-08 19:57 - 2015-11-25 05:28 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-12-08 19:57 - 2015-11-25 05:28 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
2015-12-08 19:57 - 2015-11-25 05:27 - 02180608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-12-08 19:57 - 2015-11-25 05:25 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-12-08 19:57 - 2015-11-25 05:23 - 19323392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-12-08 19:57 - 2015-11-25 05:23 - 03588096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-12-08 19:57 - 2015-11-25 05:23 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-12-08 19:57 - 2015-11-25 05:22 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2015-12-08 19:57 - 2015-11-25 05:22 - 01383424 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-12-08 19:57 - 2015-11-25 05:22 - 00603648 _____ (Microsoft Corporation) C:\WINDOWS\system32\duser.dll
2015-12-08 19:57 - 2015-11-25 05:19 - 01795584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-12-08 19:57 - 2015-11-25 05:18 - 01233920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Globalization.dll
2015-12-08 19:57 - 2015-11-25 05:17 - 00774656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-12-08 19:57 - 2015-11-25 05:16 - 01442816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2015-12-08 19:57 - 2015-11-25 05:16 - 00786432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Magnify.exe
2015-12-08 19:57 - 2015-11-25 05:13 - 02153984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-12-08 19:57 - 2015-11-25 05:11 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ninput.dll
2015-12-08 19:57 - 2015-11-25 05:10 - 18801664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-12-08 19:57 - 2015-11-25 05:10 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2015-12-08 19:57 - 2015-11-25 05:10 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
2015-12-08 19:57 - 2015-11-25 05:08 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2015-12-08 19:57 - 2015-11-25 05:05 - 11263488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-12-08 19:57 - 2015-11-25 05:04 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2015-12-08 19:57 - 2015-11-25 05:04 - 00480768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\duser.dll
2015-12-08 19:57 - 2015-11-25 05:04 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2015-12-08 19:56 - 2015-12-01 07:03 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\gpuenergydrv.sys
2015-12-08 19:56 - 2015-12-01 06:54 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-12-08 19:56 - 2015-12-01 06:49 - 04792320 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-12-08 19:56 - 2015-12-01 06:02 - 03580416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-12-08 19:56 - 2015-11-25 06:42 - 00168288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.exe
2015-12-08 19:56 - 2015-11-25 06:40 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-12-08 19:56 - 2015-11-25 06:32 - 00113184 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2015-12-08 19:56 - 2015-11-25 05:59 - 00092992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2015-12-08 19:56 - 2015-11-25 05:49 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2015-12-08 19:56 - 2015-11-25 05:49 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-12-08 19:56 - 2015-11-25 05:49 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2015-12-08 19:56 - 2015-11-25 05:48 - 00146944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EthernetMediaManager.dll
2015-12-08 19:56 - 2015-11-25 05:36 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usb8023.sys
2015-12-08 19:56 - 2015-11-25 05:30 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2015-12-08 19:56 - 2015-11-25 05:26 - 00849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-12-08 19:56 - 2015-11-25 05:26 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-12-08 19:56 - 2015-11-25 05:25 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2015-12-08 19:56 - 2015-11-25 05:22 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbdgeoqw.dll
2015-12-08 19:56 - 2015-11-25 05:22 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDAZST.DLL
2015-12-08 19:56 - 2015-11-25 05:22 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDAZEL.DLL
2015-12-08 19:56 - 2015-11-25 05:22 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDAZE.DLL
2015-12-08 19:56 - 2015-11-25 05:19 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-12-08 19:56 - 2015-11-25 05:10 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-12-08 19:56 - 2015-11-25 05:07 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2015-12-08 19:56 - 2015-11-25 05:04 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbdgeoqw.dll
2015-12-08 19:56 - 2015-11-25 05:04 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDAZST.DLL
2015-12-08 19:56 - 2015-11-25 05:04 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDAZEL.DLL
2015-12-08 19:56 - 2015-11-25 05:04 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDAZE.DLL
2015-12-08 19:56 - 2015-11-25 03:52 - 00775312 _____ C:\WINDOWS\SysWOW64\locale.nls
2015-12-08 19:56 - 2015-11-25 03:52 - 00775312 _____ C:\WINDOWS\system32\locale.nls
2015-12-08 09:24 - 2015-12-08 09:24 - 00000000 ____D C:\Users\LukᚠKilhof\AppData\LocalLow\Sun
2015-12-08 09:23 - 2015-12-08 09:23 - 00000000 ____D C:\Users\Luk▀▄ Kilhof
2015-12-01 19:51 - 2015-12-19 20:30 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-12-01 19:51 - 2015-12-10 19:08 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-01 19:50 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-11-29 11:48 - 2015-12-19 22:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-11-29 11:48 - 2015-12-11 17:19 - 00001248 _____ C:\Users\Lukáš Kilhof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-11-29 11:47 - 2015-11-29 11:47 - 42988160 _____ C:\Users\Lukáš Kilhof\Downloads\Firefox Setup 42.0.exe
2015-11-29 10:27 - 2015-11-29 10:27 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2015-11-29 10:26 - 2015-11-29 10:26 - 00004256 _____ C:\Users\Lukáš Kilhof\Documents\cc_20151129_102617.reg
2015-11-28 23:25 - 2015-11-28 23:25 - 00089900 _____ C:\Users\Lukáš Kilhof\Documents\cc_20151128_232510.reg
2015-11-28 15:28 - 2015-11-28 15:25 - 00386096 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-11-28 15:26 - 2015-12-20 12:41 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-11-28 15:26 - 2015-12-11 17:21 - 00002013 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2015-11-28 15:26 - 2015-11-28 15:26 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Roaming\AVAST Software
2015-11-28 15:26 - 2015-11-28 15:25 - 00273784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-11-28 15:26 - 2015-11-28 15:25 - 00154256 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-11-28 15:25 - 2015-11-28 15:25 - 01059656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-11-28 15:25 - 2015-11-28 15:25 - 00449992 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-11-28 15:25 - 2015-11-28 15:25 - 00097648 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-11-28 15:25 - 2015-11-28 15:25 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-11-28 15:25 - 2015-11-28 15:25 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-11-28 15:25 - 2015-11-28 15:25 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-11-28 15:25 - 2015-11-28 15:25 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-11-28 15:24 - 2015-11-28 15:24 - 00000000 ____D C:\ProgramData\AVAST Software
2015-11-28 15:24 - 2015-11-28 15:24 - 00000000 ____D C:\Program Files\AVAST Software
2015-11-28 14:17 - 2015-11-28 14:18 - 00000000 ____D C:\Program Files (x86)\FileHippo.com
2015-11-28 11:57 - 2015-12-20 08:58 - 00004204 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{CA5749B0-4168-4219-B4F1-443000905E89}
2015-11-28 11:57 - 2015-11-28 11:57 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Local\Chromium
2015-11-26 08:23 - 2015-12-20 12:41 - 00008192 _____ C:\WINDOWS\SysWOW64\WDPABKP.dat
2015-11-22 14:23 - 2015-11-22 14:23 - 00003268 _____ C:\Users\Lukáš Kilhof\Documents\cc_20151122_142350.reg
2015-11-22 14:23 - 2015-11-22 14:23 - 00003268 _____ C:\Users\Lukáš Kilhof\Documents\cc_20151122_142303.reg
2015-11-22 14:22 - 2015-11-22 14:22 - 00003268 _____ C:\Users\Lukáš Kilhof\Documents\cc_20151122_142155.reg
2015-11-22 14:21 - 2015-11-22 14:21 - 00010280 _____ C:\Users\Lukáš Kilhof\Documents\cc_20151122_142109.reg
2015-11-22 14:20 - 2015-11-22 14:20 - 00117486 _____ C:\Users\Lukáš Kilhof\Documents\cc_20151122_142008.reg
2015-11-22 14:02 - 2015-11-22 14:11 - 00000000 ____D C:\wdisplay
2015-11-22 10:15 - 2015-12-20 12:38 - 00000000 ____D C:\Wswin

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-20 12:48 - 2015-02-25 20:03 - 00000000 ____D C:\FRST
2015-12-20 12:39 - 2015-07-10 13:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-20 12:39 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-12-20 12:39 - 2014-07-01 17:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-12-20 12:34 - 2015-04-04 08:11 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-19 22:20 - 2015-08-07 16:06 - 00000000 ____D C:\Users\Lukáš Kilhof
2015-12-19 20:24 - 2015-07-10 12:04 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-19 20:24 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-19 20:17 - 2009-10-01 06:02 - 00001859 _____ C:\WINDOWS\system32\ServiceFilter.ini
2015-12-15 21:01 - 2015-07-10 10:05 - 00000000 ____D C:\Windows
2015-12-12 21:49 - 2012-06-17 09:45 - 00002259 _____ C:\WINDOWS\epplauncher.mif
2015-12-12 16:13 - 2012-06-17 12:22 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Roaming\Tyre
2015-12-11 17:21 - 2015-10-19 15:39 - 00002523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-11 17:21 - 2015-08-14 15:37 - 00002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-12-11 17:21 - 2015-08-07 16:15 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-12-11 17:21 - 2015-03-15 18:28 - 00001154 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pixillion Image Converter.lnk
2015-12-11 17:21 - 2013-08-27 16:26 - 00001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
2015-12-11 17:21 - 2013-01-26 21:59 - 00001295 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2015-12-11 17:21 - 2012-08-29 20:41 - 00001364 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-12-11 17:21 - 2012-08-02 21:21 - 00001432 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-12-11 17:21 - 2012-08-02 21:20 - 00002508 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-12-11 17:21 - 2012-06-17 12:13 - 00001104 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-12-11 17:21 - 2009-10-01 05:57 - 00001204 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
2015-12-11 17:21 - 2009-10-01 05:48 - 00000999 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat.com.lnk
2015-12-11 17:20 - 2015-08-23 18:41 - 00001192 _____ C:\Users\Lukáš Kilhof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Telegram.lnk
2015-12-11 17:20 - 2015-08-07 16:35 - 00002418 _____ C:\Users\Lukáš Kilhof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-12-11 17:20 - 2015-08-07 16:33 - 00001049 _____ C:\Users\Lukáš Kilhof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Volitelné funkce.lnk
2015-12-11 17:20 - 2013-03-26 19:07 - 00001868 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Software Updates.lnk
2015-12-11 16:47 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\rescache
2015-12-11 16:33 - 2013-02-13 17:41 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-12-11 16:01 - 2015-08-07 16:30 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Local\Packages
2015-12-09 19:57 - 2014-06-21 06:58 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Local\Adobe
2015-12-09 19:50 - 2015-07-10 13:20 - 00339520 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-09 08:23 - 2015-08-07 16:04 - 02039120 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-09 08:23 - 2015-07-10 17:02 - 00843554 _____ C:\WINDOWS\system32\perfh005.dat
2015-12-09 08:23 - 2015-07-10 17:02 - 00192782 _____ C:\WINDOWS\system32\perfc005.dat
2015-12-09 08:23 - 2015-07-10 12:02 - 00000000 ____D C:\WINDOWS\INF
2015-12-09 08:16 - 2013-03-14 08:07 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-12-09 08:16 - 2013-03-14 08:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-12-09 08:13 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-12-09 04:39 - 2012-06-17 09:49 - 00301728 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-12-08 20:28 - 2009-10-01 05:28 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-08 20:27 - 2013-03-14 08:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-12-08 20:25 - 2015-07-10 11:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-12-08 20:24 - 2013-07-25 14:09 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-12-08 20:18 - 2012-12-01 20:57 - 140158008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-12-05 19:21 - 2014-10-26 12:51 - 00004030 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-05 19:21 - 2014-10-26 12:51 - 00003798 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-01 01:32 - 2015-10-05 14:19 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-12-01 01:32 - 2015-10-05 14:19 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-29 10:27 - 2012-06-17 10:18 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-11-28 23:20 - 2009-10-01 06:02 - 00002476 _____ C:\WINDOWS\system32\AutoRunFilter.ini
2015-11-28 22:03 - 2013-08-17 17:07 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\LocalLow\KMPlayer
2015-11-28 16:00 - 2012-06-17 12:15 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Local\Google
2015-11-28 16:00 - 2012-06-17 12:15 - 00000000 ____D C:\Program Files (x86)\Google
2015-11-28 14:19 - 2012-06-17 12:22 - 00000000 ____D C:\ProgramData\Tyre
2015-11-28 13:20 - 2014-11-30 17:40 - 00000000 ____D C:\ProgramData\Oracle
2015-11-28 13:16 - 2014-11-30 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-11-28 13:16 - 2012-08-31 20:09 - 00000000 ____D C:\Program Files (x86)\Java
2015-11-28 13:15 - 2015-09-11 06:59 - 00000000 ____D C:\Users\Lukáš Kilhof\.oracle_jre_usage
2015-11-28 13:15 - 2012-08-31 20:10 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-11-22 20:29 - 2013-12-26 22:47 - 00000000 ____D C:\Program Files (x86)\Weather Capture Advance
2015-11-22 14:18 - 2015-08-07 16:56 - 00000000 ___DC C:\WINDOWS\Panther
2015-11-22 14:18 - 2012-10-18 16:40 - 00000000 ____D C:\Users\Lukáš Kilhof\AppData\Roaming\DAEMON Tools Lite
2015-11-22 14:16 - 2015-07-10 12:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-11-22 14:16 - 2014-09-04 12:51 - 00000000 ____D C:\Users\Lukáš Kilhof\Documents\ReceptyData

==================== Files in the root of some directories =======

2007-06-12 17:34 - 2007-06-12 17:34 - 0035822 _____ () C:\Program Files (x86)\Common Files\ASPG_icon.ico
2008-05-22 16:35 - 2008-05-22 16:35 - 0051962 _____ () C:\Program Files (x86)\Common Files\banner.jpg
2009-04-08 18:31 - 2009-04-08 18:31 - 0106496 _____ () C:\Program Files (x86)\Common Files\CPInstallAction.dll
2008-08-12 05:45 - 2008-08-12 05:45 - 0155648 _____ (ASUS) C:\Program Files (x86)\Common Files\MSIactionall.dll
2013-10-26 18:59 - 2013-10-26 18:59 - 0000037 ___SH () C:\Users\Lukáš Kilhof\AppData\Local\70149b02515b3bb20dd492.47983420
2012-12-06 06:47 - 2012-12-06 06:47 - 0003584 _____ () C:\Users\Lukáš Kilhof\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-30 18:00 - 2014-12-30 18:00 - 0000870 _____ () C:\Users\Lukáš Kilhof\AppData\Local\recently-used.xbel
2012-06-17 15:00 - 2012-06-17 15:00 - 0000057 _____ () C:\ProgramData\Ament.ini
2013-07-09 19:17 - 2013-07-09 19:17 - 0000095 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2013-07-09 19:16 - 2013-07-09 19:16 - 0000089 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc
2009-10-01 05:42 - 2009-10-01 05:43 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2009-10-01 05:42 - 2009-10-01 05:42 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-12-20 10:20

==================== End of FRST.txt ============================

artmle9
Návštěvník
Návštěvník
Příspěvky: 108
Registrován: 27 úno 2009 11:21

Re: Prosím o kontrolu, děkuji

#40 Příspěvek od artmle9 »

Additional scan result of Farbar Recovery Scan Tool (x64) Version:19-12-2015
Ran by Lukáš Kilhof (2015-12-20 12:50:28)
Running from C:\Users\Lukáš Kilhof\Desktop
Windows 10 Home (X64) (2015-08-07 15:30:36)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-563694034-3119439484-3167028291-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-563694034-3119439484-3167028291-503 - Limited - Disabled)
Guest (S-1-5-21-563694034-3119439484-3167028291-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-563694034-3119439484-3167028291-1006 - Limited - Enabled)
Lukáš Kilhof (S-1-5-21-563694034-3119439484-3167028291-1000 - Administrator - Enabled) => C:\Users\Lukáš Kilhof

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

AC3Filter 1.63b (HKLM-x32\...\AC3Filter_is1) (Version: 1.63b - Alexander Vigovsky)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Activation Assistant for the 2007 Microsoft Office suites (HKLM-x32\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (x32 Version: 1.0 - Microsoft Corporation) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.009.20079 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.0.7220 - Adobe Systems Inc.)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
Adobe Flash Player 20 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 20.0.0.228 - Adobe Systems Incorporated)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{5A22D889-FBDD-4AE8-86EC-089D45FC133E}) (Version: 1.2.17.25001 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.2.17.25001 - Alcor Micro Corp.) Hidden
Any Video Converter 3.5.5 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com)
AnyPic JPG to PDF Converter 1.0.2 (HKLM-x32\...\{ADD050EC-6B50-437F-807B-FF9F29216FA5}_is1) (Version: - AnyPic Soft)
Apple Application Support (HKLM-x32\...\{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}) (Version: 2.3.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo Burning Studio 6 FREE v.6.81 (HKLM-x32\...\Ashampoo Burning Studio 6 FREE_is1) (Version: 6.8.1 - Ashampoo GmbH & Co. KG)
ASUS AI Recovery (HKLM-x32\...\{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}) (Version: 1.0.6 - ASUS)
ASUS CopyProtect (HKLM-x32\...\{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}) (Version: 1.0.0015 - ASUS)
ASUS FancyStart (HKLM-x32\...\{60D6618B-153F-4353-8185-908E676E5888}) (Version: 1.0.5 - ASUSTeK Computer Inc.)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS)
ASUS MultiFrame (HKLM-x32\...\{9D48531D-2135-49FC-BC29-ACCDA5396A76}) (Version: 1.0.0019 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{1686C4D1-B1FD-42E8-B7A8-FB4C4DBA5BA8}) (Version: 1.1.19 - ASUS)
ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0007 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0028 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.17 - asus)
Asus_Camera_ScreenSaver (HKLM-x32\...\Asus_Camera_ScreenSaver) (Version: 2.0.0009 - ASUS)
Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.16 - Atheros Communications Inc.)
ATK Generic Function Service (HKLM-x32\...\{D3D54F3E-C5C3-443D-978F-87A72E5616E8}) (Version: 1.00.0008 - ATK)
ATK Hotkey (HKLM-x32\...\{7C05592D-424B-46CB-B505-E0013E8E75C9}) (Version: 1.0.0051 - ASUS)
ATK Media (HKLM-x32\...\{D1E5870E-E3E5-4475-98A6-ADD614524ADF}) (Version: 2.0.0005 - ASUS)
ATKOSD2 (HKLM-x32\...\{3B05F2FB-745B-4012-ADF2-439F36B2E70B}) (Version: 7.0.0005 - ASUS)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2241 - AVAST Software)
Brother MFL-Pro Suite DCP-7065DN (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.0.9.0 - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 3.19 - Piriform)
CoreAAC Audio Decoder (remove only) (HKLM-x32\...\CoreAAC Audio Decoder) (Version: - )
CropImage 1.00 (HKLM-x32\...\CropImage_is1) (Version: - Milan Travnicek)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.46.1.0328 - DT Soft Ltd)
Defraggler (HKLM\...\Defraggler) (Version: 2.16 - Piriform)
ELAN Touchpad 15.9.5.3_X64_WHQL (HKLM\...\Elantech) (Version: 15.9.5.3 - ELAN Microelectronic Corp.)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.3 - ASUS)
FormatFactory 2.95 (HKLM-x32\...\FormatFactory) (Version: 2.95 - Free Time)
Fotogalerie (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Free YouTube to MP3 Converter version 3.12.46.923 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.46.923 - DVDVideoSoft Ltd.)
GIMP 2.8.0 (HKLM\...\GIMP-2_is1) (Version: 2.8.0 - The GIMP Team)
Google Earth (HKLM-x32\...\{28E82311-8616-11E1-BEB0-B8AC6F97B88E}) (Version: 6.2.2.6613 - Google)
Google Earth Pro (HKLM-x32\...\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2021 - Intel Corporation)
Intel® PROSet/Wireless WiMAX Software (HKLM\...\{FAE224AF-B15E-448B-88FA-1839A7570CF8}) (Version: 1.04.0000 - Intel Corporation)
Java 8 Update 66 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218066F0}) (Version: 8.0.660.18 - Oracle Corporation)
Jpeg Resampler Vs 6+ (HKLM-x32\...\JpegResampler2010_is1) (Version: - Jpeg Resampler)
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
KMPlayer (HKLM-x32\...\The KMPlayer) (Version: 3.9.1.135 - PandoraTV)
Malwarebytes Anti-Malware verze 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
MKVToolNix 5.6.0 (HKLM-x32\...\MKVToolNix) (Version: 5.6.0 - Moritz Bunkus)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 43.0.1 (x86 cs) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 cs)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Need for Speed Underground 2 (HKLM-x32\...\{909F8EBC-EC7F-48FF-0085-475D818F0F31}) (Version: - )
NCH Toolbox (HKLM-x32\...\ToolBox) (Version: - NCH Software)
Nuance PaperPort 12 (HKLM-x32\...\{DA715959-CFF1-48A2-B3BB-98B9E569C6AC}) (Version: 12.1.0000 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
Old Calculator for Windows 10 (HKLM-x32\...\OldCalcForWin10) (Version: 1.0 - hxxp://winaero.com)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
PDFTools Version 1.3 (08/26/2007) (HKLM-x32\...\PDFTools_is1) (Version: 1.3 - www.SheelApps.com - Sheel Khanna)
Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden
Pracovní kalendář (HKLM-x32\...\Pracovní kalendář) (Version: - )
Quicksys RegDefrag 2.9 (HKLM-x32\...\{5D26BF7B-BEF6-477D-8FC1-0C1C159B6364}_is1) (Version: - )
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
rajče průvodce verze 1.59.40.255 (HKLM-x32\...\rajče.net_is1) (Version: - rajče.net)
Recover Files 3.31 (HKLM-x32\...\Recover Files_is1) (Version: - Undelete & Unerase, Inc.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Richard Burns Rally (HKLM-x32\...\{92C7D009-A464-4948-A980-7A3E28CB2F49}_is1) (Version: 1.0 - US - ACTION, s.r.o.)
Scansoft PDF Professional (x32 Version: - ) Hidden
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartClock 2.1 (HKLM-x32\...\SmartClock) (Version: - )
TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.22298 - TeamViewer)
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: 8.51 - Ghisler Software GmbH)
Trust Webcam (HKLM-x32\...\{ECD03DA7-5952-406A-8156-5F0C93618D1F}) (Version: 5.18.1211.103 - Sonix)
Tyre (HKLM\...\Tyre_is1) (Version: 6.4.4.1 - 't Schrijverke)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
UxStyle Core Beta (HKLM\...\{8E363055-15E5-4D8A-9C69-A0A9DE9A3337}) (Version: 0.2.1.1 - The Within Network, LLC)
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.)
WD Quick View (HKLM-x32\...\{10E4655D-047D-472A-AE5C-CCEF665B47E8}) (Version: 2.4.12.1 - Western Digital Technologies, Inc.)
WD SmartWare (HKLM\...\{17A76C9D-91D4-4E01-922D-1B3000DEB9F1}) (Version: 2.4.12.1 - Western Digital Technologies, Inc.)
WD SmartWare Installer (HKLM-x32\...\{979a4332-3eb0-4561-9f74-a4fb871cf2bd}) (Version: 2.4.12.1 - Western Digital Technologies, Inc.)
Weather Capture Advance (HKLM-x32\...\{E10017D0-CDC3-4205-87F8-B1AC58124DE9}_is1) (Version: - )
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{4B4451CE-D1E6-4BDE-B4B2-59F03BB83B7C}) (Version: 14.0.8050.1202 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.26.0 - ASUS)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.10 - ASUS)
WsWin V2.98.0 - 2015-08-31 (HKLM-x32\...\PC-Wetterstation_is1) (Version: 2.98.0 - Werner Krenn)
Xvid 1.2.2 final uninstall (HKLM-x32\...\Xvid_is1) (Version: 1.2 - Xvid team (Koepi))

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

05-12-2015 18:58:23 Naplánovaný kontrolní bod
08-12-2015 08:36:04 zoek.exe restore point
08-12-2015 19:51:25 JRT Pre-Junkware Removal
11-12-2015 15:58:24 dbes
19-12-2015 22:06:04 Naplánovaný kontrolní bod

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2015-12-10 08:10 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts


127.0.0.1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {005C09B9-13E3-48F4-9851-6B4FF0639F50} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {01C995FF-D178-4E7B-AC4A-9E950006A207} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {0837D897-84CB-4E30-A8DD-807937A81DFC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {0F1FC558-90E6-41AA-8D37-4FBE69053762} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {148318FC-5974-4508-A415-B3AFD16E5DDB} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {1C77D171-4A67-4470-89BA-6252929BC9CA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {29308477-8F7E-4D4F-92D5-F1534E61B6F5} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {2AFDB3D3-02A5-4F39-B732-9E90184F1514} - \Ball Form -> No File <==== ATTENTION
Task: {2C53893E-00E8-4E50-A00A-B724E06988CA} - System32\Tasks\{D09FAE56-5A9B-41F1-B1C3-246D720EF022} => C:\Program Files (x86)\Network Stumbler\NetStumbler.exe
Task: {2FFCF9C3-61EE-4659-9F8F-729AF7B9CD80} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
Task: {301166CC-3CD0-4627-B480-9A010C0636F5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-09] (Adobe Systems Incorporated)
Task: {313E2F38-6D00-4DAC-90D9-C596BAF49F0D} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {33802523-AB21-4F8F-A10C-77AA33B098E1} - System32\Tasks\{F24BF22E-2FFB-432B-8FB3-BE7512B8A11A} => pcalua.exe -a "C:\Program Files (x86)\Nuance\PaperPort\ScannerWizardU.exe" -c /A [PaperPort 12.1] /L [czh]
Task: {3496A396-D5D1-414F-AB8F-1F0060379788} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2009-07-29] (ATK)
Task: {3C9616B2-742C-4820-AFAE-F3D2459E9677} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {3D966D87-5FE5-4FBC-8E90-DB0F48E454DB} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {3E3E65EA-6693-4ACC-947D-206853F50D65} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {3E84B87D-E72F-4682-9C7A-EE47F15B150A} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe
Task: {42145BE5-4059-431F-919A-1A381C5966DE} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {4AB58050-BE96-4FE1-AEFE-2F1EB2597D5A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {5A3F1012-0F07-4730-A478-1D72DEE3EF78} - System32\Tasks\NCH Software\ExpressBurnSevenDays => C:\Program Files (x86)\NCH Software\ExpressBurn\ExpressBurn.exe
Task: {63B6CC4D-92BE-47CF-81C4-6FE592788A70} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {6436DE78-1813-4690-9DBD-30658CCBFD03} - System32\Tasks\{8A7892DF-9BE2-4249-9409-E3CC635B980B} => C:\Program Files (x86)\WS32\Wswin32.exe
Task: {67A4DA67-AA40-44A6-84C4-93B0EBC4599B} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {67BA13F5-23BA-4ECC-903C-924D2464AD8B} - System32\Tasks\WC3 => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2009-07-24] ()
Task: {6C265910-FA5A-4220-928A-2F837DEDD469} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {6CDD8F65-9A1F-42C2-8749-C95235BC06DA} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {6FECF9BE-AED8-4627-80ED-91FF5361960F} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {773492A6-4F08-4DAF-9C1B-778BC17ACAED} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {78588675-6CF3-4E50-B5B1-1EC34EAA2F6B} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {7DDF9673-8D0B-4652-B795-1BEAD1206B65} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {85EDAE30-84D9-42C7-B93D-A0C926CCDE87} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01] (Google Inc.)
Task: {8815C381-04BB-44AE-AAFE-2A6806E2106E} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK)
Task: {8928834D-9A64-48C2-B6AA-4DA410F020C1} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-12-08] (Microsoft Corporation)
Task: {8955A4AD-F32B-43CA-BDCC-09AF9ECD3416} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-11-28] (AVAST Software)
Task: {8EABE69A-8617-435F-8F98-AFAB8F43B7A7} - \ASUSControlDeck -> No File <==== ATTENTION
Task: {90DEFD96-8D9E-48B2-8582-D317B804BDCB} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {9705D9EB-1D45-4922-BA16-15AE241B3E9C} - System32\Tasks\{AB2C805F-7EC5-4878-84C6-013C49A34901} => C:\Program Files (x86)\Network Stumbler\NetStumbler.exe
Task: {9A2D8E71-CCF8-42E7-9973-4E5C76636A9B} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {AA921623-B84A-4EC8-A6DA-5D46323FC6D9} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {B4944A9F-7F4C-4EBF-B50A-42E3D7F08708} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {BE98C7E8-2A03-47B0-8547-748BA88B5988} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS)
Task: {C778374C-94FE-41B0-B705-5FC952201AC0} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {CB14DF3D-517B-48BC-BD72-DDCD3DD1A1F1} - System32\Tasks\{EE69E637-4FF8-478B-A0E7-AEFF0B12D2E6} => C:\Program Files (x86)\Gmail Notifier\Gmail Notifier.exe
Task: {D46443C3-EE5E-4E03-8E84-E5F92F3E36FA} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {DD548504-31EE-43FF-A573-1E9BCB56DC76} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {E3868EE1-AD80-4E22-A106-AC89CA413807} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {E3B7F7F3-C090-48E0-A4BD-8E381FCC9077} - System32\Tasks\hpUrlLauncher.exe_{CA1F916B-B2BD-4D0B-BBB8-88346365F9F3} => C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\utils\hpUrlLauncher.exe
Task: {E4334EF6-4D26-4578-8902-49B26FB5F842} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {E959E007-A71C-4952-8EA8-22DE146D6227} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {F0496437-71B1-4E96-9E9C-3BC2F52CDE46} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {F51C5B4B-29E9-4FFE-9DE9-E009E91A4EA8} - System32\Tasks\{D5471058-19F6-4E7D-999C-C673108949FC} => C:\Program Files (x86)\Network Stumbler\NetStumbler.exe
Task: {FA7F8F84-6FB5-4135-8561-0E896171E9F9} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {FACB8164-0888-403B-B4E6-7F59329EA90F} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {FBC8485F-A585-489F-8E2C-C65FEABC1BEF} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {FF87BC2B-9AB8-40C9-AFD6-6B664988C57E} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-05-18] (ASUS)
Task: {FFEE4F98-789F-4BC5-9EBF-91D4AC658C46} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-08-07 16:51 - 2015-08-07 16:51 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2009-10-01 05:58 - 2007-08-08 08:08 - 00094208 _____ () C:\Program Files\ATKGFNEX\GFNEXSrv.exe
2015-08-19 17:43 - 2015-08-11 10:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2012-08-10 19:29 - 2005-04-22 05:36 - 00143360 ____R () C:\WINDOWS\system32\BrSNMP64.dll
2015-10-01 18:20 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2008-08-14 04:59 - 2008-08-14 04:59 - 00301624 _____ () C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe
2015-10-01 18:20 - 2015-09-17 07:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2009-05-05 18:00 - 2009-05-05 18:00 - 00041472 _____ () C:\Program Files\P4G\DevMng.dll
2009-07-27 18:12 - 2009-07-27 18:12 - 00026624 _____ () C:\Program Files\P4G\OvrClk.dll
2009-10-01 05:58 - 2007-03-10 02:58 - 00124416 _____ () C:\Program Files\ATKGFNEX\AGFNEX64.dll
2008-10-01 07:02 - 2008-10-01 07:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2009-07-24 18:32 - 2009-07-24 18:32 - 01593344 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
2015-10-01 18:19 - 2015-09-17 06:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-12-08 19:57 - 2015-11-25 05:20 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-12-08 19:56 - 2015-11-25 05:17 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-12-08 19:57 - 2015-11-25 05:17 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-01 18:20 - 2015-09-17 06:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2012-08-02 18:06 - 2007-05-10 12:18 - 00835584 _____ () C:\Windows\vsnpstd3.exe
2015-11-28 15:25 - 2015-11-28 15:25 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-11-28 15:25 - 2015-11-28 15:25 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-12-19 20:19 - 2015-12-19 20:19 - 02805760 _____ () C:\Program Files\AVAST Software\Avast\defs\15121901\algo.dll
2015-11-28 15:25 - 2015-11-28 15:25 - 00466448 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-12-20 12:41 - 2015-12-20 12:41 - 02805760 _____ () C:\Program Files\AVAST Software\Avast\defs\15122000\algo.dll
2013-03-26 19:10 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2015-11-28 15:25 - 2015-11-28 15:25 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:66BB1E73

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-563694034-3119439484-3167028291-1000\Control Panel\Desktop\\Wallpaper -> c:\users\lukáš kilhof\appdata\local\microsoft\windows\themes\transcodedwallpaper.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk => C:\Windows\pss\FancyStart daemon.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Lukáš Kilhof^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Trillian.lnk => C:\Windows\pss\Trillian.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Lukáš Kilhof^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^WinMySQLadmin.lnk => C:\Windows\pss\WinMySQLadmin.lnk.Startup
MSCONFIG\startupreg: AmIcoSinglun64 => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
MSCONFIG\startupreg: ETDWare => C:\Program Files\Elantech\ETDCtrl.exe
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: Setwallpaper => c:\programdata\SetWallpaper.cmd
MSCONFIG\startupreg: SmartClock => C:\Program Files (x86)\SmartClock\SmartClock.exe /boot
MSCONFIG\startupreg: snpstd3 => C:\Windows\vsnpstd3.exe
MSCONFIG\startupreg: WD Quick View => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
HKLM\...\StartupApproved\Run32: => "PDF5 Registry Controller"
HKLM\...\StartupApproved\Run32: => "PDFHook"
HKU\S-1-5-21-563694034-3119439484-3167028291-1000\...\StartupApproved\Run: => "OneDrive"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{25660C1A-96CF-41E7-8576-0C9278D1BA10}] => (Allow) C:\Program Files (x86)\webcamXP 5\wService.exe
FirewallRules: [{D10BF82D-6AC1-4763-A15D-0E322B5B5798}] => (Allow) C:\Program Files (x86)\webcamXP 5\wService.exe
FirewallRules: [{B3690465-247D-45CE-8CE8-60719C0E31A8}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [{B5F4DA4A-9230-41D3-B8AB-E97228C98FB4}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [{46A3B2D0-83C7-4519-857D-E412D2F529D8}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{2D294963-B2F7-4E02-8610-FCBF78192742}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{EFC3F968-471E-4F44-8FE9-A6CBE929B1D2}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{C94A48BE-C414-4EC3-8C4A-0B72487B354C}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
FirewallRules: [{73395FDC-047F-4C6B-86FB-0F47CCC4ABE9}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{DD5AD59C-1516-4D59-8D98-07F9CAE26367}] => (Allow) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
FirewallRules: [{9FC444A1-182B-4C17-9AB8-D367DDC2F0EC}] => (Allow) LPort=54925
FirewallRules: [{EF920094-059C-457D-9D74-5D7D22F0016C}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{22B728B1-8ECB-4F5F-9440-46358ED9D096}] => (Allow) LPort=1900
FirewallRules: [{6BDCB331-1D69-442D-B0E9-A519E8728644}] => (Allow) LPort=2869
FirewallRules: [{617BD608-7FCC-4A03-8CCB-F50A785A63CD}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{4F2BA0AC-A8AE-418F-8DCB-BF4AB3E56A31}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{4FC3A7DB-3E3E-4471-9776-483E84D116BF}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{3983DC5B-CC04-406D-A1EA-1FA94B05A259}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{A4749F55-7B46-4DBC-8A22-F8786061D8B0}] => (Allow) C:\Program Files (x86)\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{0D920565-21DA-48BC-8BDA-24189F27C804}] => (Allow) svchost.exe
FirewallRules: [{F387D1A7-92ED-4B28-81F0-97152D3F1240}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{3E8BC249-2206-4397-B9AC-0D99DC9DE096}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{DC48727E-05A6-4E27-98AC-934CFED91B65}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (12/20/2015 12:40:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ElanTPCfg64.exe, verze: 1.0.50.1, časové razítko: 0x49d9c165
Název chybujícího modulu: ETDApi.dll, verze: 11.9.0.0, časové razítko: 0x5448e4ce
Kód výjimky: 0xc0000005
Posun chyby: 0x0000000000008f72
ID chybujícího procesu: 0x1084
Čas spuštění chybující aplikace: 0xElanTPCfg64.exe0
Cesta k chybující aplikaci: ElanTPCfg64.exe1
Cesta k chybujícímu modulu: ElanTPCfg64.exe2
ID zprávy: ElanTPCfg64.exe3
Úplný název chybujícího balíčku: ElanTPCfg64.exe4
ID aplikace související s chybujícím balíčkem: ElanTPCfg64.exe5

Error: (12/20/2015 09:58:57 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: plugin-container.exe, verze: 43.0.1.5828, časové razítko: 0x56723a12
Název chybujícího modulu: mozglue.dll, verze: 43.0.1.5828, časové razítko: 0x56722c0b
Kód výjimky: 0x80000003
Posun chyby: 0x0000ed63
ID chybujícího procesu: 0x6b0
Čas spuštění chybující aplikace: 0xplugin-container.exe0
Cesta k chybující aplikaci: plugin-container.exe1
Cesta k chybujícímu modulu: plugin-container.exe2
ID zprávy: plugin-container.exe3
Úplný název chybujícího balíčku: plugin-container.exe4
ID aplikace související s chybujícím balíčkem: plugin-container.exe5

Error: (12/20/2015 08:57:59 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (6676) Nový soubor protokolu se nedá vytvořit, protože databáze nemůže zapisovat na jednotku protokolu. Jednotka může být jen pro čtení, špatně nakonfigurovaná nebo poškozená nebo na ní nemusí být dost místa. Chyba: -1032

Error: (12/20/2015 08:57:59 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (6676) Pokus o vytvoření souboru C:\WINDOWS\system32\edbtmp.log selhal. Došlo k systémové chybě 5 (0x00000005): Přístup byl odepřen. . Operace vytvoření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (12/20/2015 08:57:49 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (6676) Nový soubor protokolu se nedá vytvořit, protože databáze nemůže zapisovat na jednotku protokolu. Jednotka může být jen pro čtení, špatně nakonfigurovaná nebo poškozená nebo na ní nemusí být dost místa. Chyba: -1032

Error: (12/20/2015 08:57:49 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (6676) Pokus o vytvoření souboru C:\WINDOWS\system32\edbtmp.log selhal. Došlo k systémové chybě 5 (0x00000005): Přístup byl odepřen. . Operace vytvoření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (12/20/2015 08:57:39 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (6676) Nový soubor protokolu se nedá vytvořit, protože databáze nemůže zapisovat na jednotku protokolu. Jednotka může být jen pro čtení, špatně nakonfigurovaná nebo poškozená nebo na ní nemusí být dost místa. Chyba: -1032

Error: (12/20/2015 08:57:39 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (6676) Pokus o vytvoření souboru C:\WINDOWS\system32\edbtmp.log selhal. Došlo k systémové chybě 5 (0x00000005): Přístup byl odepřen. . Operace vytvoření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (12/20/2015 08:57:28 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (6676) Nový soubor protokolu se nedá vytvořit, protože databáze nemůže zapisovat na jednotku protokolu. Jednotka může být jen pro čtení, špatně nakonfigurovaná nebo poškozená nebo na ní nemusí být dost místa. Chyba: -1032

Error: (12/20/2015 08:57:28 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (6676) Pokus o vytvoření souboru C:\WINDOWS\system32\edbtmp.log selhal. Došlo k systémové chybě 5 (0x00000005): Přístup byl odepřen. . Operace vytvoření souboru selže a dojde k chybě -1032 (0xfffffbf8).


System errors:
=============
Error: (12/20/2015 12:40:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba MySql byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (12/20/2015 12:40:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Adaptér naslouchání Net.Pipe neuspěla při spuštění v důsledku následující chyby:
%%1053

Error: (12/20/2015 12:40:28 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Adaptér naslouchání Net.Pipe bylo dosaženo časového limitu (30000 ms).

Error: (12/20/2015 12:40:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Adaptér naslouchání Net.Msmq neuspěla při spuštění v důsledku následující chyby:
%%1053

Error: (12/20/2015 12:40:28 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Adaptér naslouchání Net.Msmq bylo dosaženo časového limitu (30000 ms).

Error: (12/20/2015 12:39:55 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Adaptér naslouchání Net.Tcp závisí na službě Služba sdílení portů Net.Tcp, která neuspěla při spuštění v důsledku následující chyby:
%%1058

Error: (12/20/2015 12:38:59 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {A677570A-2BA2-4E9A-B2E2-8A02CD8B4FD3}

Error: (12/20/2015 12:38:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Přístup k uživatelským datům_Session2 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (12/20/2015 12:38:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Úložiště uživatelských dat_Session2 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (12/20/2015 12:38:54 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Data kontaktů_Session2 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.


CodeIntegrity:
===================================
Date: 2015-12-19 22:14:22.929
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-12-16 22:36:35.733
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2015-12-09 19:04:20.906
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-12-09 19:04:20.798
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-12-09 19:04:20.670
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-12-09 19:04:20.507
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-12-09 19:04:20.427
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-12-09 19:04:20.350
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-12-09 19:04:16.172
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2015-12-09 19:04:15.308
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU T5870 @ 2.00GHz
Percentage of memory in use: 42%
Total physical RAM: 4061.08 MB
Available physical RAM: 2344.14 MB
Total Virtual: 8157.08 MB
Available Virtual: 6468.97 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:232.88 GB) (Free:176.8 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:218.23 GB) (Free:191.71 GB) NTFS
Drive f: () (Removable) (Total:1.86 GB) (Free:0.16 GB) FAT

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: D9B3496E)
Partition 1: (Not Active) - (Size=14.6 GB) - (Type=1C)
Partition 2: (Active) - (Size=232.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=218.2 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 1.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu, děkuji

#41 Příspěvek od altrok »

  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    Folder: C:\Wswin
    Folder: C:\wdisplay
    Folder: C:\Program Files (x86)\WS32
    File: C:\Wswin\WsWinAprs.exe
    C:\Wswin\WsWinAprs.exe
    AlternateDataStreams: C:\ProgramData\Temp:66BB1E73
    End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

artmle9
Návštěvník
Návštěvník
Příspěvky: 108
Registrován: 27 úno 2009 11:21

Re: Prosím o kontrolu, děkuji

#42 Příspěvek od artmle9 »

Fix result of Farbar Recovery Scan Tool (x64) Version:19-12-2015
Ran by Lukáš Kilhof (2015-12-20 16:33:56) Run:5
Running from C:\Users\Lukáš Kilhof\Desktop
Loaded Profiles: Lukáš Kilhof (Available Profiles: Lukáš Kilhof & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
Folder: C:\Wswin
Folder: C:\wdisplay
Folder: C:\Program Files (x86)\WS32
File: C:\Wswin\WsWinAprs.exe
C:\Wswin\WsWinAprs.exe
AlternateDataStreams: C:\ProgramData\Temp:66BB1E73
End
*****************

Processes closed successfully.

========================= Folder: C:\Wswin ========================

2015-11-22 10:15 - 2006-10-19 23:25 - 0017020 _____ () C:\Wswin\current_en.txt
2015-11-22 10:15 - 2005-02-26 19:50 - 0002049 _____ () C:\Wswin\custom_r_.txt
2015-11-22 12:20 - 2015-11-22 12:52 - 0017623 _____ () C:\Wswin\EXP11_15.CSV
2015-11-22 10:15 - 2015-09-07 16:51 - 0196287 _____ () C:\Wswin\info.txt
2015-11-22 10:15 - 2015-09-07 16:51 - 0196287 _____ () C:\Wswin\info_en.txt
2015-11-22 10:15 - 2002-09-20 16:40 - 0086528 _____ () C:\Wswin\lame_enc.dll
2015-11-22 10:15 - 2003-01-11 19:12 - 0009148 _____ () C:\Wswin\libSMBM.js
2015-11-22 10:15 - 2015-07-23 20:13 - 0001254 _____ () C:\Wswin\License_en.txt
2015-11-22 10:15 - 2010-01-05 15:05 - 0009389 _____ () C:\Wswin\sunmoon_.txt
2015-11-22 10:15 - 2005-02-26 19:46 - 0002224 _____ () C:\Wswin\template_d_.txt
2015-11-22 10:15 - 2005-02-26 19:50 - 0018206 _____ () C:\Wswin\template_d_en.txt
2015-11-22 10:15 - 2009-01-24 10:51 - 0002968 _____ () C:\Wswin\template_m_.txt
2015-11-22 10:15 - 2009-01-24 10:49 - 0002933 _____ () C:\Wswin\template_noaa_m_.txt
2015-11-22 10:15 - 2009-01-24 10:50 - 0004455 _____ () C:\Wswin\template_noaa_y_.txt
2015-11-22 10:15 - 2009-01-24 11:46 - 0004668 _____ () C:\Wswin\template_y_.txt
2015-11-22 10:15 - 2005-02-26 19:50 - 0010610 _____ () C:\Wswin\template_yest_.txt
2015-11-22 10:15 - 2005-02-26 19:50 - 0000613 _____ () C:\Wswin\ticker_en.txt
2015-11-22 10:15 - 2015-11-22 10:15 - 0017775 _____ () C:\Wswin\unins000.dat
2015-11-22 10:15 - 2015-11-22 10:15 - 1197409 _____ () C:\Wswin\unins000.exe
2015-11-22 10:15 - 2006-03-07 11:17 - 0045056 _____ () C:\Wswin\USB.dll
2015-11-22 10:15 - 2003-12-22 15:45 - 0001527 _____ () C:\Wswin\wap_.txt
2015-11-22 10:19 - 2015-12-01 08:01 - 0165698 _____ () C:\Wswin\WD_11_15.DAT
2015-12-01 08:01 - 2015-12-20 13:29 - 0082250 _____ () C:\Wswin\WD_12_15.DAT
2015-11-22 10:20 - 2015-12-20 13:29 - 0491530 _____ () C:\Wswin\WD2_2015.DAT
2015-11-22 10:15 - 2002-09-28 21:04 - 0017467 _____ () C:\Wswin\ws_alarm_.wav
2015-11-22 10:20 - 2015-12-20 13:29 - 0001680 _____ () C:\Wswin\ws_ddays.txt
2015-11-22 10:19 - 2015-12-20 13:30 - 0007367 _____ () C:\Wswin\ws_hist.txt
2015-11-22 10:15 - 2005-02-26 19:50 - 0001944 _____ () C:\Wswin\ws_speech_.txt
2015-11-22 10:15 - 2015-09-07 16:43 - 0182073 _____ () C:\Wswin\ws_variables_en.txt
2015-11-22 10:15 - 2001-04-30 09:43 - 0083968 _____ () C:\Wswin\Wsarchiv0.mdb
2015-11-29 09:59 - 2015-11-29 09:59 - 0028346 _____ () C:\Wswin\WSWIN.B~K
2015-11-22 10:15 - 2015-12-20 13:30 - 0028347 _____ () C:\Wswin\WSWIN.CFG
2015-11-22 10:15 - 2007-06-02 16:20 - 0000024 _____ () C:\Wswin\WSWIN.SET
2015-11-22 10:19 - 2015-11-22 10:19 - 0000171 _____ () C:\Wswin\wswin_www.cfg
2015-11-22 10:15 - 2013-02-02 18:48 - 0000660 _____ () C:\Wswin\wswin_x-csv_cumulus.cfg
2015-11-22 10:15 - 2009-03-31 21:55 - 0000578 _____ () C:\Wswin\wswin_x-csv_elv_ws300.cfg
2015-11-22 10:15 - 2009-03-17 17:03 - 0000607 _____ () C:\Wswin\wswin_x-csv_elv_ws550.cfg
2015-11-22 10:15 - 2011-06-09 00:58 - 0001889 _____ () C:\Wswin\wswin_x-csv_envoy8x.cfg
2015-11-22 10:15 - 2011-06-09 22:16 - 0003529 _____ () C:\Wswin\wswin_x-csv_Envoy8x.csv
2015-11-22 10:15 - 2009-12-03 00:49 - 0000545 _____ () C:\Wswin\wswin_x-csv_eusotec_vantage.cfg
2015-11-22 10:15 - 2015-03-01 02:46 - 0000561 _____ () C:\Wswin\wswin_x-csv_hp1000wifi.cfg
2015-11-22 10:15 - 2015-04-01 16:53 - 0000528 _____ () C:\Wswin\wswin_x-csv_hp1000wifi_php.cfg
2015-11-22 10:15 - 2009-03-12 16:40 - 0000295 _____ () C:\Wswin\wswin_x-csv_hygrosens.cfg
2015-11-22 10:15 - 2010-10-06 00:24 - 0000610 _____ () C:\Wswin\wswin_x-csv_logger_te923.cfg
2015-11-22 10:15 - 2009-03-12 16:42 - 0000503 _____ () C:\Wswin\wswin_x-csv_reinhardt_mws.cfg
2015-11-22 10:15 - 2015-08-06 16:42 - 0000635 _____ () C:\Wswin\wswin_x-csv_reinhardt_mws5mv-10.cfg
2015-11-22 10:15 - 2015-08-06 16:47 - 0000518 _____ () C:\Wswin\wswin_x-csv_reinhardt_mws5mv-10x.cfg
2015-11-22 10:15 - 2009-03-17 17:36 - 0000694 _____ () C:\Wswin\wswin_x-csv_tfa-nexus.cfg
2015-11-22 10:15 - 2010-10-06 22:32 - 0000475 _____ () C:\Wswin\wswin_x-csv_wdcsv.cfg
2015-11-22 10:15 - 2009-03-17 17:37 - 0000571 _____ () C:\Wswin\wswin_x-csv_wh1080.cfg
2015-11-22 10:15 - 2011-06-28 18:34 - 0000718 _____ () C:\Wswin\wswin_x-csv_wh3080.cfg
2015-11-22 10:15 - 2012-12-31 12:28 - 0001151 _____ () C:\Wswin\wswin_x-csv_wmr200.cfg
2015-11-22 10:15 - 2014-08-28 20:33 - 0001022 _____ () C:\Wswin\wswin_x-csv_wmr300.cfg
2015-11-22 10:15 - 2005-02-26 19:46 - 0043289 _____ () C:\Wswin\wswin_xml_.txt
2015-11-22 10:15 - 2015-09-08 18:15 - 2042880 _____ (none) C:\Wswin\Wswin32.exe
2015-11-22 10:15 - 2015-08-01 01:44 - 8526859 _____ () C:\Wswin\WSWIN32.HLP
2015-11-22 12:53 - 2015-11-22 12:53 - 0000050 _____ () C:\Wswin\WsWinAprsError.txt
2015-11-22 10:15 - 2009-02-05 00:22 - 0003382 _____ () C:\Wswin\www_template_example.txt
2015-11-22 10:15 - 2015-05-23 14:15 - 0003195 _____ () C:\Wswin\www_template_example_en.txt
2015-11-22 10:15 - 2011-04-16 21:29 - 0000709 _____ () C:\Wswin\www_template_pws.txt
2015-11-22 10:15 - 2015-05-27 23:33 - 0004053 _____ () C:\Wswin\www_template_weathercloud.txt
2015-11-22 10:15 - 2015-12-20 13:29 - 0000000 ____D () C:\Wswin\html
2015-11-22 10:15 - 2008-04-08 20:20 - 0000046 _____ () C:\Wswin\html\6x6.gif
2015-11-22 10:15 - 2000-09-23 22:06 - 0015085 _____ () C:\Wswin\html\acloud.gif
2015-11-22 10:15 - 2000-09-02 23:08 - 0006107 _____ () C:\Wswin\html\acloud0.gif
2015-11-22 10:15 - 2000-09-02 23:08 - 0006789 _____ () C:\Wswin\html\apart_sun_rain.gif
2015-11-22 10:15 - 2000-09-02 23:08 - 0008666 _____ () C:\Wswin\html\apart_sun_rain_snow.gif
2015-11-22 10:15 - 2000-09-02 23:08 - 0005186 _____ () C:\Wswin\html\apart_sun_snow.gif
2015-11-22 10:15 - 2000-09-23 21:55 - 0007540 _____ () C:\Wswin\html\arain.gif
2015-11-22 10:15 - 2000-09-02 23:08 - 0006008 _____ () C:\Wswin\html\arainandsnow.gif
2015-11-22 10:15 - 2000-09-02 23:08 - 0006447 _____ () C:\Wswin\html\asnow.gif
2015-11-22 10:15 - 2000-09-01 17:08 - 0003336 _____ () C:\Wswin\html\astorm.gif
2015-11-22 10:15 - 2000-09-01 17:08 - 0005255 _____ () C:\Wswin\html\asun.gif
2015-11-22 10:15 - 2000-09-01 17:08 - 0005200 _____ () C:\Wswin\html\asuncl.gif
2015-11-22 10:15 - 2008-04-08 20:22 - 0000050 _____ () C:\Wswin\html\auf.gif
2015-11-22 10:15 - 2001-08-29 08:55 - 0004672 _____ () C:\Wswin\html\awind.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001458 _____ () C:\Wswin\html\barom.gif
2015-11-22 10:20 - 2015-12-20 13:29 - 0001016 _____ () C:\Wswin\html\barotrend.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001258 _____ () C:\Wswin\html\cal.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0012824 _____ () C:\Wswin\html\clima_y.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0011471 _____ () C:\Wswin\html\clima_y2015.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001335 _____ () C:\Wswin\html\clock.gif
2015-11-22 10:20 - 2015-12-20 13:29 - 0011408 _____ () C:\Wswin\html\current.html
2015-11-22 10:15 - 2014-12-02 20:55 - 0003767 _____ () C:\Wswin\html\davisticker.zip
2015-11-22 10:15 - 2000-08-10 23:43 - 0001077 _____ () C:\Wswin\html\day.gif
2015-11-22 10:15 - 2002-05-25 10:33 - 0001077 _____ () C:\Wswin\html\dayicon.gif
2015-11-22 14:32 - 2015-11-22 14:32 - 0024268 _____ () C:\Wswin\html\ddis_current.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001154 _____ () C:\Wswin\html\dewp.gif
2015-11-22 10:15 - 2001-03-26 17:46 - 0000550 _____ () C:\Wswin\html\e.gif
2015-11-22 10:15 - 2001-06-09 21:30 - 0000621 _____ () C:\Wswin\html\ene.gif
2015-11-22 10:15 - 2001-03-26 17:47 - 0000597 _____ () C:\Wswin\html\ese.gif
2015-11-22 10:15 - 2003-04-25 23:12 - 0001187 _____ () C:\Wswin\html\et.gif
2015-11-22 10:15 - 2001-04-14 13:22 - 0002362 _____ () C:\Wswin\html\forec1.jpg
2015-11-22 10:15 - 2001-04-14 13:22 - 0002283 _____ () C:\Wswin\html\forec2.jpg
2015-11-22 10:15 - 2001-04-14 13:23 - 0002357 _____ () C:\Wswin\html\forec3.jpg
2015-11-22 10:15 - 2001-04-14 13:23 - 0002403 _____ () C:\Wswin\html\forec5.jpg
2015-11-22 10:15 - 2001-04-14 13:23 - 0002310 _____ () C:\Wswin\html\forec6.jpg
2015-11-22 10:15 - 2001-06-27 00:12 - 0002035 _____ () C:\Wswin\html\forec7.jpg
2015-11-22 10:15 - 2003-04-05 19:00 - 0001053 _____ () C:\Wswin\html\frost.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0011562 _____ () C:\Wswin\html\his_y2015.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001623 _____ () C:\Wswin\html\hour.gif
2015-11-22 10:15 - 2002-05-25 10:33 - 0001623 _____ () C:\Wswin\html\houricon.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001325 _____ () C:\Wswin\html\hum.gif
2015-11-22 10:15 - 2001-12-16 10:59 - 0002167 _____ () C:\Wswin\html\ice.gif
2015-11-22 10:15 - 2003-02-12 08:16 - 0000287 _____ () C:\Wswin\html\lights_black.gif
2015-11-22 10:15 - 2003-02-11 11:14 - 0000367 _____ () C:\Wswin\html\lights_green.gif
2015-11-22 10:15 - 2003-02-11 11:14 - 0000341 _____ () C:\Wswin\html\lights_red.gif
2015-11-22 10:15 - 2003-02-11 11:13 - 0000350 _____ () C:\Wswin\html\lights_yellow.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0019490 _____ () C:\Wswin\html\long_coldday.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0022781 _____ () C:\Wswin\html\long_coldsum.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0022444 _____ () C:\Wswin\html\long_greenland.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0027699 _____ () C:\Wswin\html\long_rain.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0029340 _____ () C:\Wswin\html\long_temp.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0024688 _____ () C:\Wswin\html\long_warmday.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0023480 _____ () C:\Wswin\html\long_warmsum.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0009103 _____ () C:\Wswin\html\longtimecalculated.gif
2015-11-22 10:37 - 2015-11-22 10:37 - 0005513 _____ () C:\Wswin\html\minidisplay.gif
2015-11-22 15:26 - 2015-11-22 15:26 - 0011422 _____ () C:\Wswin\html\minmax_20151122.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0009241 _____ () C:\Wswin\html\minmax2015_1.gif
2015-11-22 14:31 - 2015-11-22 15:28 - 0006214 _____ () C:\Wswin\html\minmax2015_2.gif
2015-11-22 10:15 - 2002-05-25 10:33 - 0001115 _____ () C:\Wswin\html\monthicon.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0011787 _____ () C:\Wswin\html\monthlongtime.gif
2015-11-22 10:15 - 2001-04-11 18:00 - 0093875 _____ () C:\Wswin\html\moon.gif
2015-11-22 10:15 - 2001-04-11 17:48 - 0000885 _____ () C:\Wswin\html\moon0.gif
2015-11-22 10:15 - 2001-04-11 17:48 - 0001037 _____ () C:\Wswin\html\moon1.gif
2015-11-22 10:15 - 2001-04-11 17:50 - 0002039 _____ () C:\Wswin\html\moon10.gif
2015-11-22 10:15 - 2001-04-11 17:50 - 0002051 _____ () C:\Wswin\html\moon11.gif
2015-11-22 10:15 - 2001-04-11 17:50 - 0002065 _____ () C:\Wswin\html\moon12.gif
2015-11-22 10:15 - 2001-04-11 17:50 - 0002077 _____ () C:\Wswin\html\moon13.gif
2015-11-22 10:15 - 2001-04-11 17:51 - 0002017 _____ () C:\Wswin\html\moon14.gif
2015-11-22 10:15 - 2001-04-11 17:43 - 0002035 _____ () C:\Wswin\html\moon15.gif
2015-11-22 10:15 - 2001-04-11 17:44 - 0002017 _____ () C:\Wswin\html\moon16.gif
2015-11-22 10:15 - 2001-04-11 17:45 - 0002062 _____ () C:\Wswin\html\moon17.gif
2015-11-22 10:15 - 2001-04-11 17:45 - 0002028 _____ () C:\Wswin\html\moon18.gif
2015-11-22 10:15 - 2001-04-11 17:34 - 0001969 _____ () C:\Wswin\html\moon19.gif
2015-11-22 10:15 - 2001-04-11 17:48 - 0001090 _____ () C:\Wswin\html\moon2.gif
2015-11-22 10:15 - 2001-04-11 17:45 - 0001940 _____ () C:\Wswin\html\moon20.gif
2015-11-22 10:15 - 2001-04-11 17:45 - 0001870 _____ () C:\Wswin\html\moon21.gif
2015-11-22 10:15 - 2001-04-11 17:46 - 0001726 _____ () C:\Wswin\html\moon22.gif
2015-11-22 10:15 - 2001-04-11 17:46 - 0001579 _____ () C:\Wswin\html\moon23.gif
2015-11-22 10:15 - 2001-04-18 16:12 - 0002202 _____ () C:\Wswin\html\moon24.gif
2015-11-22 10:15 - 2001-04-11 17:47 - 0001286 _____ () C:\Wswin\html\moon25.gif
2015-11-22 10:15 - 2001-04-11 17:47 - 0001197 _____ () C:\Wswin\html\moon26.gif
2015-11-22 10:15 - 2001-04-11 17:47 - 0001138 _____ () C:\Wswin\html\moon27.gif
2015-11-22 10:15 - 2001-04-11 17:48 - 0001084 _____ () C:\Wswin\html\moon28.gif
2015-11-22 10:15 - 2001-04-11 17:48 - 0001024 _____ () C:\Wswin\html\moon29.gif
2015-11-22 10:15 - 2001-04-11 17:48 - 0001203 _____ () C:\Wswin\html\moon3.gif
2015-11-22 10:15 - 2001-04-13 23:44 - 0002919 _____ () C:\Wswin\html\moon30.gif
2015-11-22 10:15 - 2001-04-11 17:49 - 0001276 _____ () C:\Wswin\html\moon4.gif
2015-11-22 10:15 - 2001-04-11 17:49 - 0001486 _____ () C:\Wswin\html\moon5.gif
2015-11-22 10:15 - 2001-04-11 17:49 - 0001569 _____ () C:\Wswin\html\moon6.gif
2015-11-22 10:15 - 2001-04-11 17:49 - 0001707 _____ () C:\Wswin\html\moon7.gif
2015-11-22 10:15 - 2001-04-11 17:50 - 0001825 _____ () C:\Wswin\html\moon8.gif
2015-11-22 10:15 - 2001-04-11 17:50 - 0001914 _____ () C:\Wswin\html\moon9.gif
2015-11-22 10:15 - 2001-03-26 17:46 - 0000574 _____ () C:\Wswin\html\n.gif
2015-11-22 10:15 - 2001-03-26 17:50 - 0000616 _____ () C:\Wswin\html\ne.gif
2015-11-22 10:15 - 2001-03-26 17:50 - 0000619 _____ () C:\Wswin\html\nne.gif
2015-11-22 10:15 - 2001-06-09 21:30 - 0000612 _____ () C:\Wswin\html\nnw.gif
2015-11-22 10:15 - 2001-12-16 10:59 - 0000089 _____ () C:\Wswin\html\no_ice.gif
2015-11-22 10:15 - 2001-03-26 17:48 - 0000613 _____ () C:\Wswin\html\nw.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0000849 _____ () C:\Wswin\html\p_do.gif
2015-11-22 10:15 - 2000-09-01 15:50 - 0000855 _____ () C:\Wswin\html\p_s.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0000847 _____ () C:\Wswin\html\p_up.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001196 _____ () C:\Wswin\html\rain.gif
2015-11-22 10:15 - 2000-09-01 16:10 - 0001332 _____ () C:\Wswin\html\rainday.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0009564 _____ () C:\Wswin\html\rainsun_y2015.gif
2015-11-22 10:15 - 2001-03-26 17:46 - 0000567 _____ () C:\Wswin\html\s.gif
2015-11-22 10:15 - 2004-05-21 13:19 - 0021594 _____ () C:\Wswin\html\scloudy.gif
2015-11-22 10:15 - 2004-05-23 23:03 - 0014492 _____ () C:\Wswin\html\sdark.gif
2015-11-22 10:15 - 2001-03-26 17:48 - 0000616 _____ () C:\Wswin\html\se.gif
2015-11-22 10:15 - 2001-04-08 22:06 - 0002329 _____ () C:\Wswin\html\sea0.gif
2015-11-22 10:15 - 2001-04-08 22:09 - 0045778 _____ () C:\Wswin\html\sea1.gif
2015-11-22 10:15 - 2001-04-08 18:51 - 0045778 _____ () C:\Wswin\html\sea2.gif
2015-11-22 10:15 - 2004-05-21 18:59 - 0017443 _____ () C:\Wswin\html\shazy.gif
2015-11-22 10:15 - 2001-06-09 21:30 - 0000631 _____ () C:\Wswin\html\sse.gif
2015-11-22 10:15 - 2004-05-21 18:38 - 0010514 _____ () C:\Wswin\html\sslcloudy.gif
2015-11-22 10:15 - 2004-05-21 16:20 - 0018915 _____ () C:\Wswin\html\sstcloudy.gif
2015-11-22 10:15 - 2004-05-21 19:49 - 0018846 _____ () C:\Wswin\html\ssunny.gif
2015-11-22 10:15 - 2001-03-26 17:47 - 0000610 _____ () C:\Wswin\html\ssw.gif
2015-11-22 10:26 - 2015-11-22 11:56 - 0009323 _____ () C:\Wswin\html\Status1_sencor ws180.gif
2015-11-22 10:21 - 2015-11-22 10:21 - 0006994 _____ () C:\Wswin\html\Status5_sencor ws180.gif
2015-11-22 10:15 - 2001-04-14 13:53 - 0003151 _____ () C:\Wswin\html\sun.gif
2015-11-22 10:15 - 2002-08-03 15:33 - 0003704 _____ () C:\Wswin\html\sunbr.gif
2015-11-22 10:15 - 2001-03-26 17:46 - 0000627 _____ () C:\Wswin\html\sw.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001210 _____ () C:\Wswin\html\temp.gif
2015-11-22 10:15 - 2000-07-14 08:48 - 0004514 _____ () C:\Wswin\html\thermic.gif
2015-11-22 10:15 - 2001-07-21 20:02 - 0003266 _____ () C:\Wswin\html\thermic0.gif
2015-11-22 10:15 - 2001-07-21 19:18 - 0003139 _____ () C:\Wswin\html\thermic1.gif
2015-11-22 10:15 - 2002-08-03 15:31 - 0001438 _____ () C:\Wswin\html\uv.gif
2015-11-22 10:15 - 2001-03-26 17:45 - 0000545 _____ () C:\Wswin\html\w.gif
2015-11-22 10:15 - 2002-05-25 10:33 - 0001134 _____ () C:\Wswin\html\weekicon.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001105 _____ () C:\Wswin\html\wind.gif
2015-11-22 14:31 - 2015-11-22 14:31 - 0005239 _____ () C:\Wswin\html\wind_y2015.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001435 _____ () C:\Wswin\html\windb.gif
2015-11-22 10:15 - 2000-09-24 01:23 - 0003031 _____ () C:\Wswin\html\windc.gif
2015-11-22 10:15 - 2001-04-08 22:23 - 0017363 _____ () C:\Wswin\html\winddir.gif
2015-11-22 10:15 - 2001-04-02 00:05 - 0008890 _____ () C:\Wswin\html\winddir0.gif
2015-11-22 10:15 - 2000-08-10 23:43 - 0001247 _____ () C:\Wswin\html\windr.gif
2015-11-22 10:15 - 2001-03-26 17:49 - 0000597 _____ () C:\Wswin\html\wnw.gif
2015-11-22 10:15 - 2001-03-26 17:49 - 0000597 _____ () C:\Wswin\html\w-nw.gif
2015-11-22 10:15 - 2000-06-13 18:34 - 0015448 _____ () C:\Wswin\html\wolken.gif
2015-11-22 10:15 - 2001-06-09 21:29 - 0000631 _____ () C:\Wswin\html\wsw.gif
2015-11-22 10:15 - 2002-05-25 10:33 - 0000960 _____ () C:\Wswin\html\yearicon.gif
2015-11-22 10:15 - 2008-04-08 20:23 - 0000050 _____ () C:\Wswin\html\zu.gif
2015-11-22 12:45 - 2015-11-22 12:45 - 0000000 ____D () C:\Wswin\PDF
2015-11-22 12:45 - 2015-11-22 12:45 - 0021959 _____ () C:\Wswin\PDF\xgraphic_20151122ti.pdf
2015-11-22 10:15 - 2015-11-22 12:46 - 0000000 ____D () C:\Wswin\Text
2015-11-22 12:46 - 2015-11-22 15:26 - 0001017 _____ () C:\Wswin\Text\ws_report.txt

====== End of Folder: ======


========================= Folder: C:\wdisplay ========================

2015-11-22 14:05 - 2015-11-22 14:05 - 0000003 _____ () C:\wdisplay\ftplog.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0000005 _____ () C:\wdisplay\ftplogfull.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 _____ () C:\wdisplay\programerrorlog.txt
2015-11-22 14:11 - 2015-11-22 14:11 - 0000000 _____ () C:\wdisplay\SYNOP.INI
2015-11-22 14:10 - 2015-11-22 14:11 - 0001935 _____ () C:\wdisplay\WDISPLAY.INI
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 ____D () C:\wdisplay\datafiles
2015-11-22 14:05 - 2015-11-22 14:05 - 0011528 _____ () C:\wdisplay\datafiles\24hourrain.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0004057 _____ () C:\wdisplay\datafiles\detailedraindata.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0000248 _____ () C:\wdisplay\datafiles\fwi.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0001200 _____ () C:\wdisplay\datafiles\fwinew.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0000048 _____ () C:\wdisplay\datafiles\graphdata3.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0023056 _____ () C:\wdisplay\datafiles\last24solar.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 1651720 _____ () C:\wdisplay\datafiles\last31daysdata.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 1696360 _____ () C:\wdisplay\datafiles\last31daysdataextra.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 1607080 _____ () C:\wdisplay\datafiles\last31daysdatavp.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 3035592 _____ () C:\wdisplay\datafiles\last31daysdatavp2.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0031816 _____ () C:\wdisplay\datafiles\latest.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0038896 _____ () C:\wdisplay\datafiles\latestindoor.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0001442 _____ () C:\wdisplay\datafiles\lightning.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0001442 _____ () C:\wdisplay\datafiles\lightning2.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 1517800 _____ () C:\wdisplay\datafiles\month112015.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0357128 _____ () C:\wdisplay\datafiles\month112015direction3.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0937472 _____ () C:\wdisplay\datafiles\month112015latesttime.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0000288 _____ () C:\wdisplay\datafiles\month112015lightntingdays.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 1696360 _____ () C:\wdisplay\datafiles\monthextra112015.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 3035592 _____ () C:\wdisplay\datafiles\monthextrav2p112015.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 1607080 _____ () C:\wdisplay\datafiles\monthextravp112015.inf
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 _____ () C:\wdisplay\datafiles\vptemplog.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 ____D () C:\wdisplay\downloads
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 ____D () C:\wdisplay\logfiles
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 _____ () C:\wdisplay\logfiles\lightninglog.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 ____D () C:\wdisplay\metar
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 ____D () C:\wdisplay\synopmetar
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 ____D () C:\wdisplay\synops
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 ____D () C:\wdisplay\weathermaps
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 ____D () C:\wdisplay\webfiles
2015-11-22 14:05 - 2015-11-22 14:05 - 0001857 _____ () C:\wdisplay\webfiles\clientrawdaily.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0002918 _____ () C:\wdisplay\webfiles\clientrawextra.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0002348 _____ () C:\wdisplay\webfiles\clientrawhour.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0005461 _____ () C:\wdisplay\webfiles\cloudheight.gif
2015-11-22 14:05 - 2015-11-22 14:05 - 0000451 _____ () C:\wdisplay\webfiles\datahtm0.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0000614 _____ () C:\wdisplay\webfiles\datahtm2.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0000611 _____ () C:\wdisplay\webfiles\datahtm3.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0000000 _____ () C:\wdisplay\webfiles\lightninglog.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0000026 _____ () C:\wdisplay\webfiles\mousewebcamcustomtemp.txt
2015-11-22 14:05 - 2015-11-22 14:05 - 0015543 _____ () C:\wdisplay\webfiles\raindetail2.gif
2015-11-22 14:05 - 2015-11-22 14:05 - 0000026 _____ () C:\wdisplay\webfiles\webcamcustomtemp.txt

====== End of Folder: ======


========================= Folder: C:\Program Files (x86)\WS32 ========================

not found.

====== End of Folder: ======


========================= File: C:\Wswin\WsWinAprs.exe ========================

"C:\Wswin\WsWinAprs.exe" => not found.
====== End of File: ======

"C:\Wswin\WsWinAprs.exe" => not found.
C:\ProgramData\Temp => ":66BB1E73" ADS removed successfully.


The system needed a reboot.

==== End of Fixlog 16:34:04 ====

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu, děkuji

#43 Příspěvek od altrok »

:arrow: Ulozte na plochu RogueKiller - http://www.bleepingcomputer.com/download/roguekiller/
  • spustte jako spravce
  • prijmete EULA podminky kliknutim na Accept
  • vpravo kliknete na Scan (potrva az nekolik desitek minut)
  • vpravo vyberte Report
  • vpravo dole Export TXT
  • report ulozte na plochu a jeho obsah vlozte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

artmle9
Návštěvník
Návštěvník
Příspěvky: 108
Registrován: 27 úno 2009 11:21

Re: Prosím o kontrolu, děkuji

#44 Příspěvek od artmle9 »

RogueKiller V11.0.3.0 [Dec 14 2015] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.10240) 64 bits version
Started in : Normal mode
User : Luká? Kilhof [Administrator]
Started from : C:\Users\Luká? Kilhof\Desktop\RogueKiller.exe
Mode : Scan -- Date : 12/20/2015 17:53:09

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 4 ¤¤¤
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Partner -> Found
[PUP] (X86) HKEY_LOCAL_MACHINE\Software\Pandora.TV -> Found
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Found
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Found

¤¤¤ Tasks : 2 ¤¤¤
[Suspicious.Path] \Ball Form -- C:\WINDOWS\system32\rundll32.exe ("C:\Users\Luká? Kilhof\AppData\Local\Ball Form\{18C998D1-CF89-7CC1-2147-E79947877AB8}\BallForm.dll",#3) -> Found
[Suspicious.Path] \Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan -- C:\Program Files\Microsoft Security Client\MpCmdRun.exe (Scan -ScheduleJob -RestrictPrivileges) -> Found

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] eewe149m.default : user_pref("browser.startup.homepage", "https://www.seznam.cz/"); -> Found

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST9500325AS +++++
--- User ---
[MBR] 2fbc865bd6bc2d2585a6c9b3e903709d
[BSP] ba7218981e13a587b0937e6cd93cfb0a : HP MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 2048 | Size: 14997 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 30715904 | Size: 238470 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 519102464 | Size: 223471 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Multiple Card Reader +++++
--- User ---
[MBR] fa390f073d9e40285d89465d2a8f04f8
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [ACTIVE] FAT16 (0x6) [VISIBLE] Offset (sectors): 129 | Size: 1908 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Po?adavek není podporován. )

altrok
Moderátor
Moderátor
Příspěvky: 7317
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu, děkuji

#45 Příspěvek od altrok »

:arrow: Vypnete trvale Windows Defender - http://windows.microsoft.com/cs-cz/wind ... =windows-7


  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CloseProcesses:
    Task: {2AFDB3D3-02A5-4F39-B732-9E90184F1514} - \Ball Form -> No File <==== ATTENTION
    C:\Users\Luká? Kilhof\AppData\Local\Ball Form
    Task: {6436DE78-1813-4690-9DBD-30658CCBFD03} - System32\Tasks\{8A7892DF-9BE2-4249-9409-E3CC635B980B} => C:\Program Files (x86)\WS32\Wswin32.exe
    DeleteKey: "HKEY_LOCAL_MACHINE\Software\Partner"
    DeleteKey: "HKEY_LOCAL_MACHINE\Software\Pandora.TV"
    CMD: ipconfig /flushdns
    End


:arrow: Pote vyzkousejte, zda problem s reklamami pretrvava.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Odpovědět