Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Mám ho ok?

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
maybe
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 04 led 2010 21:06

Mám ho ok?

#1 Příspěvek od maybe »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-12-2015
Ran by Vendy (administrator) on Vendy-PC (17-12-2015 23:06:53)
Running from C:\Users\Vendy\Desktop
Loaded Profiles: UpdatusUser & Vendy (Available Profiles: UpdatusUser & Vendy)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\Lpksetup.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Atheros) C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\makecab.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12452456 2012-02-22] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-02-08] (Realtek Semiconductor)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1021056 2012-03-09] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800896 2012-03-09] (Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2886416 2012-03-02] (Synaptics Incorporated)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-08] (Acer Incorporated)
HKLM\...\Run: [InstantUpdate] => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe [124520 2012-04-07] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-09-23] (Apple Inc.)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296984 2012-01-05] (NTI Corporation)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-24] (Dritek System Inc.)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-11] (AVAST Software)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2015-11-12] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-1558930999-2891573978-138013815-1001\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-1558930999-2891573978-138013815-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [260928 2012-03-05] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [215360 2012-03-05] (NVIDIA Corporation)
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-11] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.10.1.1
Tcpip\..\Interfaces\{8E3F9A00-D13A-452E-B384-20B06CFB1DAA}: [DhcpNameServer] 7.254.254.254
Tcpip\..\Interfaces\{935AB9E4-9972-4F7E-94A4-6A6065C0BB05}: [DhcpNameServer] 10.10.1.1
Tcpip\..\Interfaces\{E088752C-4476-4CBA-B83F-55C1C2A64135}: [DhcpNameServer] 192.53.104.21

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
HKU\S-1-5-21-1558930999-2891573978-138013815-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157
HKU\S-1-5-21-1558930999-2891573978-138013815-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {52db1893-8a90-4192-aede-08e00b8f8473} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=103&systemid=473&v=a13674-348&apn_uid=3144914811624030&apn_dtid=BND101&o=APN10640&apn_ptnrs=AG1&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-1558930999-2891573978-138013815-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1558930999-2891573978-138013815-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120524133152.dll => No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-24] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-23] (Oracle Corporation)
BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120524133152.dll => No File
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-03-09] (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-24] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-23] (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File

FireFox:
========
FF ProfilePath: C:\Users\Vendy\AppData\Roaming\Mozilla\Firefox\Profiles\rif9ueqq.default-1436897549134
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-12-05] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-12-05] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll [2015-02-16] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-07] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-23] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore => not found
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-12]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-12]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found

Chrome:
=======
CHR Profile: C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-19]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-24]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [107648 2012-03-09] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-11] (AVAST Software)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-03-16] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [162648 2012-03-16] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256536 2012-01-05] (NTI Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [76960 2012-02-28] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-11] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-11] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [450504 2015-12-11] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-11] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-11] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S1 kfrjutwg; \??\C:\Windows\system32\drivers\kfrjutwg.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-17 23:06 - 2015-12-17 23:08 - 00021049 _____ C:\Users\Vendy\Desktop\FRST.txt
2015-12-17 22:51 - 2015-12-17 22:55 - 00000000 ____D C:\AdwCleaner
2015-12-17 18:56 - 2015-12-17 18:56 - 00296728 _____ C:\Windows\Minidump\121715-21715-01.dmp
2015-12-17 18:08 - 2015-12-17 18:08 - 00000000 _____ C:\Users\Vendy\AppData\Local\{B5020CEF-224C-4234-81E9-814FC91E5202}
2015-12-17 08:36 - 2015-12-17 16:07 - 00021416 _____ C:\Users\Vendy\Desktop\FRST10.txt
2015-12-17 08:35 - 2015-12-17 23:06 - 00000000 ____D C:\FRST
2015-12-17 08:34 - 2015-12-17 08:34 - 02370048 _____ (Farbar) C:\Users\Vendy\Desktop\FRST64.exe
2015-12-17 08:30 - 2015-12-17 08:30 - 00001178 _____ C:\Users\Vendy\Desktop\Videa.lnk
2015-12-17 08:30 - 2015-12-17 08:30 - 00001171 _____ C:\Users\Vendy\Desktop\Hudba.lnk
2015-12-17 08:29 - 2015-12-17 08:29 - 00002051 _____ C:\Users\Vendy\Desktop\Seriály.lnk
2015-12-17 08:28 - 2015-12-17 08:28 - 00001807 _____ C:\Users\Vendy\Desktop\vzpomínky.lnk
2015-12-17 08:27 - 2015-12-17 08:27 - 00002134 _____ C:\Users\Vendy\Desktop\iPhone fotky.lnk
2015-12-17 08:27 - 2015-12-17 08:27 - 00001994 _____ C:\Users\Vendy\Desktop\meme.lnk
2015-12-17 08:27 - 2015-12-17 08:27 - 00001960 _____ C:\Users\Vendy\Desktop\OA.lnk
2015-12-17 08:27 - 2015-12-17 08:27 - 00001743 _____ C:\Users\Vendy\Desktop\Vendy.lnk
2015-12-13 10:17 - 2015-12-17 18:56 - 577996480 _____ C:\Windows\MEMORY.DMP
2015-12-13 10:17 - 2015-12-17 18:56 - 00000000 ____D C:\Windows\Minidump
2015-12-13 10:17 - 2015-12-13 10:17 - 00262192 _____ C:\Windows\Minidump\121315-38922-01.dmp
2015-12-11 22:28 - 2015-12-11 22:28 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-11 22:28 - 2015-12-11 22:28 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-12-11 20:32 - 2015-12-11 20:32 - 00000000 ____D C:\Users\Vendy\AppData\Roaming\dvdcss
2015-12-09 18:26 - 2015-11-20 19:54 - 03170304 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-12-09 18:26 - 2015-11-20 19:54 - 02609152 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-12-09 18:26 - 2015-11-20 19:54 - 00709632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-12-09 18:26 - 2015-11-20 19:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-12-09 18:26 - 2015-11-20 19:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-12-09 18:26 - 2015-11-05 20:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-12-09 18:26 - 2015-11-05 20:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-12-09 18:26 - 2015-11-03 20:04 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2015-12-09 18:26 - 2015-11-03 19:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-12-09 18:25 - 2015-11-20 19:54 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-12-09 18:25 - 2015-11-20 19:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-12-09 18:25 - 2015-11-20 19:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-12-09 18:25 - 2015-11-20 19:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-12-09 18:25 - 2015-11-20 19:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-12-09 18:25 - 2015-11-11 21:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-12-09 18:25 - 2015-11-11 19:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2015-12-09 18:25 - 2015-11-11 19:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2015-12-09 18:25 - 2015-11-11 19:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2015-12-09 18:25 - 2015-11-11 19:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2015-12-09 18:25 - 2015-11-11 15:57 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-12-09 18:25 - 2015-11-10 19:55 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-12-09 18:25 - 2015-11-10 19:55 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-12-09 18:25 - 2015-11-10 19:55 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-12-09 18:25 - 2015-11-10 19:39 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-12-09 18:25 - 2015-11-10 19:37 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-12-09 18:25 - 2015-11-10 18:47 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-12-09 18:25 - 2015-11-10 01:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-12-09 18:25 - 2015-11-10 01:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-12-09 18:25 - 2015-11-10 01:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-12-09 18:25 - 2015-11-10 01:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-12-09 18:25 - 2015-11-10 01:06 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-12-09 18:25 - 2015-11-10 00:50 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-12-09 18:25 - 2015-11-10 00:44 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-12-09 18:25 - 2015-11-10 00:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-12-09 18:25 - 2015-11-08 23:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-12-09 18:25 - 2015-11-08 23:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-12-09 18:25 - 2015-11-08 23:06 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-12-09 18:25 - 2015-11-08 23:01 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-12-09 18:25 - 2015-11-08 22:40 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-12-09 18:25 - 2015-11-08 22:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-12-09 18:25 - 2015-11-05 20:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2015-12-09 18:25 - 2015-11-05 20:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll
2015-12-09 18:25 - 2015-11-05 10:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2015-12-09 18:25 - 2015-10-09 00:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2015-12-09 18:25 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
2015-12-09 18:25 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2015-12-09 18:25 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2015-12-09 18:25 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2015-12-09 18:25 - 2015-10-09 00:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
2015-12-09 18:25 - 2015-10-09 00:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
2015-12-09 18:25 - 2015-10-09 00:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2015-12-09 18:25 - 2015-10-08 20:13 - 00419928 _____ C:\Windows\SysWOW64\locale.nls
2015-12-09 18:25 - 2015-10-08 19:52 - 00419928 _____ C:\Windows\system32\locale.nls
2015-12-09 18:24 - 2015-11-11 22:12 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-12-09 18:24 - 2015-11-11 17:21 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-12-09 18:24 - 2015-11-11 17:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-12-09 18:24 - 2015-11-11 16:44 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-12-09 18:24 - 2015-11-11 16:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-12-09 18:24 - 2015-11-11 16:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-12-09 18:24 - 2015-11-11 16:12 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-12-09 18:24 - 2015-11-10 01:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-12-09 18:24 - 2015-11-10 01:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-12-09 18:24 - 2015-11-10 01:12 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-12-09 18:24 - 2015-11-10 01:06 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-12-09 18:24 - 2015-11-10 01:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-12-09 18:24 - 2015-11-10 01:03 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-12-09 18:24 - 2015-11-10 01:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-12-09 18:24 - 2015-11-10 01:02 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-12-09 18:24 - 2015-11-10 00:47 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-12-09 18:24 - 2015-11-10 00:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-12-09 18:24 - 2015-11-10 00:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-12-09 18:24 - 2015-11-10 00:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-12-09 18:24 - 2015-11-10 00:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-12-09 18:24 - 2015-11-10 00:35 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-12-09 18:24 - 2015-11-10 00:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-12-09 18:24 - 2015-11-10 00:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-12-09 18:24 - 2015-11-08 23:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-12-09 18:24 - 2015-11-08 23:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-12-09 18:24 - 2015-11-08 23:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-12-09 18:24 - 2015-11-08 23:15 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-12-09 18:24 - 2015-11-08 23:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-12-09 18:24 - 2015-11-08 23:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-12-09 18:24 - 2015-11-08 23:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-12-09 18:24 - 2015-11-08 23:04 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-12-09 18:24 - 2015-11-08 23:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-12-09 18:24 - 2015-11-08 23:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-12-09 18:24 - 2015-11-08 23:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-12-09 18:24 - 2015-11-08 23:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-12-09 18:24 - 2015-11-08 22:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-12-09 18:24 - 2015-11-08 22:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-12-09 18:24 - 2015-11-08 22:35 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-12-09 18:24 - 2015-11-08 22:32 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-12-09 18:24 - 2015-11-08 22:29 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-12-09 18:24 - 2015-11-08 22:18 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-12-09 18:24 - 2015-11-08 22:15 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-12-09 18:24 - 2015-11-08 22:14 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-12-09 18:24 - 2015-11-08 22:14 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-12-09 18:24 - 2015-11-08 22:13 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-12-09 18:24 - 2015-11-08 21:53 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-12-09 18:24 - 2015-11-08 21:41 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-12-09 18:24 - 2015-11-08 21:30 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-12-09 18:21 - 2015-11-03 20:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2015-12-09 18:21 - 2015-11-03 19:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll
2015-12-03 16:55 - 2015-12-03 16:55 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2015-12-03 16:55 - 2015-12-03 16:55 - 00000000 ____D C:\Program Files\Common Files\AV
2015-11-27 20:29 - 2015-12-13 19:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-11-27 20:28 - 2015-12-13 19:16 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-17 23:08 - 2014-05-31 10:51 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-17 23:08 - 2009-07-14 05:45 - 00031472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-17 23:08 - 2009-07-14 05:45 - 00031472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-17 22:59 - 2012-12-08 16:48 - 00000000 ____D C:\Users\Vendy\AppData\Local\LogMeIn Hamachi
2015-12-17 22:59 - 2012-10-27 09:42 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-12-17 22:57 - 2012-10-26 13:19 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-17 22:57 - 2012-05-24 21:40 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2015-12-17 22:57 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-17 22:42 - 2012-10-26 13:19 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-17 19:00 - 2012-05-24 21:37 - 00000000 ____D C:\Users\UpdatusUser
2015-12-17 18:56 - 2011-02-12 08:24 - 00000000 ____D C:\Windows
2015-12-17 15:58 - 2012-05-24 21:40 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2015-12-14 21:39 - 2014-10-11 17:57 - 00000000 ____D C:\Users\Vendy\AppData\Roaming\vlc
2015-12-14 21:39 - 2012-10-25 10:51 - 00000000 ____D C:\Users\Vendy\Documents\Seriály
2015-12-13 19:45 - 2012-05-24 22:15 - 01148312 _____ C:\Windows\system32\perfh005.dat
2015-12-13 19:45 - 2012-05-24 22:15 - 00308808 _____ C:\Windows\system32\perfc005.dat
2015-12-13 19:45 - 2009-07-14 06:13 - 00006264 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-13 19:16 - 2015-04-05 09:22 - 00000000 ___SD C:\Windows\system32\GWX
2015-12-13 19:16 - 2013-09-16 14:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2015-12-13 19:16 - 2013-09-16 14:25 - 00000000 ____D C:\Program Files (x86)\Tunngle
2015-12-13 19:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2015-12-13 19:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2015-12-13 10:21 - 2012-10-25 09:36 - 00000000 ____D C:\Users\Vendy
2015-12-12 15:17 - 2012-03-28 19:43 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-12-12 15:12 - 2014-02-10 12:10 - 00000000 ____D C:\Program Files (x86)\Euro Truck Simulator 2
2015-12-12 15:06 - 2014-05-30 16:47 - 00000000 ____D C:\Users\Vendy\AppData\Roaming\uTorrent
2015-12-11 22:30 - 2012-11-04 20:44 - 00000000 ____D C:\Users\Vendy\AppData\Local\CrashDumps
2015-12-11 22:28 - 2014-05-04 15:41 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-11 22:28 - 2014-02-07 23:23 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-12-11 22:28 - 2013-03-05 18:30 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-11 22:28 - 2013-03-05 18:30 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-11 22:28 - 2012-10-27 09:42 - 00450504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-12-11 22:28 - 2012-10-27 09:42 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-12-11 22:28 - 2012-10-27 09:42 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-12-11 22:27 - 2012-10-27 09:42 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-11 17:29 - 2009-07-14 05:45 - 00440160 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-11 17:27 - 2014-09-17 11:11 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-12-11 17:27 - 2014-09-17 11:11 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-12-11 16:29 - 2014-03-13 18:41 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-11 16:29 - 2012-10-25 10:06 - 00000000 ____D C:\Users\Vendy\Documents\Vendy
2015-12-11 16:28 - 2014-09-17 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-12-11 16:24 - 2015-07-22 14:48 - 00000000 ____D C:\Users\Vendy\Documents\iPhone fotky
2015-12-11 16:17 - 2013-07-27 21:52 - 00000000 ____D C:\Windows\system32\MRT
2015-12-10 19:39 - 2012-10-27 09:51 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-07 17:25 - 2012-10-26 13:19 - 00000000 ____D C:\Users\Vendy\AppData\Local\Google
2015-12-05 13:50 - 2014-07-20 20:06 - 00000000 ____D C:\Users\Vendy\AppData\Local\Adobe
2015-12-05 13:50 - 2014-05-31 10:51 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-05 13:50 - 2012-03-28 19:36 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-12-05 13:50 - 2012-03-28 19:36 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-02 16:08 - 2012-10-26 13:19 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-02 16:08 - 2012-10-26 13:19 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-02 13:18 - 2010-11-21 04:27 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-12-01 20:47 - 2013-10-07 17:45 - 00000000 ____D C:\Users\Vendy\Documents\OA
2015-12-01 15:38 - 2013-06-15 19:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive

==================== Files in the root of some directories =======

2013-09-01 19:17 - 2014-10-12 18:17 - 0004608 _____ () C:\Users\Vendy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-05 09:21 - 2015-04-05 09:21 - 0000000 _____ () C:\Users\Vendy\AppData\Local\{335A376E-BBBA-465B-A779-607864A570F9}
2015-08-21 18:53 - 2015-08-21 18:53 - 0000000 _____ () C:\Users\Vendy\AppData\Local\{551E2F58-BCB8-45B5-836A-39597B7DB8A3}
2015-12-17 18:08 - 2015-12-17 18:08 - 0000000 _____ () C:\Users\Vendy\AppData\Local\{B5020CEF-224C-4234-81E9-814FC91E5202}
2012-05-24 21:54 - 2012-05-24 21:59 - 0002454 _____ () C:\ProgramData\clear.fiSDK20.log
2012-05-24 21:58 - 2015-04-04 09:59 - 0000032 _____ () C:\ProgramData\PS.log

Some files in TEMP:
====================
C:\Users\Vendy\AppData\Local\Temp\clearfiSetup.exe
C:\Users\Vendy\AppData\Local\Temp\DeltaTB.exe
C:\Users\Vendy\AppData\Local\Temp\EAD41FE.exe
C:\Users\Vendy\AppData\Local\Temp\EAD6392.exe
C:\Users\Vendy\AppData\Local\Temp\EADA65C.exe
C:\Users\Vendy\AppData\Local\Temp\FLVPlayerSetup.exe
C:\Users\Vendy\AppData\Local\Temp\FLVPlayerUpdate_downloader_by_FLVPlayerUpdate.exe
C:\Users\Vendy\AppData\Local\Temp\i4jdel0.exe
C:\Users\Vendy\AppData\Local\Temp\i4jdel1.exe
C:\Users\Vendy\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe
C:\Users\Vendy\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\Vendy\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Vendy\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\Vendy\AppData\Local\Temp\jre-8u66-windows-au.exe
C:\Users\Vendy\AppData\Local\Temp\ose00000.exe
C:\Users\Vendy\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Vendy\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Vendy\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Vendy\AppData\Local\Temp\utt45D7.tmp.exe
C:\Users\Vendy\AppData\Local\Temp\vlcurm.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-11-09 20:18

==================== End of FRST.txt ============================

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mám ho ok?

#2 Příspěvek od Márty84 »

Zdravim :)

:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Cleaning
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner[C?].txt ). Ten mi sem zkopirujte.

:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu (cili Vlastni sken vsech disku) http://forum.viry.cz/viewtopic.php?f=29&t=144868 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

maybe
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 04 led 2010 21:06

Re: Mám ho ok?

#3 Příspěvek od maybe »

# AdwCleaner v5.025 - Logfile created 19/12/2015 at 11:03:30
# Updated 13/12/2015 by Xplode
# Database : 2015-12-13.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Vendy - Vendy-PC
# Running from : C:\Users\Vendy\Desktop\adwcleaner_5.025.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\DataMngr_Toolbar

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [730 bytes] ##########

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 19.12.2015
Čas skenování: 11:14
Protokol: malwarebytes.txt
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2015.12.19.02
Databáze rootkitů: v2015.12.18.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Ochrana programu: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Vendy

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 611600
Uplynulý čas: 6 hod, 1 min, 32 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 8
PUP.Optional.Babylon, HKU\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [13dbf9ad62290f27f8841c3a33cf6a96],
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{52DB1893-8A90-4192-AEDE-08E00B8F8473}, , [a945a5011a7168ce4dcb7d873fc536ca],
PUP.Optional.IFEO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\VOLARO, , [78768521008b47ef72ad970a1ee55aa6],
PUP.Optional.IFEO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\VONTEERA, , [3eb0faacc1ca39fdc15f0998bc472bd5],
PUP.Optional.IFEO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\VOLARO, , [40aee1c5c5c6c373d54a851ce91a9070],
PUP.Optional.IFEO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\VONTEERA, , [5a941393e5a67fb7b967435e7d865aa6],
PUP.Optional.DataMngr.AppFlsh, HKU\S-1-5-21-1558930999-2891573978-138013815-1001\SOFTWARE\DataMngr_Toolbar, , [6b8312948b007db9e04d10f4709414ec],
PUP.Optional.MoviesToolBar, HKU\S-1-5-21-1558930999-2891573978-138013815-1001\SOFTWARE\somotomoviestoolbar181, , [42ac574ffe8dd165928b5d4ece35b24e],

Hodnoty registru: 5
PUP.Optional.Bandoo.AppFlsh, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{52db1893-8a90-4192-aede-08e00b8f8473}|URL, http://dts.search.ask.com/sr?src=ieb&gc ... earchTerms}, , [a945a5011a7168ce4dcb7d873fc536ca]
PUP.Optional.IFEO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\VOLARO|debugger, tasklist.exe, , [78768521008b47ef72ad970a1ee55aa6]
PUP.Optional.IFEO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\VONTEERA|debugger, tasklist.exe, , [3eb0faacc1ca39fdc15f0998bc472bd5]
PUP.Optional.IFEO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\VOLARO|debugger, tasklist.exe, , [40aee1c5c5c6c373d54a851ce91a9070]
PUP.Optional.IFEO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\VONTEERA|debugger, tasklist.exe, , [5a941393e5a67fb7b967435e7d865aa6]

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 0
(Nenalezeny žádné škodlivé položky)

Soubory: 176
PUP.Optional.InstallCore, C:\$Recycle.Bin\S-1-5-21-1558930999-2891573978-138013815-1001\$RKOP4ZC.exe, , [5698b6f0b5d696a0e72db891f20ff808],
PUP.Optional.Somoto, C:\AdwCleaner\Quarantine\C\Users\Vendy\AppData\Local\FilesFrog Update Checker\uninstall.exe.vir, , [6a841f87b8d3999d8b7fd03e8f71a25e],
PUP.Optional.SafetyNut, C:\AdwCleaner\Quarantine\C\Users\Vendy\AppData\Roaming\FirefoxToolbar\Movies App\SafetyNut\components\SafetyNutHlpFF14.dll.vir, , [509eadf93754b2845bd437751de76997],
PUP.Optional.SafetyNut, C:\AdwCleaner\Quarantine\C\Users\Vendy\AppData\Roaming\FirefoxToolbar\Movies App\SafetyNut\components\SafetyNutHlpFF16.dll.vir, , [5896a9fde9a2ea4c9d92b9f362a23fc1],
PUP.Optional.SafetyNut, C:\AdwCleaner\Quarantine\C\Users\Vendy\AppData\Roaming\FirefoxToolbar\Movies App\SafetyNut\components\SafetyNutHlpFF18.dll.vir, , [f6f8e9bd6724b185db54ac00d92bdb25],
PUP.Optional.SafetyNut, C:\AdwCleaner\Quarantine\C\Users\Vendy\AppData\Roaming\FirefoxToolbar\Movies App\SafetyNut\components\SafetyNutHlpFF19.dll.vir, , [30beb2f4bfcccc6a4be4cddf887c03fd],
PUP.Optional.SafetyNut, C:\AdwCleaner\Quarantine\C\Users\Vendy\AppData\Roaming\FirefoxToolbar\Movies App\SafetyNut\components\SafetyNutHlpFF20.dll.vir, , [8a647b2b85065dd92807327a927212ee],
PUP.Optional.SafetyNut, C:\AdwCleaner\Quarantine\C\Users\Vendy\AppData\Roaming\FirefoxToolbar\Movies App\SafetyNut\components\SafetyNutHlpFF29.dll.vir, , [e707b6f0088393a378b7a60659abe020],
PUP.Optional.Montiera, C:\Users\Vendy\AppData\Local\delta chrome toolbar\delta chrome toolbar\1.3.25.0\hlpr64.exe, , [608e921484074de9ec3a4b42d32efc04],
PUP.Optional.Montiera, C:\Users\Vendy\AppData\Local\delta chrome toolbar\delta chrome toolbar\1.3.25.0\jfpohgdQ.dll, , [f4fa6541ec9f8da9e7e464f307fa8c74],
PUP.Optional.PayByAds, C:\Users\Vendy\AppData\Local\delta chrome toolbar\delta chrome toolbar\1.3.25.0\res.dll, , [a04ed4d236551125759e2e77d430b34d],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000019, , [6886b0f61e6d71c56d9e9e78da2a6e92],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000039, , [a8467f27820949ed8a81a76fdd27f010],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000000, , [db137e28ee9d66d0c942db3bd3315ea2],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000001, , [c22c287e76151b1bc24919fd38ccb947],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000002, , [c5291393018aed4982891ff7b252ed13],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000003, , [ac420c9a3e4d74c2c84331e56c9828d8],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000004, , [d31b4d59ddaeb680f417c4528d778878],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000005, , [5995bbeb8308dd5925e676a0788cc53b],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000006, , [e707376f117a76c068a33fd7ce366a96],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000007, , [bf2f8224aae1999df91274a243c147b9],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000008, , [24ca1f870f7cce68de2d37df2fd5c33d],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000009, , [2dc1b0f6e6a5152123e8af6746be51af],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000010, , [bd316e385338cc6a43c80214ce36a15f],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000011, , [826cd0d61b70d95d51ba48ce1de7a15f],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000012, , [8a649214b1da7eb8c249140239cb6997],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000013, , [16d8287eaae158deae5dc94d52b21fe1],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000014, , [1cd2f0b67a11fd39e229b56151b320e0],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000015, , [8f5f6046f596072f37d419fdc044c937],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000016, , [2cc2307664277abcb8538096ea1a6997],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000017, , [17d702a4d4b7280e8982f02628dc56aa],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000018, , [24ca92140784f640a665df37e22240c0],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000020, , [56984c5a3853043247c40610dd278d73],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000021, , [7a744363d7b461d5f61542d4c44015eb],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000022, , [20ce2a7cf299e25498739d793fc59868],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000023, , [539be2c4c1ca83b3a665dc3a37cd02fe],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000024, , [bb331591acdf75c1907bab6b947026da],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000025, , [5698aafcc5c6e2546f9c1ef8e91bc63a],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000026, , [0ce2adf96d1ed75f5bb065b11be92cd4],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000027, , [a44abcea9dee2214e427ce4855af936d],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000028, , [38b6aef8f695be78d03beb2b54b014ec],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000029, , [648a4a5c800b3ff726e57c9a4fb5af51],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000030, , [2dc1f8aeccbf280ef912cd491de78080],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000031, , [6c8220865a314ee8719a0412f113d828],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000032, , [ac42584e4942eb4b6f9c0a0c03018b75],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000033, , [08e630765239b383bf4cab6ba0645fa1],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000034, , [5995e9bd6e1d47ef6d9efa1c53b1fb05],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000035, , [b737bee8a5e68da936d51afcfe06e11f],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000036, , [29c5edb99bf0b28472995cbaa262c13f],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000037, , [c42a881ee0abad89818a37dfd43034cc],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000038, , [ae40b4f2236864d2cf3cbe5850b45aa6],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000040, , [e10d990daae1e5518487051109fb649c],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000041, , [9f4fd5d1622991a53ccf8c8a986cad53],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000042, , [519decba14773ef87e8d76a0b1531be5],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000043, , [faf4eeb8503b61d564a77f9714f030d0],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000044, , [76781393fa91aa8ca16ae82e32d249b7],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000045, , [b539a0062b60999d50bbdc3a5da77c84],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000046, , [f6f865418dfead89c8430c0a14f0d32d],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000047, , [de108323cac1a88e5facbf57798b11ef],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000048, , [0de1d3d3aedd3afc5eadc056b15324dc],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000049, , [a14dc2e495f6d56120eb100622e2dd23],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000050, , [f0fe584eaae1ec4a4ebd6aac8381b34d],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000051, , [d11d2d79acdf102638d3df374fb541bf],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000052, , [0ae47f2782092e088784a472d52fe61a],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000053, , [43ab376fb3d81e18010a28ee1fe511ef],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000054, , [98569b0b701be94d5ab1e13542c2dd23],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000055, , [ab439d09b9d254e27d8e977f887cf907],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000056, , [c12de7bfd9b288ae51ba19fdf70d5ca4],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000057, , [f9f51f876f1c81b57c8ff323af556b95],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000058, , [ce20e9bdbccf84b267a474a22fd5768a],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000059, , [8c6202a4068547ef2ddea076ae569c64],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\File System\001\t\00\00000060, , [787601a5612a76c0bd4e74a2b64e6c94],
PUP.Optional.Mediasoft, C:\Users\Vendy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5QD18PXW\pack[1].7z, , [d31b9511f09bcd69e38cc2df30d0d030],
Trojan.RotBrow.A, C:\Users\Vendy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5QD18PXW\pack[2].7z, , [dd11e8bebccf2d0997a02393c23e5ca4],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8IH71CJR\FLVPlayerUpdate_downloader_by_FLVPlayerUpdate[1].exe, , [e707495d1c6fd264af96b5f726def709],
PUP.Optional.BDJoin, C:\Users\Vendy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDSXP1SW\btclient_1.3.25.0_cn[1].exe, , [7876d9cd16752a0ccab73deea45c22de],
PUP.Optional.InstallBrain, C:\Users\Vendy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NO00A1RQ\pack[1].7z, , [a34b683e5a31999d4d3ab37ce0210000],
PUP.Optional.APNToolBar, C:\Users\Vendy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SO319M0W\WeatherBugSetup[1].exe, , [608ee9bd9dee6acc566078b4a95816ea],
PUP.Optional.InstallBrain, C:\Users\Vendy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VSEXZ9MO\pack[1].7z, , [1ed0f7af3e4d9d99c8bfd8571fe208f8],
Trojan.RotBrowse, C:\Users\Vendy\AppData\Local\Temp\126A.tmp, , [34baccda48434ee88aaf8cac9d67b050],
PUP.Optional.InstallBrain, C:\Users\Vendy\AppData\Local\Temp\140D.tmp, , [20ceb1f56b209e985d2abc736b96956b],
Trojan.RotBrow.A, C:\Users\Vendy\AppData\Local\Temp\che6791.tmp, , [3ab4dbcb94f79d992311b8fed52b8977],
PUP.Optional.Delta.ShrtCln, C:\Users\Vendy\AppData\Local\Temp\DeltaTB.exe, , [18d6cdd95e2dec4a8834e8aeb34d867a],
PUP.Optional.Conduit, C:\Users\Vendy\AppData\Local\Temp\992.tmp, , [43abced87c0f4cea465380ade120c53b],
PUP.Optional.MediaTech, C:\Users\Vendy\AppData\Local\Temp\9BAD.tmp, , [75794a5c3457fd39f82d9db71fe523dd],
PUP.Optional.InstallBrain, C:\Users\Vendy\AppData\Local\Temp\F3F0.tmp, , [3bb304a2e4a782b4ddaa26099b662ed2],
Trojan.RotBrowse, C:\Users\Vendy\AppData\Local\Temp\7541.tmp, , [d9159b0b711a55e1f34439ffa55f30d0],
PUP.Optional.FileScout, C:\Users\Vendy\AppData\Local\Temp\756D.tmp, , [09e5228418734de9861bb27c13ee5da3],
PUP.Optional.APNToolBar, C:\Users\Vendy\AppData\Local\Temp\utt45D7.tmp.exe, , [32bc1591f19adc5a1e97b17b9c658977],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Temp\FLVPlayerSetup.exe, , [3faf42648902f6407db0a18d8878768a],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Temp\FLVPlayerUpdate_downloader_by_FLVPlayerUpdate.exe, , [faf415916f1c999d1134cddf679d7a86],
PUP.Optional.Somoto, C:\Users\Vendy\AppData\Local\Temp\UpdateCheckerSetup.exe, , [c32b8323c9c2300610fa0e0019e7db25],
PUP.Optional.Babylon, C:\Users\Vendy\AppData\Local\Temp\E9F228DD-BAB0-7891-BEA6-EB11438381E1\Latest\BExternal.dll, , [da1451555536f24488eb0e1d12ee9e62],
Trojan.RotBrowse, C:\Users\Vendy\AppData\Local\Temp\E9F228DD-BAB0-7891-BEA6-EB11438381E1\Latest\ccp.exe, , [9e50aafc167565d1e94e2f0936cefe02],
PUP.Optional.Babylon, C:\Users\Vendy\AppData\Local\Temp\E9F228DD-BAB0-7891-BEA6-EB11438381E1\Latest\CrxInstaller.dll, , [e509ddc96a21cd694c7c2507d1306e92],
PUP.Optional.Babylon, C:\Users\Vendy\AppData\Local\Temp\E9F228DD-BAB0-7891-BEA6-EB11438381E1\Latest\Setup.exe, , [5896adf98b008bab3546dd4e6e9245bb],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\bus1D35\CrxUpdater_d.exe, , [d81696108605a78f1353242fd92b4bb5],
PUP.Optional.BabSolution, C:\Users\Vendy\AppData\Local\Temp\bus1F36\BUSolution.dll, , [9e507135d6b50630eed7200c3fc20ff1],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\bus4BE3\CrxUpdater_d.exe, , [f3fb990d6823fa3c0264e96a5fa5916f],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\bus4DD4\CrxUpdater_d.exe, , [7d71eeb8a3e8a88e660056fdd034926e],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\bus4F40\CrxUpdater_d.exe, , [19d51b8bc8c39c9a89dd5cf708fccb35],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\bus605E\CrxUpdater_d.exe, , [f2fc7d297417e452cd9940136f95a759],
PUP.Optional.OnlySearch.ShrtCln, C:\Users\Vendy\AppData\Local\Temp\bus6DF0\update.exe, , [6e80a303f695d6609feccb4c3ac6dd23],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\bus7D2F\CrxUpdater_d.exe, , [18d685215d2e75c16ff76ce7ff059d63],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\bus8FA4\CrxUpdater_d.exe, , [09e5545299f2181eea7c58fba1632cd4],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\busABD9\CrxUpdater_d.exe, , [1ad44b5beaa189adf86e62f15aaacd33],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\busB011\CrxUpdater_d.exe, , [a14deeb8d4b787aff0762231c63e7090],
PUP.Optional.Bandoo.AppFlsh, C:\Users\Vendy\AppData\Local\Temp\DTX\Reporting\ReportingHelper.dll, , [7d716b3b018a66d0ee0fc3e6b64edf21],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsa1548.tmp\Helper.dll, , [2dc1dccae1aa1b1bee413874ae56e51b],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsa1548.tmp\Starter.exe, , [cd21b2f4cac153e3de51ac002bd929d7],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsb58A7.tmp\Helper.dll, , [02ec178f79129b9b6fc0adff46bef50b],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsb58A7.tmp\Starter.exe, , [1fcf3d695d2e2d09d05fdcd01de735cb],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsdC6BD.tmp\Starter.exe, , [529cf0b6acdf063089a6218bc341bb45],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nse2A6E.tmp\Helper.dll, , [6b83dbcbb7d4ee48949bbaf2778d12ee],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nse2A6E.tmp\Starter.exe, , [ffefd9cd0b804fe70629525a53b14fb1],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsf8317.tmp\Helper.dll, , [57972e7892f9da5c0728cce054b0a65a],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsf8317.tmp\Starter.exe, , [19d505a1afdcb87e7eb14963c73dfe02],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsfF347.tmp\Helper.dll, , [47a706a0d5b67cba79b6634919eb53ad],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsfF347.tmp\Starter.exe, , [c628188ed9b263d3ce612983de263fc1],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsg9966.tmp\Helper.dll, , [d01e5c4aed9ed462bc73fdaf3ec66997],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsg9966.tmp\Starter.exe, , [7a748c1a622946f02b0404a8c83c20e0],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nskF7F8.tmp\Helper.dll, , [f7f79d09523900364de29c10d82c8c74],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nskF7F8.tmp\Starter.exe, , [bc32eeb82e5df64070bf129a06fe4bb5],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsl9CC1.tmp\Helper.dll, , [fcf22e781378ec4ab17e7f2d7a8a56aa],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsl9CC1.tmp\Starter.exe, , [628c9f070e7def47d35c416b1ee613ed],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsqD59A.tmp\Helper.dll, , [48a6c6e05b30e254d15ea20aeb19728e],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsqD59A.tmp\Starter.exe, , [ac425f473556cb6b57d8e8c4966e8b75],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nss13A4.tmp\Helper.dll, , [4da19e0818730135002f8e1e47bdea16],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nss13A4.tmp\Starter.exe, , [db131e88a5e6f541a78805a757ad857b],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nstD755.tmp\Helper.dll, , [7f6fced827643afcf9363b71a0649d63],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nstD755.tmp\Starter.exe, , [6e8053536b20999dbe717636fc0824dc],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsv1FED.tmp\Helper.dll, , [519de8be3d4e78be45eac2ead430857b],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsv1FED.tmp\Starter.exe, , [ba34d7cfbecd171ffb34664656ae1de3],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsv9FE3.tmp\Helper.dll, , [24ca51559fec77bf49e6fbb1a2628977],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsv9FE3.tmp\Starter.exe, , [a04eacfa0b8054e2d35c337925df05fb],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsvB387.tmp\Helper.dll, , [7876b3f36724989ee9463379f4108a76],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nsvB387.tmp\Starter.exe, , [8668376f3655cc6aae8101ab5da73ac6],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nszB711.tmp\Helper.dll, , [7579e9bd800bd165d35c1f8d35cf5aa6],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nszB711.tmp\Starter.exe, , [6787e6c01d6e4ee881ae822a0ef6d22e],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nszCAE5.tmp\Helper.dll, , [9856d6d04a41d462bb749319b35156aa],
PUP.Optional.SafetyNut, C:\Users\Vendy\AppData\Local\Temp\nszCAE5.tmp\Starter.exe, , [39b51195a2e9e65096991d8fd430768a],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\busDD82\CrxUpdater_d.exe, , [7d71386e008b0333e97d1d3694702ad6],
PUP.Optional.CRX, C:\Users\Vendy\AppData\Local\Temp\busF1C4\CrxUpdater_d.exe, , [816d4a5cafdc5fd7d393c58e92728b75],
PUP.Optional.BDJoin, C:\Users\Vendy\AppData\Local\Temp\busF77\join.exe, , [31bde4c27912c96d87fac9628e728c74],
PUP.Optional.SafetyNut, C:\Windows\Temp\110a31f0\MoviesToolbarSetup_Somoto.exe, , [34bad4d26229b581c06f951717ed17e9],
PUP.Optional.SafetyNut, C:\Windows\Temp\18430366\MoviesToolbarSetup_Somoto.exe, , [da147e283d4ebb7b0629efbdb74d0af6],
PUP.Optional.SafetyNut, C:\Windows\Temp\187840f5\MoviesToolbarSetup_Somoto.exe, , [ac42693ddab1092d6fc0c0ec3ec6639d],
PUP.Optional.SafetyNut, C:\Windows\Temp\1b472ef3\MoviesToolbarSetup_Somoto.exe, , [9a54a9fd1d6e290d70bfc0ec48bca65a],
PUP.Optional.SafetyNut, C:\Windows\Temp\255410f\MoviesToolbarSetup_Somoto.exe, , [5698673fe9a28aace24da606947028d8],
PUP.Optional.SafetyNut, C:\Windows\Temp\255e0e8f\MoviesToolbarSetup_Somoto.exe, , [826cd2d4d1ba41f53af5f1bb5ba9837d],
PUP.Optional.SafetyNut, C:\Windows\Temp\31106b4e\MoviesToolbarSetup_Somoto.exe, , [2fbf5d495932c472bf70d0dce51f01ff],
PUP.Optional.SafetyNut, C:\Windows\Temp\4474dd5\patch_ff.exe, , [db13693de7a41f1753dcdad206feeb15],
PUP.Optional.SafetyNut, C:\Windows\Temp\4c767e0b\MoviesToolbarSetup_Somoto.exe, , [638bccda6922e35386a9eac254b0cf31],
PUP.Optional.SafetyNut, C:\Windows\Temp\4e5b35ca\MoviesToolbarSetup_Somoto.exe, , [37b7396d830869cd7db2d5d7996bf010],
PUP.Optional.SafetyNut, C:\Windows\Temp\583b325e\MoviesToolbarSetup_Somoto.exe, , [cd2196103358bd79949b3c70b94b60a0],
PUP.Optional.SafetyNut, C:\Windows\Temp\631138cc\MoviesToolbarSetup_Somoto.exe, , [db13683ec6c5072f5ad5f1bb956fc040],
PUP.Optional.SafetyNut, C:\Windows\Temp\701f61ce\MoviesToolbarSetup_Somoto.exe, , [9c5273335d2eff37ba75bdefd232b947],
PUP.Optional.SafetyNut, C:\Windows\Temp\733d2fe1\MoviesToolbarSetup_Somoto.exe, , [8f5fe8be57342b0b111e8626fe06a45c],
PUP.Optional.SafetyNut, C:\Windows\Temp\7c2c11e3\MoviesToolbarSetup_Somoto.exe, , [f7f73571cdbe9e984ce32b81c53f9868],
PUP.Optional.SafetyNut, C:\Windows\Temp\7d251933\MoviesToolbarSetup_Somoto.exe, , [a44a5f47cac1cb6b151a9e0e63a18080],
PUP.Optional.SafetyNut, C:\Windows\Temp\871a6e15\MoviesToolbarSetup_Somoto.exe, , [7f6f2a7c7a11ec4a2d02c6e66e96d12f],
PUP.Optional.SafetyNut, C:\Windows\Temp\9a2b31e3\MoviesToolbarSetup_Somoto.exe, , [7d71584ea9e2d6609f9038749e662bd5],
PUP.Optional.SafetyNut, C:\Windows\Temp\9b42168e\MoviesToolbarSetup_Somoto.exe, , [846aa0061f6c60d6f43b0f9df70d4ab6],
PUP.Optional.SafetyNut, C:\Windows\Temp\f63c1d92\patch_ff.exe, , [4da1daccc7c4a19575ba0aa2b05446ba],
PUP.Optional.SafetyNut, C:\Windows\Temp\d4e2183\MoviesToolbarSetup_Somoto.exe, , [b7371591fc8f75c150dfe4c8897be61a],
PUP.Optional.SafetyNut, C:\Windows\Temp\bf416529\MoviesToolbarSetup_Somoto.exe, , [ec025e48c5c67fb7c46b03a9cd3727d9],
PUP.Optional.SafetyNut, C:\Windows\Temp\c17e6924\MoviesToolbarSetup_Somoto.exe, , [905e3274d3b8a88e2f00d1dbf80cfc04],
PUP.Optional.SafetyNut, C:\Windows\Temp\nsa81BF.tmp\Helper.dll, , [7777fbabafdcef4777b802aa0bf97c84],
PUP.Optional.SafetyNut, C:\Windows\Temp\nsk6865.tmp\Helper.dll, , [579723837f0c2016141b1a928a7a7d83],
PUP.Optional.SafetyNut, C:\Windows\Temp\a52e2140\patch_ff.exe, , [c12d2383b8d396a0ac834d5f82828977],
PUP.Optional.SafetyNut, C:\Windows\Temp\nsaED0F.tmp\Helper.dll, , [826ca4023952ed4917188e1eba4aef11],
PUP.Optional.SafetyNut, C:\Windows\Temp\nsaFE6D.tmp\Helper.dll, , [a34bccdae6a5dd5963cccfdd90747d83],
PUP.Optional.SafetyNut, C:\Windows\Temp\nsf320A.tmp\Helper.dll, , [24ca8323315ad066a788eac2ce36f010],
PUP.Optional.SafetyNut, C:\Windows\Temp\nsv2BB4.tmp\Helper.dll, , [c02e0f978b000f276ac563498381d030],
PUP.Optional.SafetyNut, C:\Windows\Temp\cb1b6c98\patch_ff.exe, , [b33b3175b2d9fd3963cca4086a9adb25],
PUP.Optional.SafetyNut, C:\Windows\Temp\cf253c8d\MoviesToolbarSetup_Somoto.exe, , [7678763055365ed8919ed5d715ef619f],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mám ho ok?

#4 Příspěvek od Márty84 »

Vsechny nalezy nechte odstranit. Po odstraneni a restartu pc test s MBAM zopakujte, at vime, jestli se to nevraci. Napiste vysledek testu a podle nej zvolim dalsi postup.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

maybe
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 04 led 2010 21:06

Re: Mám ho ok?

#5 Příspěvek od maybe »

Po restartu a novem skenu mbam 0 hrozeb.

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mám ho ok?

#6 Příspěvek od Márty84 »

:arrow: MBAM muzete odinstalovat.

:arrow: Dejte nove logy podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=13&t=133100 - vypnete na chvili antivir, je mozne, ze to bude blokovat jako skodnou, ale pouzivame to porad, jedna se o falesny poplach :)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

maybe
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 04 led 2010 21:06

Re: Mám ho ok?

#7 Příspěvek od maybe »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-12-2015
Ran by Vendy (administrator) on Vendy-PC (20-12-2015 22:42:08)
Running from C:\Users\Vendy\Desktop
Loaded Profiles: UpdatusUser & Vendy (Available Profiles: UpdatusUser & Vendy)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Atheros) C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Microsoft Corporation) C:\Windows\System32\makecab.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(forum.viry.cz) C:\Users\Vendy\Desktop\FRST-OlderVersion\FRSTLauncher.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12452456 2012-02-22] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-02-08] (Realtek Semiconductor)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1021056 2012-03-09] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [800896 2012-03-09] (Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2886416 2012-03-02] (Synaptics Incorporated)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1829768 2012-02-08] (Acer Incorporated)
HKLM\...\Run: [InstantUpdate] => C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuDaemon.exe [124520 2012-04-07] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-09-23] (Apple Inc.)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [296984 2012-01-05] (NTI Corporation)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-06-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1105488 2012-03-24] (Dritek System Inc.)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-09-20] (Egis Technology Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-11] (AVAST Software)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5565448 2015-11-12] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-1558930999-2891573978-138013815-1001\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-1558930999-2891573978-138013815-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-11] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\..\Interfaces\{8E3F9A00-D13A-452E-B384-20B06CFB1DAA}: [DhcpNameServer] 7.254.254.254
Tcpip\..\Interfaces\{935AB9E4-9972-4F7E-94A4-6A6065C0BB05}: [DhcpNameServer] 10.10.1.1
Tcpip\..\Interfaces\{E088752C-4476-4CBA-B83F-55C1C2A64135}: [DhcpNameServer] 192.53.104.21

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/p/?LinkId=255141
HKU\S-1-5-21-1558930999-2891573978-138013815-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=hxxp://go.microsoft.com/fwlink/?LinkId=69157
HKU\S-1-5-21-1558930999-2891573978-138013815-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... -SearchBox
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-1558930999-2891573978-138013815-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1558930999-2891573978-138013815-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120524133152.dll => No File
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-24] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-23] (Oracle Corporation)
BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120524133152.dll => No File
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-03-09] (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-24] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-23] (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File

FireFox:
========
FF ProfilePath: C:\Users\Vendy\AppData\Roaming\Mozilla\Firefox\Profiles\rif9ueqq.default-1436897549134
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-19] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-19] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1217157.dll [2015-02-16] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-07] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-23] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore => not found
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-12]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-12-12]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found

Chrome:
=======
CHR Profile: C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-11-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vendy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-19]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-24]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [107648 2012-03-09] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-11] (AVAST Software)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [127320 2012-03-16] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [162648 2012-03-16] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-11-12] (LogMeIn, Inc.)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256536 2012-01-05] (NTI Corporation)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [759192 2013-09-03] (Tunngle.net GmbH) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [76960 2012-02-28] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-19] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-11] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-11] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [451040 2015-12-19] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-11] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-11] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S1 kfrjutwg; \??\C:\Windows\system32\drivers\kfrjutwg.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-20 22:42 - 2015-12-20 22:44 - 00020566 _____ C:\Users\Vendy\Desktop\FRST.txt
2015-12-20 22:42 - 2015-12-20 22:42 - 00000000 ____D C:\Users\Vendy\Desktop\FRST-OlderVersion
2015-12-20 22:23 - 2015-12-20 22:24 - 00112640 _____ (forum.viry.cz) C:\Users\Vendy\Downloads\FRSTLauncher.exe
2015-12-20 19:10 - 2015-12-20 19:10 - 00002959 _____ C:\Users\Vendy\Desktop\Microsoft Excel 2010.lnk
2015-12-20 18:49 - 2015-12-20 18:49 - 00008060 _____ C:\Users\Vendy\Desktop\disk info.txt
2015-12-20 06:09 - 2015-12-20 06:09 - 00001156 _____ C:\Users\Vendy\Desktop\mav2.txt
2015-12-19 17:24 - 2015-12-19 17:24 - 00027406 _____ C:\Users\Vendy\Desktop\mav1.txt
2015-12-19 11:11 - 2015-12-20 07:41 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-12-19 11:10 - 2015-12-19 11:10 - 00001066 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-19 11:10 - 2015-12-19 11:10 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-19 11:10 - 2015-12-19 11:10 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-19 11:10 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-12-19 11:10 - 2015-10-05 09:50 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-12-19 11:10 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2015-12-19 11:07 - 2015-12-19 11:07 - 00000808 _____ C:\Users\Vendy\Desktop\AdwCleaner[C2].txt
2015-12-19 10:42 - 2015-12-19 10:42 - 01740288 _____ C:\Users\Vendy\Desktop\adwcleaner_5.025.exe
2015-12-19 03:08 - 2015-12-19 03:08 - 00003608 ____N C:\bootsqm.dat
2015-12-17 22:51 - 2015-12-19 11:03 - 00000000 ____D C:\AdwCleaner
2015-12-17 18:56 - 2015-12-17 18:56 - 00296728 _____ C:\Windows\Minidump\121715-21715-01.dmp
2015-12-17 18:08 - 2015-12-17 18:08 - 00000000 _____ C:\Users\Vendy\AppData\Local\{B5020CEF-224C-4234-81E9-814FC91E5202}
2015-12-17 08:36 - 2015-12-17 16:07 - 00021416 _____ C:\Users\Vendy\Desktop\FRST10.txt
2015-12-17 08:35 - 2015-12-20 22:42 - 00000000 ____D C:\FRST
2015-12-17 08:34 - 2015-12-20 22:42 - 02370560 _____ (Farbar) C:\Users\Vendy\Desktop\FRST64.exe
2015-12-17 08:30 - 2015-12-17 08:30 - 00001178 _____ C:\Users\Vendy\Desktop\Videa.lnk
2015-12-17 08:30 - 2015-12-17 08:30 - 00001171 _____ C:\Users\Vendy\Desktop\Hudba.lnk
2015-12-17 08:29 - 2015-12-17 08:29 - 00002051 _____ C:\Users\Vendy\Desktop\Seriály.lnk
2015-12-17 08:28 - 2015-12-17 08:28 - 00001807 _____ C:\Users\Vendy\Desktop\vzpomínky.lnk
2015-12-17 08:27 - 2015-12-17 08:27 - 00002134 _____ C:\Users\Vendy\Desktop\iPhone fotky.lnk
2015-12-17 08:27 - 2015-12-17 08:27 - 00001994 _____ C:\Users\Vendy\Desktop\meme.lnk
2015-12-17 08:27 - 2015-12-17 08:27 - 00001960 _____ C:\Users\Vendy\Desktop\OA.lnk
2015-12-17 08:27 - 2015-12-17 08:27 - 00001743 _____ C:\Users\Vendy\Desktop\Vendy.lnk
2015-12-13 10:17 - 2015-12-17 18:56 - 577996480 _____ C:\Windows\MEMORY.DMP
2015-12-13 10:17 - 2015-12-17 18:56 - 00000000 ____D C:\Windows\Minidump
2015-12-13 10:17 - 2015-12-13 10:17 - 00262192 _____ C:\Windows\Minidump\121315-38922-01.dmp
2015-12-11 22:28 - 2015-12-11 22:28 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-11 22:28 - 2015-12-11 22:28 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-12-11 20:32 - 2015-12-11 20:32 - 00000000 ____D C:\Users\Vendy\AppData\Roaming\dvdcss
2015-12-09 18:26 - 2015-11-20 19:54 - 03170304 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-12-09 18:26 - 2015-11-20 19:54 - 02609152 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-12-09 18:26 - 2015-11-20 19:54 - 00709632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-12-09 18:26 - 2015-11-20 19:34 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-12-09 18:26 - 2015-11-20 19:34 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-12-09 18:26 - 2015-11-05 20:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-12-09 18:26 - 2015-11-05 20:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-12-09 18:26 - 2015-11-03 20:04 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2015-12-09 18:26 - 2015-11-03 19:56 - 00627712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-12-09 18:25 - 2015-11-20 19:54 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-12-09 18:25 - 2015-11-20 19:54 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-12-09 18:25 - 2015-11-20 19:54 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-12-09 18:25 - 2015-11-20 19:34 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-12-09 18:25 - 2015-11-20 19:34 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-12-09 18:25 - 2015-11-20 19:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-12-09 18:25 - 2015-11-11 21:52 - 00341192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-12-09 18:25 - 2015-11-11 19:53 - 01735680 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
2015-12-09 18:25 - 2015-11-11 19:53 - 00525312 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll
2015-12-09 18:25 - 2015-11-11 19:39 - 01242624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
2015-12-09 18:25 - 2015-11-11 19:39 - 00487936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\catsrvut.dll
2015-12-09 18:25 - 2015-11-11 15:57 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-12-09 18:25 - 2015-11-10 19:55 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-12-09 18:25 - 2015-11-10 19:55 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-12-09 18:25 - 2015-11-10 19:55 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2015-12-09 18:25 - 2015-11-10 19:39 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-12-09 18:25 - 2015-11-10 19:37 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2015-12-09 18:25 - 2015-11-10 18:47 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-12-09 18:25 - 2015-11-10 01:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-12-09 18:25 - 2015-11-10 01:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-12-09 18:25 - 2015-11-10 01:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-12-09 18:25 - 2015-11-10 01:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-12-09 18:25 - 2015-11-10 01:06 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-12-09 18:25 - 2015-11-10 00:50 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-12-09 18:25 - 2015-11-10 00:44 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2015-12-09 18:25 - 2015-11-10 00:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-12-09 18:25 - 2015-11-08 23:15 - 02887168 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-12-09 18:25 - 2015-11-08 23:15 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-12-09 18:25 - 2015-11-08 23:06 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-12-09 18:25 - 2015-11-08 23:01 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-12-09 18:25 - 2015-11-08 22:40 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-12-09 18:25 - 2015-11-08 22:15 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-12-09 18:25 - 2015-11-05 20:05 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wshrm.dll
2015-12-09 18:25 - 2015-11-05 20:02 - 00014848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshrm.dll
2015-12-09 18:25 - 2015-11-05 10:53 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2015-12-09 18:25 - 2015-10-09 00:22 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2015-12-09 18:25 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
2015-12-09 18:25 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2015-12-09 18:25 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2015-12-09 18:25 - 2015-10-09 00:18 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2015-12-09 18:25 - 2015-10-09 00:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
2015-12-09 18:25 - 2015-10-09 00:18 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
2015-12-09 18:25 - 2015-10-09 00:17 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2015-12-09 18:25 - 2015-10-08 20:13 - 00419928 _____ C:\Windows\SysWOW64\locale.nls
2015-12-09 18:25 - 2015-10-08 19:52 - 00419928 _____ C:\Windows\system32\locale.nls
2015-12-09 18:24 - 2015-11-11 22:12 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-12-09 18:24 - 2015-11-11 17:21 - 25837568 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-12-09 18:24 - 2015-11-11 17:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-12-09 18:24 - 2015-11-11 16:44 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-12-09 18:24 - 2015-11-11 16:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-12-09 18:24 - 2015-11-11 16:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-12-09 18:24 - 2015-11-11 16:12 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-12-09 18:24 - 2015-11-10 01:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-12-09 18:24 - 2015-11-10 01:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-12-09 18:24 - 2015-11-10 01:12 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-12-09 18:24 - 2015-11-10 01:06 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-12-09 18:24 - 2015-11-10 01:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-12-09 18:24 - 2015-11-10 01:03 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-12-09 18:24 - 2015-11-10 01:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-12-09 18:24 - 2015-11-10 01:02 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-12-09 18:24 - 2015-11-10 00:47 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-12-09 18:24 - 2015-11-10 00:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-12-09 18:24 - 2015-11-10 00:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-12-09 18:24 - 2015-11-10 00:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-12-09 18:24 - 2015-11-10 00:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-12-09 18:24 - 2015-11-10 00:35 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-12-09 18:24 - 2015-11-10 00:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-12-09 18:24 - 2015-11-10 00:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-12-09 18:24 - 2015-11-08 23:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-12-09 18:24 - 2015-11-08 23:32 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-12-09 18:24 - 2015-11-08 23:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-12-09 18:24 - 2015-11-08 23:15 - 00571392 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-12-09 18:24 - 2015-11-08 23:15 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-12-09 18:24 - 2015-11-08 23:14 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-12-09 18:24 - 2015-11-08 23:07 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-12-09 18:24 - 2015-11-08 23:04 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-12-09 18:24 - 2015-11-08 23:02 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-12-09 18:24 - 2015-11-08 23:01 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-12-09 18:24 - 2015-11-08 23:01 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-12-09 18:24 - 2015-11-08 23:01 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-12-09 18:24 - 2015-11-08 22:52 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-12-09 18:24 - 2015-11-08 22:48 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-12-09 18:24 - 2015-11-08 22:35 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-12-09 18:24 - 2015-11-08 22:32 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-12-09 18:24 - 2015-11-08 22:29 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-12-09 18:24 - 2015-11-08 22:18 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-12-09 18:24 - 2015-11-08 22:15 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-12-09 18:24 - 2015-11-08 22:14 - 14456832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-12-09 18:24 - 2015-11-08 22:14 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-12-09 18:24 - 2015-11-08 22:13 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-12-09 18:24 - 2015-11-08 21:53 - 02487808 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-12-09 18:24 - 2015-11-08 21:41 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-12-09 18:24 - 2015-11-08 21:30 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-12-09 18:21 - 2015-11-03 20:04 - 00241664 _____ (Microsoft Corporation) C:\Windows\system32\els.dll
2015-12-09 18:21 - 2015-11-03 19:55 - 00179712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\els.dll
2015-12-03 16:55 - 2015-12-03 16:55 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2015-12-03 16:55 - 2015-12-03 16:55 - 00000000 ____D C:\Program Files\Common Files\AV
2015-11-27 20:29 - 2015-12-13 19:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-11-27 20:28 - 2015-12-13 19:16 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-20 22:39 - 2012-12-08 16:48 - 00000000 ____D C:\Users\Vendy\AppData\Local\LogMeIn Hamachi
2015-12-20 22:35 - 2012-10-26 13:19 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-20 22:35 - 2012-05-24 21:40 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2015-12-20 22:35 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-20 22:27 - 2009-07-14 05:45 - 00031472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-20 22:27 - 2009-07-14 05:45 - 00031472 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-20 22:22 - 2014-05-31 10:51 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-20 22:22 - 2012-10-26 13:19 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-20 18:00 - 2012-05-24 21:40 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2015-12-20 07:30 - 2012-03-28 20:15 - 00000000 ____D C:\Windows\tr
2015-12-20 03:01 - 2015-04-05 09:22 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-12-20 03:01 - 2015-04-05 09:22 - 00000000 ___SD C:\Windows\system32\GWX
2015-12-19 21:24 - 2012-10-27 09:42 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-12-19 11:07 - 2014-05-31 10:51 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-12-19 11:07 - 2012-03-28 19:36 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-12-19 11:07 - 2012-03-28 19:36 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-19 09:30 - 2012-10-25 09:36 - 00000000 ____D C:\Users\Vendy
2015-12-19 03:18 - 2012-10-27 09:42 - 00451040 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-12-19 03:18 - 2012-10-27 09:42 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-12-17 23:12 - 2011-02-12 08:24 - 00000000 ____D C:\Windows
2015-12-17 19:00 - 2012-05-24 21:37 - 00000000 ____D C:\Users\UpdatusUser
2015-12-14 21:39 - 2014-10-11 17:57 - 00000000 ____D C:\Users\Vendy\AppData\Roaming\vlc
2015-12-14 21:39 - 2012-10-25 10:51 - 00000000 ____D C:\Users\Vendy\Documents\Seriály
2015-12-13 19:45 - 2012-05-24 22:15 - 01148312 _____ C:\Windows\system32\perfh005.dat
2015-12-13 19:45 - 2012-05-24 22:15 - 00308808 _____ C:\Windows\system32\perfc005.dat
2015-12-13 19:45 - 2009-07-14 06:13 - 00006264 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-13 19:16 - 2013-09-16 14:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2015-12-13 19:16 - 2013-09-16 14:25 - 00000000 ____D C:\Program Files (x86)\Tunngle
2015-12-13 19:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration
2015-12-13 19:16 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2015-12-12 15:17 - 2012-03-28 19:43 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-12-12 15:12 - 2014-02-10 12:10 - 00000000 ____D C:\Program Files (x86)\Euro Truck Simulator 2
2015-12-12 15:06 - 2014-05-30 16:47 - 00000000 ____D C:\Users\Vendy\AppData\Roaming\uTorrent
2015-12-11 22:30 - 2012-11-04 20:44 - 00000000 ____D C:\Users\Vendy\AppData\Local\CrashDumps
2015-12-11 22:28 - 2014-05-04 15:41 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-11 22:28 - 2014-02-07 23:23 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-12-11 22:28 - 2013-03-05 18:30 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-11 22:28 - 2013-03-05 18:30 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-11 22:28 - 2012-10-27 09:42 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-12-11 22:27 - 2012-10-27 09:42 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-11 17:29 - 2009-07-14 05:45 - 00440160 _____ C:\Windows\system32\FNTCACHE.DAT
2015-12-11 17:27 - 2014-09-17 11:11 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-12-11 17:27 - 2014-09-17 11:11 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-12-11 16:29 - 2014-03-13 18:41 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-12-11 16:29 - 2012-10-25 10:06 - 00000000 ____D C:\Users\Vendy\Documents\Vendy
2015-12-11 16:28 - 2014-09-17 11:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-12-11 16:24 - 2015-07-22 14:48 - 00000000 ____D C:\Users\Vendy\Documents\iPhone fotky
2015-12-11 16:17 - 2013-07-27 21:52 - 00000000 ____D C:\Windows\system32\MRT
2015-12-10 19:39 - 2012-10-27 09:51 - 140158008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-12-07 17:25 - 2012-10-26 13:19 - 00000000 ____D C:\Users\Vendy\AppData\Local\Google
2015-12-05 13:50 - 2014-07-20 20:06 - 00000000 ____D C:\Users\Vendy\AppData\Local\Adobe
2015-12-02 16:08 - 2012-10-26 13:19 - 00003948 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-02 16:08 - 2012-10-26 13:19 - 00003696 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-02 13:18 - 2010-11-21 04:27 - 00301728 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-12-01 20:47 - 2013-10-07 17:45 - 00000000 ____D C:\Users\Vendy\Documents\OA
2015-12-01 15:38 - 2013-06-15 19:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive

==================== Files in the root of some directories =======

2013-09-01 19:17 - 2014-10-12 18:17 - 0004608 _____ () C:\Users\Vendy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-05 09:21 - 2015-04-05 09:21 - 0000000 _____ () C:\Users\Vendy\AppData\Local\{335A376E-BBBA-465B-A779-607864A570F9}
2015-08-21 18:53 - 2015-08-21 18:53 - 0000000 _____ () C:\Users\Vendy\AppData\Local\{551E2F58-BCB8-45B5-836A-39597B7DB8A3}
2015-12-17 18:08 - 2015-12-17 18:08 - 0000000 _____ () C:\Users\Vendy\AppData\Local\{B5020CEF-224C-4234-81E9-814FC91E5202}
2012-05-24 21:54 - 2012-05-24 21:59 - 0002454 _____ () C:\ProgramData\clear.fiSDK20.log
2012-05-24 21:58 - 2015-04-04 09:59 - 0000032 _____ () C:\ProgramData\PS.log

Some files in TEMP:
====================
C:\Users\Vendy\AppData\Local\Temp\clearfiSetup.exe
C:\Users\Vendy\AppData\Local\Temp\EAD41FE.exe
C:\Users\Vendy\AppData\Local\Temp\EAD6392.exe
C:\Users\Vendy\AppData\Local\Temp\EADA65C.exe
C:\Users\Vendy\AppData\Local\Temp\i4jdel0.exe
C:\Users\Vendy\AppData\Local\Temp\i4jdel1.exe
C:\Users\Vendy\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe
C:\Users\Vendy\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\Vendy\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Vendy\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\Vendy\AppData\Local\Temp\jre-8u66-windows-au.exe
C:\Users\Vendy\AppData\Local\Temp\ose00000.exe
C:\Users\Vendy\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Vendy\AppData\Local\Temp\sqlite3.dll
C:\Users\Vendy\AppData\Local\Temp\UninstallEADM.dll
C:\Users\Vendy\AppData\Local\Temp\vlcurm.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Vendy\Desktop" je 6 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mám ho ok?

#8 Příspěvek od Márty84 »

:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

Start
CloseProcesses:
CreateRestorePoint:

HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId= ... kId=255141
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId= ... kId=255141
HKU\S-1-5-21-1558930999-2891573978-138013815-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId= ... nkId=69157
HKU\S-1-5-21-1558930999-2891573978-138013815-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
BHO: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120524133152.dll => No File
BHO-x32: scriptproxy -> {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -> C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120524133152.dll => No File
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File

FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore => not found
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found

S1 kfrjutwg; \??\C:\Windows\system32\drivers\kfrjutwg.sys [X]

C:\Windows\system32\drivers\kfrjutwg.sys

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Hosts:
EmptyTemp:
Reboot:
End
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev fixlist a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte FRST jako spravce, kliknete na napis Fix a program vykona prikazy.
Po restartu pc by se mel objevit novy log - s nazvem fixlog, ten mi sem zase zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

maybe
Návštěvník
Návštěvník
Příspěvky: 10
Registrován: 04 led 2010 21:06

Re: Mám ho ok?

#9 Příspěvek od maybe »

Na PC je asi jina chyba. NB nejde spustit. Ani po připojení k síti se nerozvíti. Zanesl jsem do servisu. I tak děkuji za rady.

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Mám ho ok?

#10 Příspěvek od Márty84 »

To je mi lito :-(

Necham tema zatim otevrene, kdyztak dejte vedet, jak to dopadlo.

Zatim se mejte :bye:



20.2. :lock: http://forum.viry.cz/viewtopic.php?f=12&t=123975
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno