
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o preventivku, děkuji
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosím o preventivku, děkuji
ok, díky už se stalo.
spíš mám problém s rychlosti spuštění, zkouším tedy co jde.
spíš mám problém s rychlosti spuštění, zkouším tedy co jde.
Re: Prosím o preventivku, děkuji
dobrý den, po odmlce se hlásím s logem. notas je docela pomalý ale má 4GB ram a Win 8....tak asi normální
# AdwCleaner v5.028 - Logfile created 10/01/2016 at 21:20:30
# Updated 04/01/2016 by Xplode
# Database : 2016-01-04.2 [Server]
# Operating system : Windows 8.1 (x64)
# Username : Anna - ANDULKA
# Running from : C:\Users\Anna\Desktop\adwcleaner_5.028.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Users\Anna\AppData\Local\FileViewPro
[-] Folder Deleted : C:\Users\Anna\AppData\Roaming\cpuminer
***** [ Files ] *****
[-] File Deleted : C:\WINDOWS\SysNative\cpuminer-conf.json
[-] File Deleted : C:\WINDOWS\SysNative\cpuminer-gw64.exe
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cpuminer
***** [ Web browsers ] *****
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1119 bytes] ##########
# AdwCleaner v5.028 - Logfile created 10/01/2016 at 21:20:30
# Updated 04/01/2016 by Xplode
# Database : 2016-01-04.2 [Server]
# Operating system : Windows 8.1 (x64)
# Username : Anna - ANDULKA
# Running from : C:\Users\Anna\Desktop\adwcleaner_5.028.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Users\Anna\AppData\Local\FileViewPro
[-] Folder Deleted : C:\Users\Anna\AppData\Roaming\cpuminer
***** [ Files ] *****
[-] File Deleted : C:\WINDOWS\SysNative\cpuminer-conf.json
[-] File Deleted : C:\WINDOWS\SysNative\cpuminer-gw64.exe
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cpuminer
***** [ Web browsers ] *****
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1119 bytes] ##########
Re: Prosím o preventivku, děkuji
ještě jsem tedy koukal a přijde mi že běží celkem dost procesů na pozadí systému...
Re: Prosím o preventivku, děkuji


Pozn. pri druhem a dalsim spusteni FRST je pro vytvoreni logu Addition.txt nutne tuto volbu explicitne zatrhnout pred zacatkem skenu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o preventivku, děkuji
Dobrý den, zase jsem se po delší době dostal k notebooku. Zasílám log z FRST a addition. Děkuji
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-01-2016
Ran by Anna (administrator) on ANDULKA (22-01-2016 17:19:33)
Running from C:\Users\Anna\Desktop
Loaded Profiles: Anna (Available Profiles: Anna & Administrator & Guest)
Platform: Windows 8.1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corp.) C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(forum.viry.cz) C:\Users\Anna\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2873744 2012-10-19] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LManager] => [X]
HKLM-x32\...\Run: [RadioController] => C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2012-11-15] (Dritek System Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-16] (Avast Software s.r.o.)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\Run: [GoogleChromeAutoLaunch_12C6C396F9F079F593189BD3E5EB8A5F] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [741704 2015-12-11] (Google Inc.)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\Run: [Dropbox Update] => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-01] (Dropbox, Inc.)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8590760 2015-12-08] (Piriform Ltd)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {b920dd28-1d89-11e5-be8e-b888e3d0e965} - "E:\autorun.exe"
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {ea6350a9-a29e-11e5-be9b-b888e3d0e965} - "E:\autorun.exe"
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {eb8f2070-1055-11e5-be8e-b888e3d0e965} - "E:\autorun.exe"
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-04-21] (Avast Software s.r.o.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk [2012-10-25]
ShortcutTarget: Acer Backup Manager Tray.lnk -> C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk [2015-11-29]
ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.)
Startup: C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-12-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Anna\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3C795E8F-C61D-4CCA-89DB-D14502E0E189}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{C2B2BEF3-82A8-46E7-B83B-D4E137315A67}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.cz/
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.facebook.com/
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> DefaultScope {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL =
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> {19E916F4-580B-4993-AF57-04930919E284} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-21] (Avast Software s.r.o.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-21] (Avast Software s.r.o.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-05-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-12]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchKeyword: Default -> google.cz____
CHR Profile: C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-01]
CHR Extension: (Angry Birds) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2014-12-13]
CHR Extension: (Dokumenty Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-11]
CHR Extension: (Disk Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-29]
CHR Extension: (Zhasnout světla) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2016-01-22]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-06-01]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2015-06-01]
CHR Extension: (YouTube) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-30]
CHR Extension: (Vyhledávání Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2014-10-12]
CHR Extension: (Tabulky Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-01]
CHR Extension: (Dokumenty Google offline) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-14]
CHR Extension: (AdBlock) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-22]
CHR Extension: (Slinky Prastsrý) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkdjbhifhppglclhnmmnlfloepnolbkn [2015-06-08]
CHR Extension: (Cheapstamatic) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\lamcdjgcnmmghjceofmdaghmgoehlkbn [2014-10-12]
CHR Extension: (Pix: Pixel Mixer) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbjiacdnbellpbhocabghholhnlboibg [2014-10-12]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-23]
CHR Extension: (piZap Photo Editor) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\occpjibghkbopohbefbejkklnfdkdmok [2014-10-12]
CHR Extension: (Můj motiv Chrome) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2015-09-04]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-11-08]
CHR Extension: (Gmail) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-19]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-21]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-21] (Avast Software s.r.o.)
R2 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-21] (Broadcom Corp.) [File not signed]
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2435728 2012-08-24] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-23] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-23] (Acer Incorporated)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-23] (NTI Corporation)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [96880 2012-11-15] (Dritek System INC.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-04-21] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-21] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-21] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-06-29] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-04-21] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-04-21] ()
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2015-11-29] (ITE )
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-11-15] (Dritek System Inc.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-22 17:16 - 2016-01-22 17:19 - 00021206 _____ C:\Users\Anna\Desktop\FRST.txt
2016-01-22 17:16 - 2016-01-22 17:19 - 00000000 ____D C:\FRST
2016-01-22 17:15 - 2016-01-22 17:15 - 02370560 _____ (Farbar) C:\Users\Anna\Desktop\FRST64.exe
2016-01-22 17:13 - 2016-01-22 17:13 - 00112640 _____ (forum.viry.cz) C:\Users\Anna\Desktop\FRSTLauncher.exe
2016-01-10 21:39 - 2016-01-10 21:39 - 00002786 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-01-10 21:39 - 2016-01-10 21:39 - 00000838 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-01-10 21:39 - 2016-01-10 21:39 - 00000000 ____D C:\Program Files\CCleaner
2016-01-10 21:38 - 2016-01-10 21:38 - 06808384 _____ (Piriform Ltd) C:\Users\Anna\Desktop\ccsetup513pro.exe
2016-01-10 21:14 - 2016-01-10 21:28 - 00000000 ____D C:\AdwCleaner
2016-01-10 21:13 - 2016-01-10 21:13 - 01749504 _____ C:\Users\Anna\Desktop\adwcleaner_5.028.exe
2015-12-27 21:12 - 2015-12-27 21:12 - 00052039 _____ C:\Users\Anna\Desktop\info.txt
2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\rsit
2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\Program Files\trend micro
2015-12-27 21:04 - 2015-12-27 21:04 - 01222144 _____ C:\Users\Anna\Desktop\RSITx64.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-22 17:18 - 2015-11-07 17:13 - 00000000 ____D C:\Users\Anna\AppData\Roaming\uTorrent
2016-01-22 17:18 - 2013-08-22 14:36 - 00000000 ____D C:\Windows
2016-01-22 17:16 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-01-22 17:15 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-01-22 17:12 - 2012-07-26 08:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-01-22 17:00 - 2015-08-01 21:55 - 00000930 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001UA.job
2016-01-22 16:58 - 2015-01-10 13:02 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-01-22 16:57 - 2015-01-30 12:58 - 00003962 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4937A563-BEEA-44AF-9C33-AB91F4C9D26E}
2016-01-17 21:42 - 2014-10-10 22:35 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1921050744-976541742-1940543023-1001
2016-01-17 20:52 - 2014-10-12 15:46 - 00002207 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-17 20:52 - 2014-10-12 15:46 - 00000976 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-17 20:01 - 2014-11-13 14:08 - 00000000 ____D C:\Users\Anna\OneDrive
2016-01-17 20:00 - 2014-10-12 15:46 - 00000972 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-17 19:51 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-01-12 11:32 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-01-12 11:26 - 2014-11-13 14:52 - 00000000 ____D C:\Users\Anna\AppData\Local\Deployment
2016-01-12 11:22 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\Inf
2016-01-10 21:44 - 2014-11-13 13:05 - 00000000 ___DC C:\WINDOWS\Panther
2016-01-10 21:44 - 2014-10-13 14:30 - 00000000 ____D C:\Users\Anna\AppData\Local\CrashDumps
2016-01-10 21:09 - 2015-05-18 19:22 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2016-01-10 21:09 - 2015-05-18 19:21 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Seznam.cz
2016-01-10 21:08 - 2015-09-12 17:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-01-10 20:57 - 2014-10-12 15:47 - 00000000 ____D C:\Program Files\Google
2016-01-10 20:57 - 2014-10-12 15:45 - 00000000 ____D C:\Program Files (x86)\Google
2016-01-10 20:52 - 2014-10-12 15:45 - 00000000 ____D C:\Users\Anna\AppData\Local\Google
2016-01-10 16:47 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-01-10 16:02 - 2014-09-24 17:23 - 01745984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-01-10 16:02 - 2014-09-24 16:39 - 00739924 _____ C:\WINDOWS\system32\perfh005.dat
2016-01-10 16:02 - 2014-09-24 16:39 - 00151610 _____ C:\WINDOWS\system32\perfc005.dat
2016-01-07 13:35 - 2014-10-29 13:06 - 00000000 ____D C:\Users\Anna\AppData\Roaming\vlc
2015-12-26 09:48 - 2015-11-17 09:27 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-12-26 09:48 - 2015-11-17 09:27 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
Some files in TEMP:
====================
C:\Users\Anna\AppData\Local\Temp\sqlite3.dll
C:\Users\Anna\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001Core.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001UA.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Anna\Desktop" je 3631 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-01-2016
Ran by Anna (administrator) on ANDULKA (22-01-2016 17:19:33)
Running from C:\Users\Anna\Desktop
Loaded Profiles: Anna (Available Profiles: Anna & Administrator & Guest)
Platform: Windows 8.1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corp.) C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\avastui.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(forum.viry.cz) C:\Users\Anna\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2873744 2012-10-19] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LManager] => [X]
HKLM-x32\...\Run: [RadioController] => C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2012-11-15] (Dritek System Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-05-16] (Avast Software s.r.o.)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\Run: [GoogleChromeAutoLaunch_12C6C396F9F079F593189BD3E5EB8A5F] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [741704 2015-12-11] (Google Inc.)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\Run: [Dropbox Update] => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-01] (Dropbox, Inc.)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8590760 2015-12-08] (Piriform Ltd)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {b920dd28-1d89-11e5-be8e-b888e3d0e965} - "E:\autorun.exe"
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {ea6350a9-a29e-11e5-be9b-b888e3d0e965} - "E:\autorun.exe"
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {eb8f2070-1055-11e5-be8e-b888e3d0e965} - "E:\autorun.exe"
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Anna\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-04-21] (Avast Software s.r.o.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk [2012-10-25]
ShortcutTarget: Acer Backup Manager Tray.lnk -> C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TMMonitor.lnk [2015-11-29]
ShortcutTarget: TMMonitor.lnk -> C:\Program Files (x86)\ArcSoft\TotalMedia 3.5\TMMonitor.exe (ArcSoft, Inc.)
Startup: C:\Users\Anna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-12-12]
ShortcutTarget: Dropbox.lnk -> C:\Users\Anna\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3C795E8F-C61D-4CCA-89DB-D14502E0E189}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{C2B2BEF3-82A8-46E7-B83B-D4E137315A67}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.cz/
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.facebook.com/
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> DefaultScope {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL =
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> {19E916F4-580B-4993-AF57-04930919E284} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-21] (Avast Software s.r.o.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-21] (Avast Software s.r.o.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-07] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-05-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-12]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR DefaultSearchKeyword: Default -> google.cz____
CHR Profile: C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-01]
CHR Extension: (Angry Birds) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2014-12-13]
CHR Extension: (Dokumenty Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-11]
CHR Extension: (Disk Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-29]
CHR Extension: (Zhasnout světla) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn [2016-01-22]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-06-01]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2015-06-01]
CHR Extension: (YouTube) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-30]
CHR Extension: (Vyhledávání Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2014-10-12]
CHR Extension: (Tabulky Google) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-01]
CHR Extension: (Dokumenty Google offline) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-14]
CHR Extension: (AdBlock) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-22]
CHR Extension: (Slinky Prastsrý) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkdjbhifhppglclhnmmnlfloepnolbkn [2015-06-08]
CHR Extension: (Cheapstamatic) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\lamcdjgcnmmghjceofmdaghmgoehlkbn [2014-10-12]
CHR Extension: (Pix: Pixel Mixer) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbjiacdnbellpbhocabghholhnlboibg [2014-10-12]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-23]
CHR Extension: (piZap Photo Editor) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\occpjibghkbopohbefbejkklnfdkdmok [2014-10-12]
CHR Extension: (Můj motiv Chrome) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2015-09-04]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-11-08]
CHR Extension: (Gmail) - C:\Users\Anna\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-19]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-04-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-21]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-21] (Avast Software s.r.o.)
R2 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-21] (Broadcom Corp.) [File not signed]
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2435728 2012-08-24] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-23] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-23] (Acer Incorporated)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-23] (NTI Corporation)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [96880 2012-11-15] (Dritek System INC.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-04-21] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-21] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-21] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-06-29] (Avast Software s.r.o.)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-04-21] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-04-21] ()
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [165504 2015-11-29] (ITE )
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-11-15] (Dritek System Inc.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-22 17:16 - 2016-01-22 17:19 - 00021206 _____ C:\Users\Anna\Desktop\FRST.txt
2016-01-22 17:16 - 2016-01-22 17:19 - 00000000 ____D C:\FRST
2016-01-22 17:15 - 2016-01-22 17:15 - 02370560 _____ (Farbar) C:\Users\Anna\Desktop\FRST64.exe
2016-01-22 17:13 - 2016-01-22 17:13 - 00112640 _____ (forum.viry.cz) C:\Users\Anna\Desktop\FRSTLauncher.exe
2016-01-10 21:39 - 2016-01-10 21:39 - 00002786 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-01-10 21:39 - 2016-01-10 21:39 - 00000838 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-01-10 21:39 - 2016-01-10 21:39 - 00000000 ____D C:\Program Files\CCleaner
2016-01-10 21:38 - 2016-01-10 21:38 - 06808384 _____ (Piriform Ltd) C:\Users\Anna\Desktop\ccsetup513pro.exe
2016-01-10 21:14 - 2016-01-10 21:28 - 00000000 ____D C:\AdwCleaner
2016-01-10 21:13 - 2016-01-10 21:13 - 01749504 _____ C:\Users\Anna\Desktop\adwcleaner_5.028.exe
2015-12-27 21:12 - 2015-12-27 21:12 - 00052039 _____ C:\Users\Anna\Desktop\info.txt
2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\rsit
2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\Program Files\trend micro
2015-12-27 21:04 - 2015-12-27 21:04 - 01222144 _____ C:\Users\Anna\Desktop\RSITx64.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-22 17:18 - 2015-11-07 17:13 - 00000000 ____D C:\Users\Anna\AppData\Roaming\uTorrent
2016-01-22 17:18 - 2013-08-22 14:36 - 00000000 ____D C:\Windows
2016-01-22 17:16 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-01-22 17:15 - 2013-08-22 16:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-01-22 17:12 - 2012-07-26 08:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-01-22 17:00 - 2015-08-01 21:55 - 00000930 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001UA.job
2016-01-22 16:58 - 2015-01-10 13:02 - 00003886 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-01-22 16:57 - 2015-01-30 12:58 - 00003962 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4937A563-BEEA-44AF-9C33-AB91F4C9D26E}
2016-01-17 21:42 - 2014-10-10 22:35 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1921050744-976541742-1940543023-1001
2016-01-17 20:52 - 2014-10-12 15:46 - 00002207 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-17 20:52 - 2014-10-12 15:46 - 00000976 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-17 20:01 - 2014-11-13 14:08 - 00000000 ____D C:\Users\Anna\OneDrive
2016-01-17 20:00 - 2014-10-12 15:46 - 00000972 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-17 19:51 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-01-12 11:32 - 2013-08-22 14:25 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-01-12 11:26 - 2014-11-13 14:52 - 00000000 ____D C:\Users\Anna\AppData\Local\Deployment
2016-01-12 11:22 - 2013-08-22 14:36 - 00000000 ____D C:\WINDOWS\Inf
2016-01-10 21:44 - 2014-11-13 13:05 - 00000000 ___DC C:\WINDOWS\Panther
2016-01-10 21:44 - 2014-10-13 14:30 - 00000000 ____D C:\Users\Anna\AppData\Local\CrashDumps
2016-01-10 21:09 - 2015-05-18 19:22 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2016-01-10 21:09 - 2015-05-18 19:21 - 00000000 ____D C:\Users\Anna\AppData\Roaming\Seznam.cz
2016-01-10 21:08 - 2015-09-12 17:41 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-01-10 20:57 - 2014-10-12 15:47 - 00000000 ____D C:\Program Files\Google
2016-01-10 20:57 - 2014-10-12 15:45 - 00000000 ____D C:\Program Files (x86)\Google
2016-01-10 20:52 - 2014-10-12 15:45 - 00000000 ____D C:\Users\Anna\AppData\Local\Google
2016-01-10 16:47 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-01-10 16:02 - 2014-09-24 17:23 - 01745984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-01-10 16:02 - 2014-09-24 16:39 - 00739924 _____ C:\WINDOWS\system32\perfh005.dat
2016-01-10 16:02 - 2014-09-24 16:39 - 00151610 _____ C:\WINDOWS\system32\perfc005.dat
2016-01-07 13:35 - 2014-10-29 13:06 - 00000000 ____D C:\Users\Anna\AppData\Roaming\vlc
2015-12-26 09:48 - 2015-11-17 09:27 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-12-26 09:48 - 2015-11-17 09:27 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
Some files in TEMP:
====================
C:\Users\Anna\AppData\Local\Temp\sqlite3.dll
C:\Users\Anna\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001Core.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001UA.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Anna\Desktop" je 3631 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Re: Prosím o preventivku, děkuji

- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi
Kód: Vybrat vše
Start CreateRestorePoint: CloseProcesses: Folder: C:\Users\Anna\AppData\Local\CrashDumps HKLM-x32\...\Run: [LManager] => [X] HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.) HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {b920dd28-1d89-11e5-be8e-b888e3d0e965} - "E:\autorun.exe" HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {ea6350a9-a29e-11e5-be9b-b888e3d0e965} - "E:\autorun.exe" HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {eb8f2070-1055-11e5-be8e-b888e3d0e965} - "E:\autorun.exe" SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> DefaultScope {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL = SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL = 2016-01-22 17:16 - 2016-01-22 17:19 - 00021206 _____ C:\Users\Anna\Desktop\FRST.txt 2016-01-10 21:14 - 2016-01-10 21:28 - 00000000 ____D C:\AdwCleaner 2016-01-10 21:13 - 2016-01-10 21:13 - 01749504 _____ C:\Users\Anna\Desktop\adwcleaner_5.028.exe 2015-12-27 21:12 - 2015-12-27 21:12 - 00052039 _____ C:\Users\Anna\Desktop\info.txt 2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\rsit 2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\Program Files\trend micro 2015-12-27 21:04 - 2015-12-27 21:04 - 01222144 _____ C:\Users\Anna\Desktop\RSITx64.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001Core.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001UA.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe EmptyTemp: End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o preventivku, děkuji
Fix result of Farbar Recovery Scan Tool (x64) Version:18-01-2016
Ran by Anna (2016-01-24 10:07:44) Run:1
Running from C:\Users\Anna\Desktop
Loaded Profiles: Anna (Available Profiles: Anna & Administrator & Guest)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
Folder: C:\Users\Anna\AppData\Local\CrashDumps
HKLM-x32\...\Run: [LManager] => [X]
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {b920dd28-1d89-11e5-be8e-b888e3d0e965} - "E:\autorun.exe"
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {ea6350a9-a29e-11e5-be9b-b888e3d0e965} - "E:\autorun.exe"
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {eb8f2070-1055-11e5-be8e-b888e3d0e965} - "E:\autorun.exe"
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> DefaultScope {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL =
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL =
2016-01-22 17:16 - 2016-01-22 17:19 - 00021206 _____ C:\Users\Anna\Desktop\FRST.txt
2016-01-10 21:14 - 2016-01-10 21:28 - 00000000 ____D C:\AdwCleaner
2016-01-10 21:13 - 2016-01-10 21:13 - 01749504 _____ C:\Users\Anna\Desktop\adwcleaner_5.028.exe
2015-12-27 21:12 - 2015-12-27 21:12 - 00052039 _____ C:\Users\Anna\Desktop\info.txt
2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\rsit
2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\Program Files\trend micro
2015-12-27 21:04 - 2015-12-27 21:04 - 01222144 _____ C:\Users\Anna\Desktop\RSITx64.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001Core.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001UA.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
========================= Folder: C:\Users\Anna\AppData\Local\CrashDumps ========================
====== End of Folder: ======
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\LManager => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS5ServiceManager => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value removed successfully
"HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b920dd28-1d89-11e5-be8e-b888e3d0e965}" => key removed successfully
HKCR\CLSID\{b920dd28-1d89-11e5-be8e-b888e3d0e965} => key not found.
"HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea6350a9-a29e-11e5-be9b-b888e3d0e965}" => key removed successfully
HKCR\CLSID\{ea6350a9-a29e-11e5-be9b-b888e3d0e965} => key not found.
"HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eb8f2070-1055-11e5-be8e-b888e3d0e965}" => key removed successfully
HKCR\CLSID\{eb8f2070-1055-11e5-be8e-b888e3d0e965} => key not found.
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1D9E12D6-367C-4BA7-BA43-6C18FA611202}" => key removed successfully
HKCR\CLSID\{1D9E12D6-367C-4BA7-BA43-6C18FA611202} => key not found.
C:\Users\Anna\Desktop\FRST.txt => moved successfully
C:\AdwCleaner => moved successfully
C:\Users\Anna\Desktop\adwcleaner_5.028.exe => moved successfully
C:\Users\Anna\Desktop\info.txt => moved successfully
C:\rsit => moved successfully
C:\Program Files\trend micro => moved successfully
C:\Users\Anna\Desktop\RSITx64.exe => moved successfully
C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001Core.job => moved successfully
C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001UA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
EmptyTemp: => 133.3 MB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 10:09:23 ====
Ran by Anna (2016-01-24 10:07:44) Run:1
Running from C:\Users\Anna\Desktop
Loaded Profiles: Anna (Available Profiles: Anna & Administrator & Guest)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
Folder: C:\Users\Anna\AppData\Local\CrashDumps
HKLM-x32\...\Run: [LManager] => [X]
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {b920dd28-1d89-11e5-be8e-b888e3d0e965} - "E:\autorun.exe"
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {ea6350a9-a29e-11e5-be9b-b888e3d0e965} - "E:\autorun.exe"
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\...\MountPoints2: {eb8f2070-1055-11e5-be8e-b888e3d0e965} - "E:\autorun.exe"
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> DefaultScope {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL =
SearchScopes: HKU\S-1-5-21-1921050744-976541742-1940543023-1001 -> {1D9E12D6-367C-4BA7-BA43-6C18FA611202} URL =
2016-01-22 17:16 - 2016-01-22 17:19 - 00021206 _____ C:\Users\Anna\Desktop\FRST.txt
2016-01-10 21:14 - 2016-01-10 21:28 - 00000000 ____D C:\AdwCleaner
2016-01-10 21:13 - 2016-01-10 21:13 - 01749504 _____ C:\Users\Anna\Desktop\adwcleaner_5.028.exe
2015-12-27 21:12 - 2015-12-27 21:12 - 00052039 _____ C:\Users\Anna\Desktop\info.txt
2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\rsit
2015-12-27 21:05 - 2015-12-27 21:05 - 00000000 ____D C:\Program Files\trend micro
2015-12-27 21:04 - 2015-12-27 21:04 - 01222144 _____ C:\Users\Anna\Desktop\RSITx64.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001Core.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001UA.job => C:\Users\Anna\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
========================= Folder: C:\Users\Anna\AppData\Local\CrashDumps ========================
====== End of Folder: ======
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\LManager => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SwitchBoard => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AdobeCS5ServiceManager => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value removed successfully
"HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b920dd28-1d89-11e5-be8e-b888e3d0e965}" => key removed successfully
HKCR\CLSID\{b920dd28-1d89-11e5-be8e-b888e3d0e965} => key not found.
"HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea6350a9-a29e-11e5-be9b-b888e3d0e965}" => key removed successfully
HKCR\CLSID\{ea6350a9-a29e-11e5-be9b-b888e3d0e965} => key not found.
"HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eb8f2070-1055-11e5-be8e-b888e3d0e965}" => key removed successfully
HKCR\CLSID\{eb8f2070-1055-11e5-be8e-b888e3d0e965} => key not found.
HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-1921050744-976541742-1940543023-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1D9E12D6-367C-4BA7-BA43-6C18FA611202}" => key removed successfully
HKCR\CLSID\{1D9E12D6-367C-4BA7-BA43-6C18FA611202} => key not found.
C:\Users\Anna\Desktop\FRST.txt => moved successfully
C:\AdwCleaner => moved successfully
C:\Users\Anna\Desktop\adwcleaner_5.028.exe => moved successfully
C:\Users\Anna\Desktop\info.txt => moved successfully
C:\rsit => moved successfully
C:\Program Files\trend micro => moved successfully
C:\Users\Anna\Desktop\RSITx64.exe => moved successfully
C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001Core.job => moved successfully
C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1921050744-976541742-1940543023-1001UA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
EmptyTemp: => 133.3 MB temporary data Removed.
The system needed a reboot.
==== End of Fixlog 10:09:23 ====
Re: Prosím o preventivku, děkuji
Vse probehlo v poradku. Jak se chova PC? Budeme hledat hloubeji?
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o preventivku, děkuji
Nejsem ted u notebooku (jak jinak
) ale myslím, že jde pořád stejně jako před odstraněním mineru a virů. Ale to už asi bude tím, že to jsou 4GB ram a procesor teď zpaměti nevím (mrknu příště). Docela by mě zajímalo "normální" pracovní vytížení takovéhoto notebooku - myslím RAM a využití procesoru s WIN 8. Podívám se na něj příště při běžné práci kolik to "vysává". Zatím děkuji moc za vyčištění. Radek

Re: Prosím o preventivku, děkuji
Neexistuje (alespon o ni nevim) definice, kolik RAM je normalni a kolik ne - jde o muj nazor. Na PC se po startu spousti procesy, ktere najdete (na Win 8.1) po stisku Ctrl+Shift+Esc na karte Po spusteni a dale sluzby, na ktere se dostanete Win+R -> msconfig - jsou to ty, ktere maji nastavene spousteni Automaticky. Pokud se rozhodnete neco zakazat, mejte na pameti, ze muze jit o dulezitou soucast operacniho systemu. Nachazi se tam ale i potencialne nechtene procesy, ktere startuji automaticky (radim mezi ne napr. Skype, ruzne updatery, ...) a RAM potrebuji. Na stranu druhou, RAM pamet je od toho, aby byla pouzivana a urychlovala tak cinnost PC. Pokud je vyuziti RAM ~ 40 % v klidu, jedna se o naprosto normalni stav.
BitCoin miner smazal uz AdwCleaner. Muzete PC zkontrolovat jeste pomoci MBAM. Nainstalujte MBAM a udelejte vlastni sken vsech disku - http://forum.viry.cz/viewtopic.php?f=29&t=144868
Upozorneni: tento sken zabere od 30 minut po nekolik hodin.
BitCoin miner smazal uz AdwCleaner. Muzete PC zkontrolovat jeste pomoci MBAM. Nainstalujte MBAM a udelejte vlastni sken vsech disku - http://forum.viry.cz/viewtopic.php?f=29&t=144868
Upozorneni: tento sken zabere od 30 minut po nekolik hodin.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Prosím o preventivku, děkuji
Pres msconfig uz jsem nektere sluzby po spusteni zakazal. Ctrl+Shift+Esc a procesy jsem nekoukal, ale mrknu. Povypínal jsem různé utility od ACERu, které si aspon myslím nejsou potreba, nevim jaky mate nazor na ruzne "urychlovace" a "optimalizatory" ukladani mista na disku ale tem take moc neholduji takze jsem take odinstaloval. (tusim ze to byl nejaky noname soft a nevim jak se do notebooku dostal). Jeste na to priste mrknu. PC bezi, mozna mam take trochu zkresleni z meho stolniho (i5-4460 3,2 GHz a 16 GB RAM) a proto povazuji notebook za pomaly.
Re: Prosím o preventivku, děkuji
Na bloatware (predinstalovany soft vyrobcu notebooku) take nadavam a jedine, co proti tomu delam je vzdy po koupi noveho stroje format a cista instalacka... Optimalizerum vseho druhu naklonen nejsem (krom CCleaneru, ktery je v defaultnim nastaveni neskodny). Nekdo s nimi muze mit pozitivni zkusenosti, ale ja je holt nemam 

Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.