Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Číňani na koni

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Noviik
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 28 říj 2013 15:53

Číňani na koni

#1 Příspěvek od Noviik »

Ahoj,

včera jsem si do kompu stáhl nějakej šmejd a teď tu mám čínské mužíky s čínským písmem (teda asi čínským). Pokusil jsem se odstranit vše, ale určitě jsem nebyl úplně úspěšný. Prosím proto o zásah profíků :-)

Díky moc

Noviik



Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Martin (administrator) on MARTIN-PC (25-03-2016 10:37:48)
Running from C:\Users\Martin\Desktop
Loaded Profiles: Martin (Available Profiles: Martin & DefaultAppPool)
Platform: Windows 10 Home (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\asww10mon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
(NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe
() C:\ProgramData\Boxtools\Toolbox.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Lenovo) C:\Users\Martin\AppData\Local\Apps\2.0\G8O0KMPB.CW0\T344K5RY.9OW\lsb...tion_91a10ba61c75c82d_0001.0006_014be6b8b4b27d94\LSB.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtsFT] => RTFTrack.exe
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-23] (AVAST Software)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [571928 2015-12-30] (Vimicro)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [13229912 2014-01-15] (NTeWORKS)
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\...\Run: [Boxoft Tools] => C:\ProgramData\Boxtools\Boxofttoolbox.exe [514048 2010-12-15] ()
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4179288 2015-11-30] (Disc Soft Ltd)
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [583680 2015-07-10] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [175552 2016-03-08] (NVIDIA Corporation)
AppInit_DLLs: , C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [175552 2016-03-08] (NVIDIA Corporation)
AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [175552 2016-03-08] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [153208 2016-03-08] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-12] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{01021f86-2d02-446c-ae13-41e776d12267}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{5101965d-5da9-4c8f-8ef6-aeec3376cb71}: [DhcpNameServer] 10.0.0.138
ManualProxies:

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-3754952095-1263816399-3501759939-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-12] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-06] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-12] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-06] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-3754952095-1263816399-3501759939-1000 -> hxxp://google.cz/

FireFox:
========
FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1f7jxlmq.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-24] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-24] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-06] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3754952095-1263816399-3501759939-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Martin\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin HKU\S-1-5-21-3754952095-1263816399-3501759939-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Martin\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Extension: Adblock Plus - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1f7jxlmq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-03-05]
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-24] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-13]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-13]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/
CHR Profile: C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-17]
CHR Extension: (Dokumenty Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-17]
CHR Extension: (Disk Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-17]
CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-17]
CHR Extension: (Vyhledávání Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-17]
CHR Extension: (Kalendář Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2016-02-17]
CHR Extension: (Tabulky Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-17]
CHR Extension: (Dokumenty Google offline) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-18]
CHR Extension: (Avast Online Security) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-17]
CHR Extension: (Last.fm scrobbler for Google Play) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhlmaloocaogaldcbpimhlbimmhaonep [2016-02-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-17]
CHR Extension: (电脑管家上网防护) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm [2016-03-25]
CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-17]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-12]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-11-03] (SUPERAntiSpyware.com)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-12] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [119128 2016-02-12] (AVAST Software)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1368408 2015-11-30] (Disc Soft Ltd)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [625632 2015-07-22] (Lenovo)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [271296 2015-08-17] (Lenovo)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation)
S2 SetupARService; C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [10752 2015-11-30] () [File not signed]
S3 ShareItSvc; C:\Program Files (x86)\Lenovo\SHAREit\Shareit.Service.exe [31192 2016-02-02] (SHAREit Technologies Co.Ltd)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5429520 2015-01-30] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-12] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-02-12] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-09] (AVAST Software)
R1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [552880 2016-02-23] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-12] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-12] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-09] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-23] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-12] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-12] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-01-10] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [46392 2016-01-10] (Disc Soft Ltd)
S3 ldiagio_uefi; C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [24808 2015-04-01] (Lenovo Group Limited (R))
R3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3354384 2015-06-18] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-06-18] (Realtek )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2015-11-02] (DEVGURU Co., LTD.(http://www.devguru.co.kr))
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [648872 2015-12-30] (Vimicro Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 IntcAzAudAddService; \SystemRoot\system32\drivers\RTKVHD64.sys [X]
S1 QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\QMUdisk64.sys [X]
S1 softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\softaal64.sys [X]
S2 tsnethlpx64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\TsNetHlpX64.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-25 10:37 - 2016-03-25 10:38 - 00020273 _____ C:\Users\Martin\Desktop\FRST.txt
2016-03-25 10:34 - 2016-03-25 10:34 - 00029696 _____ C:\Users\Martin\AppData\Local\MSGBOX.EXE
2016-03-25 10:34 - 2016-03-25 10:34 - 00015327 _____ C:\Users\Martin\Desktop\LM.bat
2016-03-25 10:33 - 2016-03-25 10:34 - 00112640 _____ (forum.viry.cz) C:\Users\Martin\Desktop\FRSTLauncher.exe
2016-03-25 10:28 - 2016-03-25 10:35 - 02374144 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe
2016-03-25 10:22 - 2016-03-25 10:22 - 00016148 _____ C:\WINDOWS\system32\MARTIN-PC_Martin_HistoryPrediction.bin
2016-03-25 10:04 - 2016-03-25 10:04 - 00000000 ___HD C:\OneDriveTemp
2016-03-24 23:31 - 2016-03-24 23:31 - 00000270 __RSH C:\Users\Martin\ntuser.pol
2016-03-24 22:51 - 2016-03-24 22:51 - 00002658 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-24 22:51 - 2016-03-24 22:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-24 22:51 - 2016-03-24 22:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-03-24 22:46 - 2016-03-24 23:31 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-03-24 22:38 - 2016-03-24 22:38 - 00005120 _____ C:\Users\Martin\AppData\Roaming\GiftBag.db
2016-03-24 22:38 - 2016-03-24 22:38 - 00000000 ____D C:\Program Files\Common Files\Tencent
2016-03-24 22:38 - 2016-03-24 22:36 - 00132344 _____ (Tencent Technology(Shenzhen) Company Limited) C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys
2016-03-24 22:37 - 2016-03-24 22:43 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
2016-03-24 22:37 - 2016-03-24 22:37 - 00000000 ____D C:\ProgramData\TXQMPC
2016-03-24 22:37 - 2016-03-24 22:36 - 00087800 _____ (电脑管家) C:\WINDOWS\system32\Drivers\TFsFltX64.sys
2016-03-24 22:36 - 2016-03-24 22:40 - 00000000 ____D C:\ProgramData\Tencent
2016-03-24 22:36 - 2016-03-24 22:38 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Tencent
2016-03-24 22:36 - 2016-03-24 22:36 - 00000000 ____D C:\Program Files (x86)\Tencent
2016-03-24 22:35 - 2016-03-24 22:35 - 00000270 __RSH C:\ProgramData\ntuser.pol
2016-03-24 22:07 - 2016-03-24 22:07 - 00000080 _____ C:\Users\Martin\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
2016-03-24 21:59 - 2016-03-24 21:59 - 00002016 _____ C:\Users\Public\Desktop\Grand Theft Auto V.lnk
2016-03-24 19:16 - 2016-03-24 22:08 - 00000000 ____D C:\Program Files\Rockstar Games
2016-03-18 10:28 - 2016-03-18 10:28 - 00003040 _____ C:\WINDOWS\System32\Tasks\avast! Windows 10 Start Menu helper
2016-03-17 08:53 - 2016-03-17 08:58 - 00000000 ____D C:\Users\Martin\Documents\BotaniculaSaves
2016-03-14 12:14 - 2016-03-14 12:14 - 00000000 ____D C:\WINDOWS\LastGood
2016-03-14 12:12 - 2016-03-14 12:12 - 13037568 _____ (Intel Corporation) C:\WINDOWS\system32\ig4icd64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 12814752 _____ (Intel Corporation) C:\WINDOWS\system32\igdumd64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 11352688 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10umd32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 11223896 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumd32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 10820096 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig4icd32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 09016320 _____ (Intel Corporation) C:\WINDOWS\system32\igfxress.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 05916080 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUI.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 03520000 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 03129856 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 01067696 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00957472 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00584192 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00551424 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00544552 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00539312 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00523184 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 00451584 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdev.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00449024 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrell.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00448512 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfra.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00448512 _____ (Intel Corporation) C:\WINDOWS\system32\igfxresn.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00448000 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrus.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00448000 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrom.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsky.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptg.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrplk.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnld.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrita.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhrv.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdeu.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446976 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhun.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446976 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfin.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtrk.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsve.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrslv.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptb.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnor.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00445952 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtha.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00445952 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdan.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00444416 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrheb.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00444416 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrara.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00440832 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrjpn.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00439808 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrkor.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00437760 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcht.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00437248 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrchs.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00418816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxTMM.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00393216 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpph.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00339456 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxdv32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00294912 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrenu.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00266152 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 00231312 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00197040 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 00194880 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00183808 _____ (Intel Corporation) C:\WINDOWS\system32\gfxSrvc.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00183216 _____ (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 00151040 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdo.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00135680 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcpl.cpl
2016-03-14 12:12 - 2016-03-14 12:12 - 00110080 _____ C:\WINDOWS\system32\igdde64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00090112 _____ C:\WINDOWS\SysWOW64\igdde32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00041288 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00033792 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00018432 _____ ( ) C:\WINDOWS\system32\IGFXDEVLib.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00017082 _____ C:\WINDOWS\system32\iglhxs64.vp
2016-03-13 20:25 - 2016-03-24 23:35 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2016-03-13 20:25 - 2016-03-24 23:35 - 00000000 ____D C:\WINDOWS\system32\NV
2016-03-13 19:20 - 2016-03-24 23:30 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-03-13 19:18 - 2016-03-10 03:58 - 00048704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2016-03-13 19:18 - 2016-03-08 11:27 - 42968120 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 37609528 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 22971960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 21322480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 20863920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 18906048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 17732960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 17368424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 17325400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 17320280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 10547128 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 08657936 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 02613696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 02257344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 01922496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00955328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00885184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00786872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00750016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00692160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00678704 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00632152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00571912 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00423360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00379296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00377792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00317656 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00151184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00128696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00000139 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-03-13 19:18 - 2016-03-08 11:27 - 00000139 _____ C:\WINDOWS\system32\nv-vk64.json
2016-03-08 20:30 - 2016-02-23 15:53 - 01314496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-08 20:30 - 2016-02-23 15:52 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-03-08 20:30 - 2016-02-23 15:51 - 00633184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-03-08 20:30 - 2016-02-23 15:51 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-08 20:30 - 2016-02-23 15:50 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-08 20:30 - 2016-02-23 15:48 - 08022368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-08 20:30 - 2016-02-23 15:48 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-03-08 20:30 - 2016-02-23 15:48 - 01123952 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-03-08 20:30 - 2016-02-23 15:41 - 01150816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-08 20:30 - 2016-02-23 15:41 - 00299600 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMASF.DLL
2016-03-08 20:30 - 2016-02-23 15:41 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-03-08 20:30 - 2016-02-23 15:40 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-03-08 20:30 - 2016-02-23 15:38 - 00272752 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-08 20:30 - 2016-02-23 15:36 - 00080128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-03-08 20:30 - 2016-02-23 15:11 - 00781984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-08 20:30 - 2016-02-23 15:11 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-08 20:30 - 2016-02-23 15:11 - 00103776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-03-08 20:30 - 2016-02-23 15:08 - 03622272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-03-08 20:30 - 2016-02-23 15:07 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-03-08 20:30 - 2016-02-23 14:39 - 00607416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-08 20:30 - 2016-02-23 14:30 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-08 20:30 - 2016-02-23 14:25 - 01085632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-03-08 20:30 - 2016-02-23 14:23 - 00952968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-08 20:30 - 2016-02-23 14:21 - 00529456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-08 20:30 - 2016-02-23 14:21 - 00141152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-08 20:30 - 2016-02-23 14:11 - 00249976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMASF.DLL
2016-03-08 20:30 - 2016-02-23 14:11 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-03-08 20:30 - 2016-02-23 14:11 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-03-08 20:30 - 2016-02-23 14:09 - 00229352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-08 20:30 - 2016-02-23 14:06 - 00069232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-03-08 20:30 - 2016-02-23 13:58 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-03-08 20:30 - 2016-02-23 13:50 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-03-08 20:30 - 2016-02-23 13:50 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-03-08 20:30 - 2016-02-23 13:42 - 00658536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-08 20:30 - 2016-02-23 13:42 - 00467296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-03-08 20:30 - 2016-02-23 13:42 - 00078176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-03-08 20:30 - 2016-02-23 13:39 - 02879024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-03-08 20:30 - 2016-02-23 13:38 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-03-08 20:30 - 2016-02-23 13:35 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-08 20:30 - 2016-02-23 13:20 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-03-08 20:30 - 2016-02-23 13:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-03-08 20:30 - 2016-02-23 13:16 - 02237952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-08 20:30 - 2016-02-23 13:15 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-08 20:30 - 2016-02-23 13:15 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-03-08 20:30 - 2016-02-23 12:59 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2016-03-08 20:30 - 2016-02-23 12:59 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-08 20:30 - 2016-02-23 12:57 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-08 20:30 - 2016-02-23 12:55 - 24592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-08 20:30 - 2016-02-23 12:45 - 12504576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-03-08 20:30 - 2016-02-23 12:45 - 06788608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-08 20:30 - 2016-02-23 12:42 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-08 20:30 - 2016-02-23 12:42 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-08 20:30 - 2016-02-23 12:38 - 02663424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-08 20:30 - 2016-02-23 12:37 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
2016-03-08 20:30 - 2016-02-23 12:36 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-03-08 20:30 - 2016-02-23 12:25 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-08 20:30 - 2016-02-23 12:18 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-08 20:30 - 2016-02-23 12:17 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-03-08 20:30 - 2016-02-23 12:17 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-03-08 20:30 - 2016-02-23 12:14 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-03-08 20:30 - 2016-02-23 12:08 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-08 20:30 - 2016-02-23 12:04 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-08 20:30 - 2016-02-23 12:03 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-08 20:30 - 2016-02-23 12:03 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-08 20:30 - 2016-02-23 12:02 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-08 20:30 - 2016-02-23 11:55 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-08 20:30 - 2016-02-23 11:55 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-08 20:30 - 2016-02-23 11:51 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-08 20:30 - 2016-02-23 11:51 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-08 20:30 - 2016-02-23 11:48 - 21859840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-08 20:30 - 2016-02-23 11:48 - 05157376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-08 20:30 - 2016-02-23 11:46 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-08 20:30 - 2016-02-23 11:45 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-08 20:30 - 2016-02-23 11:45 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-03-08 20:30 - 2016-02-23 11:45 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-08 20:30 - 2016-02-23 11:45 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-08 20:30 - 2016-02-23 11:44 - 01821696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-03-08 20:30 - 2016-02-23 11:38 - 07524864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-08 20:30 - 2016-02-23 11:29 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-03-08 20:30 - 2016-02-23 11:17 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-08 20:30 - 2016-02-23 11:17 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-08 20:30 - 2016-02-23 11:11 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-08 20:30 - 2016-02-23 11:03 - 01495040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-08 20:30 - 2016-02-23 11:00 - 11263488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-03-08 20:30 - 2016-02-23 11:00 - 05457408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-08 20:30 - 2016-02-23 10:58 - 18800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-05 23:51 - 2016-03-05 23:51 - 00000000 ____D C:\Users\Martin\AppData\Local\Macromedia
2016-03-05 23:48 - 2016-03-06 00:13 - 00000000 ____D C:\Users\Martin\AppData\Local\Opera Software
2016-03-05 23:48 - 2016-03-05 23:48 - 00001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-03-05 23:48 - 2016-03-05 23:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-03-05 23:47 - 2016-03-24 22:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-03-05 12:49 - 2016-03-05 12:49 - 00001214 _____ C:\Users\Public\Desktop\Czech Soccer Manager.lnk
2016-03-05 12:49 - 2016-03-05 12:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Czech Soccer Manager
2016-03-05 12:48 - 2016-03-05 12:53 - 00000000 ____D C:\Program Files (x86)\Czech Soccer Manager
2016-02-28 13:16 - 2016-03-14 11:51 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-02-28 13:04 - 2016-02-17 07:40 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-02-28 13:03 - 2016-03-13 20:22 - 00000000 ____D C:\ProgramData\Package Cache
2016-02-28 13:01 - 2016-02-28 13:01 - 00000000 ____D C:\Users\Martin\AppData\Local\Intel
2016-02-28 13:00 - 2015-12-18 07:10 - 00099472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2016-02-28 13:00 - 2015-12-18 07:10 - 00090768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2016-02-27 21:06 - 2016-03-14 12:12 - 00290224 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2016-02-27 21:06 - 2013-07-02 04:51 - 00342528 _____ (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\IntcDAud.sys
2016-02-27 21:06 - 2013-07-02 04:51 - 00116224 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v3223.dll
2016-02-27 21:06 - 2013-07-02 04:51 - 00016896 _____ (Intel(R) Corporation) C:\WINDOWS\system32\IntcDAuC.dll
2016-02-27 21:04 - 2016-02-27 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LenovoSHAREit
2016-02-27 20:56 - 2016-02-27 20:56 - 00000000 ____D C:\Users\Martin\Downloads\SHAREit
2016-02-27 20:56 - 2016-02-27 20:56 - 00000000 ____D C:\Users\Martin\AppData\Local\SHAREit
2016-02-27 20:56 - 2016-02-27 20:56 - 00000000 ____D C:\SWTOOLS
2016-02-24 20:31 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2016-02-24 20:31 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2016-02-24 20:31 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2016-02-24 20:31 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2016-02-24 20:28 - 2016-02-24 20:28 - 00001755 _____ C:\Users\Public\Desktop\Star Wars - Knights of the Old Republic II.lnk
2016-02-24 20:28 - 2016-02-24 20:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Star Wars - Knights of the Old Republic II [GOG.com]
2016-02-24 12:03 - 2016-02-24 12:03 - 00000000 ____D C:\Users\Martin\AppData\Local\Adobe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-25 10:37 - 2015-06-21 14:59 - 00000000 ____D C:\FRST
2016-03-25 10:35 - 2013-09-04 18:12 - 00000000 ____D C:\Users\Martin\Aktuální
2016-03-25 10:34 - 2015-11-08 09:59 - 00000000 ____D C:\ProgramData\Boxtools
2016-03-25 10:07 - 2015-10-11 16:03 - 02030468 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-25 10:07 - 2015-09-10 06:05 - 00840160 _____ C:\WINDOWS\system32\perfh005.dat
2016-03-25 10:07 - 2015-09-10 06:05 - 00191452 _____ C:\WINDOWS\system32\perfc005.dat
2016-03-25 10:07 - 2015-07-30 23:40 - 00000000 ____D C:\WINDOWS\INF
2016-03-25 10:06 - 2015-11-11 21:54 - 00004202 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6C0AB335-8108-4982-8C6A-7CDF340D5E7B}
2016-03-25 10:04 - 2015-10-11 16:32 - 00000000 ___RD C:\Users\Martin\OneDrive
2016-03-25 10:04 - 2013-09-29 15:56 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-03-24 23:31 - 2015-10-11 16:04 - 00000000 ____D C:\Users\Martin
2016-03-24 23:31 - 2015-07-30 22:52 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-24 23:31 - 2015-07-30 22:49 - 00343440 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-24 23:30 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-03-24 23:28 - 2016-02-17 19:18 - 00000000 ____D C:\Users\Martin\AppData\Local\CrashDumps
2016-03-24 23:28 - 2015-10-27 20:05 - 00000000 ____D C:\WINDOWS\Minidump
2016-03-24 23:28 - 2013-12-23 13:09 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Media Player Classic
2016-03-24 22:55 - 2015-02-22 20:15 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-03-24 22:53 - 2015-02-22 20:15 - 00001175 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-24 22:53 - 2015-02-22 20:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-24 22:53 - 2015-02-22 20:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-24 22:53 - 2013-09-04 19:17 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Skype
2016-03-24 22:51 - 2014-03-02 17:25 - 00000000 ____D C:\Users\Martin\AppData\Local\Skype
2016-03-24 22:51 - 2013-09-04 19:17 - 00000000 ____D C:\ProgramData\Skype
2016-03-24 22:48 - 2015-09-09 18:41 - 00001143 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 22:35 - 2009-07-14 04:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2016-03-24 22:08 - 2013-09-13 17:10 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2016-03-24 22:07 - 2013-09-07 12:58 - 00000000 ____D C:\Users\Martin\AppData\Local\Rockstar Games
2016-03-24 22:05 - 2013-09-07 17:27 - 00000000 ____D C:\Users\Martin\Documents\Rockstar Games
2016-03-24 21:59 - 2013-09-13 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2016-03-24 20:20 - 2015-09-09 18:41 - 00000000 ____D C:\Users\Martin\AppData\Roaming\vlc
2016-03-24 19:16 - 2013-09-04 17:14 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-03-24 18:42 - 2015-07-30 23:42 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-24 18:42 - 2015-07-30 23:42 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-23 21:14 - 2013-09-07 09:56 - 00000000 ___RD C:\Users\Martin\Fotky
2016-03-15 17:46 - 2013-11-01 20:15 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-15 17:46 - 2013-11-01 20:15 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-14 12:12 - 2015-06-01 20:01 - 13059896 _____ (Intel Corporation) C:\WINDOWS\system32\igd10umd64.dll
2016-03-14 12:12 - 2015-06-01 20:00 - 05384176 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2016-03-14 12:12 - 2015-06-01 20:00 - 00453552 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
2016-03-14 12:12 - 2015-06-01 20:00 - 00446976 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcsy.lrc
2016-03-14 12:12 - 2015-06-01 20:00 - 00411056 _____ (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
2016-03-14 12:12 - 2015-06-01 20:00 - 00119296 _____ (Intel Corporation) C:\WINDOWS\system32\hccutils.dll
2016-03-14 12:12 - 2015-06-01 20:00 - 00102912 _____ C:\WINDOWS\system32\IccLibDll_x64.dll
2016-03-14 12:12 - 2015-06-01 20:00 - 00072704 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.dll
2016-03-13 20:25 - 2015-10-23 15:44 - 00000000 ____D C:\temp
2016-03-13 20:25 - 2015-10-11 16:00 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-13 19:25 - 2015-10-11 15:59 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-13 19:20 - 2015-10-11 15:59 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-13 18:46 - 2013-10-29 18:07 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA
2016-03-12 19:50 - 2015-10-14 15:54 - 00000000 ____D C:\Users\Martin\AppData\Roaming\dvdcss
2016-03-11 12:16 - 2015-07-30 23:25 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-11 11:48 - 2015-09-24 17:14 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-11 11:26 - 2015-10-11 16:32 - 00002394 _____ C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-10 14:09 - 2015-02-22 20:15 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-03-10 14:08 - 2015-02-22 20:15 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-03-10 14:08 - 2015-02-22 20:15 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-03-10 09:15 - 2015-09-10 06:43 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-10 09:08 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-10 09:08 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-10 09:08 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-10 09:08 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-10 04:19 - 2015-07-23 03:02 - 12653504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-03-09 17:25 - 2013-09-04 17:58 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-09 17:18 - 2013-09-04 17:58 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-09 15:46 - 2013-09-29 15:56 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-03-09 15:46 - 2013-09-29 15:56 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2016-03-08 19:05 - 2015-11-30 17:37 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA Corporation
2016-03-08 11:27 - 2015-07-23 03:02 - 20061152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 14226864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 03681672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 03259176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00545632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00448824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00175552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00153208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00037702 _____ C:\WINDOWS\system32\nvinfo.pb
2016-03-08 11:27 - 2013-09-10 18:53 - 00213952 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2016-03-08 11:27 - 2013-09-10 18:53 - 00203320 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2016-03-08 08:10 - 2015-07-30 23:43 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-08 08:10 - 2015-07-30 23:43 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-08 07:42 - 2015-10-11 16:00 - 06371384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 02992576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 02563128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 01264064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-03-08 07:42 - 2015-10-11 16:00 - 00530880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 00122304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-03-07 15:03 - 2013-09-07 10:08 - 00000000 ____D C:\Users\Martin\Hanka
2016-03-07 05:22 - 2015-10-11 16:00 - 06203411 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-03-06 11:41 - 2013-09-04 17:57 - 00000000 ____D C:\Users\Martin\AppData\Local\Last.fm
2016-03-06 00:13 - 2015-08-17 07:38 - 00000000 ____D C:\Program Files (x86)\Opera
2016-03-06 00:13 - 2014-11-11 21:28 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Opera Software
2016-02-28 13:16 - 2013-09-04 07:47 - 00000000 ____D C:\Program Files (x86)\Intel
2016-02-28 13:05 - 2015-10-11 15:59 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-02-28 13:03 - 2013-09-04 07:47 - 00000000 ____D C:\ProgramData\Intel
2016-02-27 20:57 - 2015-12-30 18:54 - 00000000 ____D C:\ProgramData\Lenovo
2016-02-27 20:56 - 2015-09-14 16:54 - 00000000 ____D C:\Program Files (x86)\Lenovo
2016-02-24 20:23 - 2016-01-10 19:03 - 00000000 ____D C:\GOG Games

==================== Files in the root of some directories =======

2013-09-14 13:13 - 2014-06-02 17:57 - 0000000 _____ () C:\Users\Martin\AppData\Roaming\bitlord_log.txt
2015-11-08 09:59 - 2015-12-28 09:33 - 0000040 _____ () C:\Users\Martin\AppData\Roaming\cdr.ini
2016-03-24 22:38 - 2016-03-24 22:38 - 0005120 _____ () C:\Users\Martin\AppData\Roaming\GiftBag.db
2016-03-25 10:34 - 2016-03-25 10:34 - 0029696 _____ () C:\Users\Martin\AppData\Local\MSGBOX.EXE
2014-06-03 03:24 - 2014-06-03 03:24 - 0000218 _____ () C:\Users\Martin\AppData\Local\recently-used.xbel
2014-03-02 20:08 - 2014-03-02 20:08 - 0007607 _____ () C:\Users\Martin\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-03-25 10:20

==================== End of FRST.txt ============================
Přílohy
Addition.rar
(12.35 KiB) Staženo 88 x

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Číňani na koni

#2 Příspěvek od motji »

Zdravím :)
Předpokládám, že antivirový program Tencent jste si nenainstaloval dobrovolně? Tak ho vykopeme, uvidíme, jak moc se bude bránit:D.
Zkusíme to nejdřív tou jednodušší cestou:
Najděte si přidat/odebrat programy a dejte odinstalovat program Tencent.

Následně otevřete blok a zkopírujte do něj:

Kód: Vybrat vše

C:\Program Files\Common Files\Tencent
2016-03-24 22:38 - 2016-03-24 22:36 - 00132344 _____ (Tencent Technology(Shenzhen) Company Limited) C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys
2016-03-24 22:37 - 2016-03-24 22:43 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
2016-03-24 22:37 - 2016-03-24 22:37 - 00000000 ____D C:\ProgramData\TXQMPC
2016-03-24 22:37 - 2016-03-24 22:36 - 00087800 _____ (电脑管家) C:\WINDOWS\system32\Drivers\TFsFltX64.sys
2016-03-24 22:36 - 2016-03-24 22:40 - 00000000 ____D C:\ProgramData\Tencent
2016-03-24 22:36 - 2016-03-24 22:38 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Tencent
2016-03-24 22:36 - 2016-03-24 22:36 - 00000000 ____D C:\Program Files (x86)\Tencent
2016-03-24 22:07 - 2016-03-24 22:07 - 00000080 _____ C:\Users\Martin\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
-uložte jako fixlist.txt vedle Frstu
-spusťte Frst a zmáčkněte tlačítko Fix. Následně se pc restartuje

Napište, jak to vypadá, pak budeme pokračovat dále:)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Noviik
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 28 říj 2013 15:53

Re: Číňani na koni

#3 Příspěvek od Noviik »

Jop, to vypadá na ty kluky čínský :-)

Proběhlo to, zdá se, v pohodě:


Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Martin (2016-03-25 11:09:25) Run:3
Running from C:\Users\Martin\Desktop
Loaded Profiles: Martin (Available Profiles: Martin & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
C:\Program Files\Common Files\Tencent
2016-03-24 22:38 - 2016-03-24 22:36 - 00132344 _____ (Tencent Technology(Shenzhen) Company Limited) C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys
2016-03-24 22:37 - 2016-03-24 22:43 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????
2016-03-24 22:37 - 2016-03-24 22:37 - 00000000 ____D C:\ProgramData\TXQMPC
2016-03-24 22:37 - 2016-03-24 22:36 - 00087800 _____ (????) C:\WINDOWS\system32\Drivers\TFsFltX64.sys
2016-03-24 22:36 - 2016-03-24 22:40 - 00000000 ____D C:\ProgramData\Tencent
2016-03-24 22:36 - 2016-03-24 22:38 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Tencent
2016-03-24 22:36 - 2016-03-24 22:36 - 00000000 ____D C:\Program Files (x86)\Tencent
2016-03-24 22:07 - 2016-03-24 22:07 - 00000080 _____ C:\Users\Martin\AppData\Local???????????????????
*****************

C:\Program Files\Common Files\Tencent => moved successfully
C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys => moved successfully

=========== "C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????" ==========

not found

========= End -> "C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\????" ========

C:\ProgramData\TXQMPC => moved successfully
C:\WINDOWS\system32\Drivers\TFsFltX64.sys => moved successfully
C:\ProgramData\Tencent => moved successfully
C:\Users\Martin\AppData\Roaming\Tencent => moved successfully
C:\Program Files (x86)\Tencent => moved successfully

=========== "C:\Users\Martin\AppData\Local???????????????????" ==========

C:\Users\Martin\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦 => moved successfully

========= End -> "C:\Users\Martin\AppData\Local???????????????????" ========


==== End of Fixlog 11:09:26 ====

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Číňani na koni

#4 Příspěvek od motji »

Jen na info, kde jste k tomu přišel? :)
A šel ten číňan odinstalovat?

:arrow: Stáhněte AdwCleaner http://www.bleepingcomputer.com/download/adwcleaner/
-Uložte program na plochu a ukončete všechny spuštěné programy .
-spusťte AdwCleaner, klikněte na Scan a po dokončení skenu na Clean
- provede se oprava, restartuje se pc - (případně restartujte) a objeví se log C:\AdwCleaner\AdwCleaner.txt , obsah logu zkopírujte zde.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Noviik
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 28 říj 2013 15:53

Re: Číňani na koni

#5 Příspěvek od Noviik »

Byl jsem ukázkový de*il a hledal jsem keygen ke hře :frusty:

Odinstaloval šel :-)


# AdwCleaner v5.033 - Logfile created 15/02/2016 at 17:38:54
# Updated 07/02/2016 by Xplode
# Database : 2016-02-07.2 [Server]
# Operating system : Windows 10 Home (x64)
# Username : Martin - MARTIN-PC
# Running from : C:\Users\Martin\Aktuální\adwcleaner_5.033.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\9abf116bbbdccfd3d5fc7583e27a8fd8
[-] Key Deleted : HKCU\Software\Conduit

***** [ Web browsers ] *****


*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [772 bytes] ##########
# AdwCleaner v5.105 - Logfile created 25/03/2016 at 11:42:03
# Updated 21/03/2016 by Xplode
# Database : 2016-03-24.4 [Server]
# Operating system : Windows 10 Home (x64)
# Username : Martin - MARTIN-PC
# Running from : C:\Users\Martin\Desktop\AdwCleaner.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : QMUdisk
[-] Service Deleted : softaal

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Common Files\tencent
[-] Folder Deleted : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm
[-] Folder Deleted : C:\Users\Martin\AppData\Local\Temp\tencent
[-] Folder Deleted : C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
[-] Folder Deleted : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\tencent

***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
[-] Key Deleted : HKLM\SOFTWARE\Classes\metnsd
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{357D32FC-F0AE-4B37-B36F-D44AA31496F5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80B3B43F-7508-4627-BE66-00FB9AE5EE72}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{5A83D7C9-4A14-4000-BC05-389268238753}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{29B6CFD5-0064-411A-8C42-9890C83F9921}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{357D32FC-F0AE-4B37-B36F-D44AA31496F5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{80B3B43F-7508-4627-BE66-00FB9AE5EE72}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\IM
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{1883B886-924D-4D96-92B0-22EB940C7C08}]
[-] Value Deleted : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules [{8147FC17-AD3C-47DA-8D56-D8108A55E624}]
[-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\2345.com
[-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.2345.com
[-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\2345.com
[-] Key Deleted : HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.2345.com

***** [ Web browsers ] *****

[-] [C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : ooebklgpfnbcnpokahmdidgbmlcdepkm

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [4619 bytes] - [15/02/2016 17:38:54]
C:\AdwCleaner\AdwCleaner[C2].txt - [841 bytes] - [06/09/2015 18:58:59]
C:\AdwCleaner\AdwCleaner[C3].txt - [708 bytes] - [06/09/2015 19:16:40]
C:\AdwCleaner\AdwCleaner[R0].txt - [1055 bytes] - [21/06/2015 18:46:59]
C:\AdwCleaner\AdwCleaner[S0].txt - [1068 bytes] - [21/06/2015 19:12:11]
C:\AdwCleaner\AdwCleaner[S1].txt - [5217 bytes] - [15/02/2016 17:33:41]
C:\AdwCleaner\AdwCleaner[S2].txt - [755 bytes] - [06/09/2015 18:56:01]
C:\AdwCleaner\AdwCleaner[S3].txt - [755 bytes] - [06/09/2015 18:58:08]
C:\AdwCleaner\AdwCleaner[S4].txt - [644 bytes] - [06/09/2015 19:05:05]
C:\AdwCleaner\AdwCleaner[S5].txt - [644 bytes] - [06/09/2015 19:15:56]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [5343 bytes] ##########

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Číňani na koni

#6 Příspěvek od motji »

Poprosím o nový log z Frstu. Co čínani, stále se vyskytují?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Noviik
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 28 říj 2013 15:53

Re: Číňani na koni

#7 Příspěvek od Noviik »

Objevil jsem je MI Edge (v příloze jejich domovská stránka, takové obrázkové centrum :-)).

Jinak to vypadá, že jinde se neusadili, ale to mluvím jen o svém mizerném oku.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Martin (administrator) on MARTIN-PC (25-03-2016 12:14:34)
Running from C:\Users\Martin\Desktop
Loaded Profiles: Martin (Available Profiles: Martin & DefaultAppPool)
Platform: Windows 10 Home (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\asww10mon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Lenovo) C:\Users\Martin\AppData\Local\Apps\2.0\G8O0KMPB.CW0\T344K5RY.9OW\lsb...tion_91a10ba61c75c82d_0001.0006_014be6b8b4b27d94\LSB.exe
(Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(NTeWORKS) C:\Program Files (x86)\PicPick\picpick.exe
() C:\ProgramData\Boxtools\Toolbox.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Last.fm) C:\Program Files (x86)\Last.fm\Last.fm Scrobbler.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtsFT] => RTFTrack.exe
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3944136 2015-06-03] (Synaptics Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-23] (AVAST Software)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [571928 2015-12-30] (Vimicro)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\...\Run: [PicPick Start] => C:\Program Files (x86)\PicPick\picpick.exe [13229912 2014-01-15] (NTeWORKS)
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\...\Run: [Boxoft Tools] => C:\ProgramData\Boxtools\Boxofttoolbox.exe [514048 2010-12-15] ()
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4179288 2015-11-30] (Disc Soft Ltd)
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [583680 2015-07-10] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [175552 2016-03-08] (NVIDIA Corporation)
AppInit_DLLs: , C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [175552 2016-03-08] (NVIDIA Corporation)
AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [175552 2016-03-08] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [153208 2016-03-08] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-02-12] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{01021f86-2d02-446c-ae13-41e776d12267}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{5101965d-5da9-4c8f-8ef6-aeec3376cb71}: [DhcpNameServer] 10.0.0.138
ManualProxies:

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3754952095-1263816399-3501759939-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-3754952095-1263816399-3501759939-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-02-12] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2015-09-22] (Eyeo GmbH)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-09-06] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-02-12] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-06] (Oracle Corporation)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-09-22] (Eyeo GmbH)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-3754952095-1263816399-3501759939-1000 -> hxxp://google.cz/

FireFox:
========
FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1f7jxlmq.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-24] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-24] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-06] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3754952095-1263816399-3501759939-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Martin\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin HKU\S-1-5-21-3754952095-1263816399-3501759939-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Martin\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Extension: Adblock Plus - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1f7jxlmq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-03-05]
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-24] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-02-13]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-02-13]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/
CHR Profile: C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-17]
CHR Extension: (Dokumenty Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-17]
CHR Extension: (Disk Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-17]
CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-17]
CHR Extension: (Vyhledávání Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-17]
CHR Extension: (Kalendář Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2016-02-17]
CHR Extension: (Tabulky Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-17]
CHR Extension: (Dokumenty Google offline) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-18]
CHR Extension: (Avast Online Security) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-17]
CHR Extension: (Last.fm scrobbler for Google Play) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhlmaloocaogaldcbpimhlbimmhaonep [2016-02-17]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-17]
CHR Extension: (电脑管家上网防护) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm [2016-03-25]
CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-17]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-02-12]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-11-03] (SUPERAntiSpyware.com)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-02-12] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [119128 2016-02-12] (AVAST Software)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1368408 2015-11-30] (Disc Soft Ltd)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [625632 2015-07-22] (Lenovo)
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [271296 2015-08-17] (Lenovo)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation)
S2 SetupARService; C:\Program Files (x86)\Realtek\Audio\SetupAfterRebootService.exe [10752 2015-11-30] () [File not signed]
S3 ShareItSvc; C:\Program Files (x86)\Lenovo\SHAREit\Shareit.Service.exe [31192 2016-02-02] (SHAREit Technologies Co.Ltd)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [249032 2015-06-03] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5429520 2015-01-30] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-02-12] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-02-12] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-09] (AVAST Software)
R1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [552880 2016-02-23] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-02-12] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-02-12] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-09] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-02-23] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-02-12] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-02-12] (AVAST Software)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-01-10] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [46392 2016-01-10] (Disc Soft Ltd)
S3 ldiagio_uefi; C:\Program Files\Lenovo\Lenovo Solution Center\App\ldiag\x64\ldiagio_uefi.sys [24808 2015-04-01] (Lenovo Group Limited (R))
R3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3354384 2015-06-18] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-06-18] (Realtek )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-06-03] (Synaptics Incorporated)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2015-11-02] (DEVGURU Co., LTD.(www.devguru.co.kr))
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [648872 2015-12-30] (Vimicro Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 IntcAzAudAddService; \SystemRoot\system32\drivers\RTKVHD64.sys [X]
S2 tsnethlpx64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\TsNetHlpX64.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-25 11:53 - 2016-03-25 11:53 - 00016148 _____ C:\WINDOWS\system32\MARTIN-PC_Martin_HistoryPrediction.bin
2016-03-25 11:26 - 2016-03-25 11:35 - 01530368 _____ C:\Users\Martin\Desktop\AdwCleaner.exe
2016-03-25 11:09 - 2016-03-25 11:09 - 00002136 _____ C:\Users\Martin\Desktop\Fixlog.txt
2016-03-25 10:41 - 2016-03-25 10:41 - 00012650 _____ C:\Users\Martin\Desktop\Addition.rar
2016-03-25 10:39 - 2016-03-25 10:40 - 00043137 _____ C:\Users\Martin\Desktop\Addition.txt
2016-03-25 10:37 - 2016-03-25 12:14 - 00020141 _____ C:\Users\Martin\Desktop\FRST.txt
2016-03-25 10:34 - 2016-03-25 10:34 - 00029696 _____ C:\Users\Martin\AppData\Local\MSGBOX.EXE
2016-03-25 10:34 - 2016-03-25 10:34 - 00015327 _____ C:\Users\Martin\Desktop\LM.bat
2016-03-25 10:28 - 2016-03-25 10:35 - 02374144 _____ (Farbar) C:\Users\Martin\Desktop\FRST64.exe
2016-03-25 10:04 - 2016-03-25 10:04 - 00000000 ___HD C:\OneDriveTemp
2016-03-24 23:31 - 2016-03-24 23:31 - 00000270 __RSH C:\Users\Martin\ntuser.pol
2016-03-24 22:51 - 2016-03-24 22:51 - 00002658 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-24 22:51 - 2016-03-24 22:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-24 22:51 - 2016-03-24 22:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-03-24 22:46 - 2016-03-24 23:31 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-03-24 22:38 - 2016-03-24 22:38 - 00005120 _____ C:\Users\Martin\AppData\Roaming\GiftBag.db
2016-03-24 22:35 - 2016-03-24 22:35 - 00000270 __RSH C:\ProgramData\ntuser.pol
2016-03-24 21:59 - 2016-03-24 21:59 - 00002016 _____ C:\Users\Public\Desktop\Grand Theft Auto V.lnk
2016-03-24 19:16 - 2016-03-24 22:08 - 00000000 ____D C:\Program Files\Rockstar Games
2016-03-18 10:28 - 2016-03-18 10:28 - 00003040 _____ C:\WINDOWS\System32\Tasks\avast! Windows 10 Start Menu helper
2016-03-17 08:53 - 2016-03-17 08:58 - 00000000 ____D C:\Users\Martin\Documents\BotaniculaSaves
2016-03-14 12:14 - 2016-03-14 12:14 - 00000000 ____D C:\WINDOWS\LastGood
2016-03-14 12:12 - 2016-03-14 12:12 - 13037568 _____ (Intel Corporation) C:\WINDOWS\system32\ig4icd64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 12814752 _____ (Intel Corporation) C:\WINDOWS\system32\igdumd64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 11352688 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10umd32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 11223896 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumd32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 10820096 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig4icd32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 09016320 _____ (Intel Corporation) C:\WINDOWS\system32\igfxress.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 05916080 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUI.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 03520000 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 03129856 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 01067696 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00957472 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00584192 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00551424 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00544552 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00539312 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00523184 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 00451584 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdev.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00449024 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrell.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00448512 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfra.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00448512 _____ (Intel Corporation) C:\WINDOWS\system32\igfxresn.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00448000 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrus.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00448000 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrom.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsky.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptg.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrplk.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnld.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrita.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhrv.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00447488 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdeu.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446976 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhun.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446976 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfin.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtrk.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsve.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrslv.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptb.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00446464 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnor.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00445952 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtha.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00445952 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdan.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00444416 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrheb.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00444416 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrara.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00440832 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrjpn.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00439808 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrkor.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00437760 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcht.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00437248 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrchs.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00418816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxTMM.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00393216 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpph.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00339456 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxdv32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00294912 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrenu.lrc
2016-03-14 12:12 - 2016-03-14 12:12 - 00266152 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 00231312 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00197040 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 00194880 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00183808 _____ (Intel Corporation) C:\WINDOWS\system32\gfxSrvc.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00183216 _____ (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
2016-03-14 12:12 - 2016-03-14 12:12 - 00151040 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdo.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00135680 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcpl.cpl
2016-03-14 12:12 - 2016-03-14 12:12 - 00110080 _____ C:\WINDOWS\system32\igdde64.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00090112 _____ C:\WINDOWS\SysWOW64\igdde32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00041288 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00033792 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00018432 _____ ( ) C:\WINDOWS\system32\IGFXDEVLib.dll
2016-03-14 12:12 - 2016-03-14 12:12 - 00017082 _____ C:\WINDOWS\system32\iglhxs64.vp
2016-03-13 20:25 - 2016-03-24 23:35 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2016-03-13 20:25 - 2016-03-24 23:35 - 00000000 ____D C:\WINDOWS\system32\NV
2016-03-13 19:20 - 2016-03-24 23:30 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-03-13 19:18 - 2016-03-10 03:58 - 00048704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2016-03-13 19:18 - 2016-03-08 11:27 - 42968120 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 37609528 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 22971960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 21322480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 20863920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 18906048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 17732960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 17368424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 17325400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 17320280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 10547128 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 08657936 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 02613696 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 02257344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 01922496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00955328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00885184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00786872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00750016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00692160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00678704 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00632152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00571912 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00423360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00379296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00377792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00317656 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00151184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00128696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-03-13 19:18 - 2016-03-08 11:27 - 00000139 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-03-13 19:18 - 2016-03-08 11:27 - 00000139 _____ C:\WINDOWS\system32\nv-vk64.json
2016-03-08 20:30 - 2016-02-23 15:53 - 01314496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-08 20:30 - 2016-02-23 15:52 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-03-08 20:30 - 2016-02-23 15:51 - 00633184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-03-08 20:30 - 2016-02-23 15:51 - 00146784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-08 20:30 - 2016-02-23 15:50 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-08 20:30 - 2016-02-23 15:48 - 08022368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-08 20:30 - 2016-02-23 15:48 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-03-08 20:30 - 2016-02-23 15:48 - 01123952 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-03-08 20:30 - 2016-02-23 15:41 - 01150816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-08 20:30 - 2016-02-23 15:41 - 00299600 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMASF.DLL
2016-03-08 20:30 - 2016-02-23 15:41 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-03-08 20:30 - 2016-02-23 15:40 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-03-08 20:30 - 2016-02-23 15:38 - 00272752 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-08 20:30 - 2016-02-23 15:36 - 00080128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-03-08 20:30 - 2016-02-23 15:11 - 00781984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-08 20:30 - 2016-02-23 15:11 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-08 20:30 - 2016-02-23 15:11 - 00103776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-03-08 20:30 - 2016-02-23 15:08 - 03622272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-03-08 20:30 - 2016-02-23 15:07 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-03-08 20:30 - 2016-02-23 14:39 - 00607416 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-08 20:30 - 2016-02-23 14:30 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-08 20:30 - 2016-02-23 14:25 - 01085632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-03-08 20:30 - 2016-02-23 14:23 - 00952968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-08 20:30 - 2016-02-23 14:21 - 00529456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-08 20:30 - 2016-02-23 14:21 - 00141152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-08 20:30 - 2016-02-23 14:11 - 00249976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMASF.DLL
2016-03-08 20:30 - 2016-02-23 14:11 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-03-08 20:30 - 2016-02-23 14:11 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-03-08 20:30 - 2016-02-23 14:09 - 00229352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-08 20:30 - 2016-02-23 14:06 - 00069232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-03-08 20:30 - 2016-02-23 13:58 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-03-08 20:30 - 2016-02-23 13:50 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-03-08 20:30 - 2016-02-23 13:50 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-03-08 20:30 - 2016-02-23 13:42 - 00658536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-08 20:30 - 2016-02-23 13:42 - 00467296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-03-08 20:30 - 2016-02-23 13:42 - 00078176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-03-08 20:30 - 2016-02-23 13:39 - 02879024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-03-08 20:30 - 2016-02-23 13:38 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-03-08 20:30 - 2016-02-23 13:35 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-08 20:30 - 2016-02-23 13:20 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-03-08 20:30 - 2016-02-23 13:17 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-03-08 20:30 - 2016-02-23 13:16 - 02237952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-08 20:30 - 2016-02-23 13:15 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-08 20:30 - 2016-02-23 13:15 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-03-08 20:30 - 2016-02-23 12:59 - 00319488 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2016-03-08 20:30 - 2016-02-23 12:59 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-08 20:30 - 2016-02-23 12:57 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-08 20:30 - 2016-02-23 12:55 - 24592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-08 20:30 - 2016-02-23 12:45 - 12504576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-03-08 20:30 - 2016-02-23 12:45 - 06788608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-08 20:30 - 2016-02-23 12:42 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-08 20:30 - 2016-02-23 12:42 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-08 20:30 - 2016-02-23 12:38 - 02663424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-08 20:30 - 2016-02-23 12:37 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
2016-03-08 20:30 - 2016-02-23 12:36 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-03-08 20:30 - 2016-02-23 12:25 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-08 20:30 - 2016-02-23 12:18 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-08 20:30 - 2016-02-23 12:17 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-03-08 20:30 - 2016-02-23 12:17 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-03-08 20:30 - 2016-02-23 12:14 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-03-08 20:30 - 2016-02-23 12:08 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-08 20:30 - 2016-02-23 12:04 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-08 20:30 - 2016-02-23 12:03 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-08 20:30 - 2016-02-23 12:03 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-08 20:30 - 2016-02-23 12:02 - 03587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-08 20:30 - 2016-02-23 11:55 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-08 20:30 - 2016-02-23 11:55 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-08 20:30 - 2016-02-23 11:51 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-08 20:30 - 2016-02-23 11:51 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-08 20:30 - 2016-02-23 11:48 - 21859840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-08 20:30 - 2016-02-23 11:48 - 05157376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-08 20:30 - 2016-02-23 11:46 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-08 20:30 - 2016-02-23 11:45 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-08 20:30 - 2016-02-23 11:45 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2016-03-08 20:30 - 2016-02-23 11:45 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-08 20:30 - 2016-02-23 11:45 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-08 20:30 - 2016-02-23 11:44 - 01821696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-03-08 20:30 - 2016-02-23 11:38 - 07524864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-08 20:30 - 2016-02-23 11:29 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-03-08 20:30 - 2016-02-23 11:17 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-08 20:30 - 2016-02-23 11:17 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-08 20:30 - 2016-02-23 11:11 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-08 20:30 - 2016-02-23 11:03 - 01495040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-08 20:30 - 2016-02-23 11:00 - 11263488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-03-08 20:30 - 2016-02-23 11:00 - 05457408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-08 20:30 - 2016-02-23 10:58 - 18800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-05 23:51 - 2016-03-05 23:51 - 00000000 ____D C:\Users\Martin\AppData\Local\Macromedia
2016-03-05 23:48 - 2016-03-06 00:13 - 00000000 ____D C:\Users\Martin\AppData\Local\Opera Software
2016-03-05 23:48 - 2016-03-05 23:48 - 00001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-03-05 23:48 - 2016-03-05 23:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-03-05 23:47 - 2016-03-24 22:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-03-05 12:49 - 2016-03-05 12:49 - 00001214 _____ C:\Users\Public\Desktop\Czech Soccer Manager.lnk
2016-03-05 12:49 - 2016-03-05 12:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Czech Soccer Manager
2016-03-05 12:48 - 2016-03-05 12:53 - 00000000 ____D C:\Program Files (x86)\Czech Soccer Manager
2016-02-28 13:16 - 2016-03-14 11:51 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2016-02-28 13:04 - 2016-02-17 07:40 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-02-28 13:03 - 2016-03-13 20:22 - 00000000 ____D C:\ProgramData\Package Cache
2016-02-28 13:01 - 2016-02-28 13:01 - 00000000 ____D C:\Users\Martin\AppData\Local\Intel
2016-02-28 13:00 - 2015-12-18 07:10 - 00099472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2016-02-28 13:00 - 2015-12-18 07:10 - 00090768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2016-02-27 21:06 - 2016-03-14 12:12 - 00290224 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2016-02-27 21:06 - 2013-07-02 04:51 - 00342528 _____ (Intel(R) Corporation) C:\WINDOWS\system32\Drivers\IntcDAud.sys
2016-02-27 21:06 - 2013-07-02 04:51 - 00116224 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v3223.dll
2016-02-27 21:06 - 2013-07-02 04:51 - 00016896 _____ (Intel(R) Corporation) C:\WINDOWS\system32\IntcDAuC.dll
2016-02-27 21:04 - 2016-02-27 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LenovoSHAREit
2016-02-27 20:56 - 2016-02-27 20:56 - 00000000 ____D C:\Users\Martin\Downloads\SHAREit
2016-02-27 20:56 - 2016-02-27 20:56 - 00000000 ____D C:\Users\Martin\AppData\Local\SHAREit
2016-02-27 20:56 - 2016-02-27 20:56 - 00000000 ____D C:\SWTOOLS
2016-02-24 20:31 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2016-02-24 20:31 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2016-02-24 20:31 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2016-02-24 20:31 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2016-02-24 20:31 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2016-02-24 20:31 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2016-02-24 20:31 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2016-02-24 20:31 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2016-02-24 20:28 - 2016-02-24 20:28 - 00001755 _____ C:\Users\Public\Desktop\Star Wars - Knights of the Old Republic II.lnk
2016-02-24 20:28 - 2016-02-24 20:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Star Wars - Knights of the Old Republic II [GOG.com]
2016-02-24 12:03 - 2016-02-24 12:03 - 00000000 ____D C:\Users\Martin\AppData\Local\Adobe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-25 12:14 - 2015-06-21 14:59 - 00000000 ____D C:\FRST
2016-03-25 11:58 - 2015-10-11 16:03 - 02030468 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-25 11:58 - 2015-09-10 06:05 - 00840160 _____ C:\WINDOWS\system32\perfh005.dat
2016-03-25 11:58 - 2015-09-10 06:05 - 00191452 _____ C:\WINDOWS\system32\perfc005.dat
2016-03-25 11:58 - 2015-07-30 23:40 - 00000000 ____D C:\WINDOWS\INF
2016-03-25 11:54 - 2015-11-08 09:59 - 00000000 ____D C:\ProgramData\Boxtools
2016-03-25 11:54 - 2015-10-11 16:32 - 00000000 ___RD C:\Users\Martin\OneDrive
2016-03-25 11:52 - 2015-07-30 22:52 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-03-25 11:51 - 2015-07-10 10:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-03-25 11:36 - 2015-06-21 18:46 - 00000000 ____D C:\AdwCleaner
2016-03-25 11:35 - 2013-09-04 18:12 - 00000000 ____D C:\Users\Martin\Aktuální
2016-03-25 10:06 - 2015-11-11 21:54 - 00004202 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6C0AB335-8108-4982-8C6A-7CDF340D5E7B}
2016-03-25 10:04 - 2013-09-29 15:56 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-03-24 23:31 - 2015-10-11 16:04 - 00000000 ____D C:\Users\Martin
2016-03-24 23:31 - 2015-07-30 22:49 - 00343440 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-03-24 23:28 - 2016-02-17 19:18 - 00000000 ____D C:\Users\Martin\AppData\Local\CrashDumps
2016-03-24 23:28 - 2015-10-27 20:05 - 00000000 ____D C:\WINDOWS\Minidump
2016-03-24 23:28 - 2013-12-23 13:09 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Media Player Classic
2016-03-24 22:55 - 2015-02-22 20:15 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-03-24 22:53 - 2015-02-22 20:15 - 00001175 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-24 22:53 - 2015-02-22 20:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-24 22:53 - 2015-02-22 20:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-24 22:53 - 2013-09-04 19:17 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Skype
2016-03-24 22:51 - 2014-03-02 17:25 - 00000000 ____D C:\Users\Martin\AppData\Local\Skype
2016-03-24 22:51 - 2013-09-04 19:17 - 00000000 ____D C:\ProgramData\Skype
2016-03-24 22:48 - 2015-09-09 18:41 - 00001143 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-24 22:35 - 2009-07-14 04:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2016-03-24 22:08 - 2013-09-13 17:10 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2016-03-24 22:07 - 2013-09-07 12:58 - 00000000 ____D C:\Users\Martin\AppData\Local\Rockstar Games
2016-03-24 22:05 - 2013-09-07 17:27 - 00000000 ____D C:\Users\Martin\Documents\Rockstar Games
2016-03-24 21:59 - 2013-09-13 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2016-03-24 20:20 - 2015-09-09 18:41 - 00000000 ____D C:\Users\Martin\AppData\Roaming\vlc
2016-03-24 19:16 - 2013-09-04 17:14 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-03-24 18:42 - 2015-07-30 23:42 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-24 18:42 - 2015-07-30 23:42 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-23 21:14 - 2013-09-07 09:56 - 00000000 ___RD C:\Users\Martin\Fotky
2016-03-15 17:46 - 2013-11-01 20:15 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-15 17:46 - 2013-11-01 20:15 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-14 12:12 - 2015-06-01 20:01 - 13059896 _____ (Intel Corporation) C:\WINDOWS\system32\igd10umd64.dll
2016-03-14 12:12 - 2015-06-01 20:00 - 05384176 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2016-03-14 12:12 - 2015-06-01 20:00 - 00453552 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
2016-03-14 12:12 - 2015-06-01 20:00 - 00446976 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcsy.lrc
2016-03-14 12:12 - 2015-06-01 20:00 - 00411056 _____ (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
2016-03-14 12:12 - 2015-06-01 20:00 - 00119296 _____ (Intel Corporation) C:\WINDOWS\system32\hccutils.dll
2016-03-14 12:12 - 2015-06-01 20:00 - 00102912 _____ C:\WINDOWS\system32\IccLibDll_x64.dll
2016-03-14 12:12 - 2015-06-01 20:00 - 00072704 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.dll
2016-03-13 20:25 - 2015-10-23 15:44 - 00000000 ____D C:\temp
2016-03-13 20:25 - 2015-10-11 16:00 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-13 19:25 - 2015-10-11 15:59 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-13 19:20 - 2015-10-11 15:59 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-13 18:46 - 2013-10-29 18:07 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA
2016-03-12 19:50 - 2015-10-14 15:54 - 00000000 ____D C:\Users\Martin\AppData\Roaming\dvdcss
2016-03-11 12:16 - 2015-07-30 23:25 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-11 11:48 - 2015-09-24 17:14 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-11 11:26 - 2015-10-11 16:32 - 00002394 _____ C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-10 14:09 - 2015-02-22 20:15 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-03-10 14:08 - 2015-02-22 20:15 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-03-10 14:08 - 2015-02-22 20:15 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-03-10 09:15 - 2015-09-10 06:43 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-10 09:08 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-10 09:08 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-10 09:08 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-10 09:08 - 2015-07-30 23:42 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-10 04:19 - 2015-07-23 03:02 - 12653504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-03-09 17:25 - 2013-09-04 17:58 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-09 17:18 - 2013-09-04 17:58 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-09 15:46 - 2013-09-29 15:56 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2016-03-09 15:46 - 2013-09-29 15:56 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswmonflt.sys
2016-03-08 19:05 - 2015-11-30 17:37 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA Corporation
2016-03-08 11:27 - 2015-07-23 03:02 - 20061152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 14226864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 03681672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 03259176 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00545632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00448824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00175552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00153208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-03-08 11:27 - 2015-07-23 03:02 - 00037702 _____ C:\WINDOWS\system32\nvinfo.pb
2016-03-08 11:27 - 2013-09-10 18:53 - 00213952 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2016-03-08 11:27 - 2013-09-10 18:53 - 00203320 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2016-03-08 08:10 - 2015-07-30 23:43 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-08 08:10 - 2015-07-30 23:43 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-08 07:42 - 2015-10-11 16:00 - 06371384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 02992576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 02563128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 01264064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-03-08 07:42 - 2015-10-11 16:00 - 00530880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 00122304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-08 07:42 - 2015-10-11 16:00 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-03-07 15:03 - 2013-09-07 10:08 - 00000000 ____D C:\Users\Martin\Hanka
2016-03-07 05:22 - 2015-10-11 16:00 - 06203411 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-03-06 11:41 - 2013-09-04 17:57 - 00000000 ____D C:\Users\Martin\AppData\Local\Last.fm
2016-03-06 00:13 - 2015-08-17 07:38 - 00000000 ____D C:\Program Files (x86)\Opera
2016-03-06 00:13 - 2014-11-11 21:28 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Opera Software
2016-02-28 13:16 - 2013-09-04 07:47 - 00000000 ____D C:\Program Files (x86)\Intel
2016-02-28 13:05 - 2015-10-11 15:59 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-02-28 13:03 - 2013-09-04 07:47 - 00000000 ____D C:\ProgramData\Intel
2016-02-27 20:57 - 2015-12-30 18:54 - 00000000 ____D C:\ProgramData\Lenovo
2016-02-27 20:56 - 2015-09-14 16:54 - 00000000 ____D C:\Program Files (x86)\Lenovo
2016-02-24 20:23 - 2016-01-10 19:03 - 00000000 ____D C:\GOG Games

==================== Files in the root of some directories =======

2013-09-14 13:13 - 2014-06-02 17:57 - 0000000 _____ () C:\Users\Martin\AppData\Roaming\bitlord_log.txt
2015-11-08 09:59 - 2015-12-28 09:33 - 0000040 _____ () C:\Users\Martin\AppData\Roaming\cdr.ini
2016-03-24 22:38 - 2016-03-24 22:38 - 0005120 _____ () C:\Users\Martin\AppData\Roaming\GiftBag.db
2016-03-25 10:34 - 2016-03-25 10:34 - 0029696 _____ () C:\Users\Martin\AppData\Local\MSGBOX.EXE
2014-06-03 03:24 - 2014-06-03 03:24 - 0000218 _____ () C:\Users\Martin\AppData\Local\recently-used.xbel
2014-03-02 20:08 - 2014-03-02 20:08 - 0007607 _____ () C:\Users\Martin\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\Martin\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-03-25 10:20

==================== End of FRST.txt ============================

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Číňani na koni

#8 Příspěvek od motji »

Otevřete poznámkový blok a zkopírujte do něj:

Kód: Vybrat vše

CHR Extension: (电脑管家上网防护) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm [2016-03-25]
-uložte jako fixlist.txt. Spusťte frst a dejte fix.
vyosek píše::arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

A pak zase napište, zda už je vše v pořádku:)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Noviik
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 28 říj 2013 15:53

Re: Číňani na koni

#9 Příspěvek od Noviik »

V Edge jsou furt.


Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Martin on p 25.03.2016 at 12:43:36,14.
Microsoft Windows 10 Home 10.0.10240 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Martin\Aktuální\zoek.exe [Scan all users] [Script inserted]

===== Runcheck 12:45:07,56 =====

--- Create Environment Variables 12:45:14,18
--- Checking Input 12:45:53,07
--- Reset Hosts File 12:47:13,60
--- AU AppData Check 12:47:14,96
--- Remove From Windows Installer 12:47:27,00
Přílohy
Obrázek 2.png
Obrázek 2.png (28.28 KiB) Zobrazeno 2667 x

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Číňani na koni

#10 Příspěvek od motji »

Ten zoek proběhl celý a pc se restartoval? Log je nějaký krátký :?:
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Noviik
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 28 říj 2013 15:53

Re: Číňani na koni

#11 Příspěvek od Noviik »

Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Martin on p  25.03.2016 at 12:43:36,14.
Microsoft Windows 10 Home 10.0.10240 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Martin\Aktuální\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2016-02-17-160822.log 9040 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\Users\DefaultAppPool\AppData\LocalLow deleted successfully
C:\Users\Martin\AppData\Local\CrashDumps deleted successfully
C:\Users\Martin\AppData\Local\NetworkTiles deleted successfully
C:\Users\Martin\AppData\Local\Opera Software deleted successfully
C:\Users\Martin\AppData\Local\Skype deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\CrashDumps deleted successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\NetworkTiles deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1f7jxlmq.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
user_pref("browser.search.suggest.enabled", false);

Added to C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1f7jxlmq.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~3\Package Cache deleted
C:\Users\Martin\AppData\Local\MSGBOX.EXE deleted
C:\windows\SysNative\Tasks\avast! Windows 10 Start Menu helper deleted
C:\windows\SysNative\GroupPolicy\Adm deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1f7jxlmq.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [13.02.2016 18:06]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF" [13.02.2016 18:06]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1f7jxlmq.default
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\1f7jxlmq.default
F627791AB91E01A9829A8D9B6E024D52 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll - Shockwave Flash
AF8A94BCB98C299C49B28CC12EBC0ED2 - C:\Users\Martin\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll - Google Update


==== Chromium Look ======================

Google Chrome Version: 46.0.2490.86

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[12.02.2016 23:12]

AdBlock - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Avast Online Security - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Last.fm scrobbler for Google Play - Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhlmaloocaogaldcbpimhlbimmhaonep

==== Chromium Fix ======================

C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{BE3C9ADE-5A0D-422A-973C-240D37EDBE27}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTer ... ORM=IESR02
HKCU\SearchScopes\{BE3C9ADE-5A0D-422A-973C-240D37EDBE27} - http://www.google.com/search?q={searchT ... utEncoding?}

==== Reset Google Chrome ======================

C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Martin\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Martin\AppData\Local\Mozilla\Firefox\Profiles\1f7jxlmq.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=445 folders=38 27138809 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Martin\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on p  25.03.2016 at 13:32:32,05 ======================

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Číňani na koni

#12 Příspěvek od motji »

Pořád to tam je? Co používáte za prohlížeč?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Noviik
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 28 říj 2013 15:53

Re: Číňani na koni

#13 Příspěvek od Noviik »

Edge po změně domovské už čínské přátele nevrací, ostatní prohlížeče taky ne. Používám chrome.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Číňani na koni

#14 Příspěvek od motji »

Ale pro jistotu udělejte reset chrome dle návodu https://www.pcrisk.cz/jak-odstranit-spy ... cu-vychozi
Takže číňani jsou fuč? :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Noviik
Návštěvník
Návštěvník
Příspěvky: 63
Registrován: 28 říj 2013 15:53

Re: Číňani na koni

#15 Příspěvek od Noviik »

Jsou. Moc díky za pomoc :-)

Odpovědět