Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Odvirované pc - pomalejší než předtím

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Tony182
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 05 čer 2016 17:14

Odvirované pc - pomalejší než předtím

#1 Příspěvek od Tony182 »

Zdravim, sem tu první den tak poprosím o trpělivost pokud udělám nějakou chybu :)
Můj problém tkvý v tom že pokaždé když odviruju nějaký počítač (Avast testy - v systému a po restartu, hijackthis, ccleaner, někdy i defregmentace disku a registrů, trojan hunter, antispware soft a většinou je to ok, pokud tahle kombinace nepmůže píšu na podobné fóra jak je toto :) ;) ) počítač má velmi pomalé načítání plochy a ikon, když už se načtou tak vše šlape v pořádku jen to načítání po přihlášení na účet někdy trvá i dvě minuty nebo dýl, záleží na železe které se ke mě dostane.

Zde na fóru sem se dobral odpovědi na můj problém a to autostart programů po spuštění, odklikal jsem přes příkaz msconfig vše nepotřebné a zbytečné ale stejně pc nabíhá velmi pomalu :( :( :( (železo ve kterém se vrtám pravě ted bylo silně zavirováno a všechny známé prohléžeče byly plné zbytečných toolbarů apodobných nesmyslů které sem odstranil)

Můžu vás poprosit o radu co bych s počítačem ještě mohl provést? věřím že je ještě hodně postupů které neznám nebo sem zatím nepoužil...

předem děkuji za každou radu nebo názor ;)


Edit: ještě by mě zajímalo jestli má smysle nechávat v systému programy jako jsou zrychlení PC nebo AVG - tune up apod.?

FRST log:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-06-2016 02
Ran by Martina Martinkova (administrator) on MARTINA (05-06-2016 18:36:25)
Running from C:\Documents and Settings\Martina Martinkova\Plocha
Loaded Profiles: Martina Martinkova (Available Profiles: Martina Martinkova & Áňulína & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
(Atheros) C:\WINDOWS\system32\acs.exe
(Agere Systems) C:\WINDOWS\system32\agrsmsvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(NewTech InfoSystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
() C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
(Atheros Communications, Inc.) C:\Program Files\Atheros\ACU.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Acer Inc.) C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IMJPMIG8.1] => C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [208952 2008-04-14] (Microsoft Corporation)
HKLM\...\Run: [MSPY2002] => C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [59392 2008-04-14] ()
HKLM\...\Run: [PHIME2002ASync] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2008-04-14] (Microsoft Corporation)
HKLM\...\Run: [PHIME2002A] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2008-04-14] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1032192 2008-02-22] (Synaptics, Inc.)
HKLM\...\Run: [AzMixerSel] => C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe [53248 2006-07-18] (Realtek Semiconductor Corp.)
HKLM\...\Run: [ePower_DMC] => C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [466944 2008-07-08] ()
HKLM\...\Run: [Boot] => C:\Program Files\Acer\Empowering Technology\ePower\Boot.exe [579584 2007-12-25] ()
HKLM\...\Run: [eRecoveryService] => C:\Program Files\Acer\Empowering Technology\eRecovery\eRAgent.exe [421888 2007-07-11] (Acer Inc.)
HKLM\...\Run: [ACU] => C:\Program Files\Atheros\ACU.exe [450648 2009-01-05] (Atheros Communications, Inc.)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7400064 2016-06-04] (AVAST Software)
HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe
Winlogon\Notify\AtiExtEvent:
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6690520 2016-06-01] (Piriform Ltd)
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {186c18d6-8b03-11de-943d-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {186c18d7-8b03-11de-943d-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {228aa30a-82ae-11de-9433-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {228aa30b-82ae-11de-9433-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {228aa30c-82ae-11de-9433-001f169596b8} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {48784602-a490-11de-9449-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {48784603-a490-11de-9449-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {49f17f3e-b028-11de-9455-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {49f17f3f-b028-11de-9455-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {703dc3eb-5537-11df-94e1-00242cd50c53} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {703dc3ec-5537-11df-94e1-00242cd50c53} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {b093fb10-8a6d-11de-943c-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {b093fb11-8a6d-11de-943c-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {c358eb34-5a5b-11df-94e4-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {c358eb35-5a5b-11df-94e4-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9ae-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9af-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9b0-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9b1-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {ccb383ed-5230-11df-94dd-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {ccb38f68-5230-11df-94dd-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-18\...\Run: [DWQueuedReporting] => C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [434080 2011-07-27] (Microsoft Corporation)
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x64] -> c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll <===== ATTENTION
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-06-04] (AVAST Software)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk [2009-03-23]
ShortcutTarget: Acer Empowering Technology.lnk -> C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe (Acer Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk [2009-03-23]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{C1B65846-1D2F-41CE-BA61-AFBBDA0CBC03}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.sweetim.com/?crg=3.1010000&st=18&barid={BB7FACEB-A8AB-11E1-8E74-0017C47F128F}
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&ptnrS=HJxdm073YYcz&ptb=29106EB8-4981-4A14-87D1-AA745792C1B4&si=pconverter
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0405&s=0&o=xpp&d=0309&m=travelmate_6593
SearchScopes: HKLM -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&st=1&barid={BB7FACEB-A8AB-11E1-8E74-0017C47F128F}&q={searchTerms}&barid={BB7FACEB-A8AB-11E1-8E74-0017C47F128F}
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... lz=1I7ACAW
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=706&systemid=406&v=a13350-116&apn_uid=7196297405484503&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
SearchScopes: HKLM -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm073YYcz&ptnrS=HJxdm073YYcz&si=pconverter&ptb=29106EB8-4981-4A14-87D1-AA745792C1B4&ind=2013010811&n=77fc1b7b&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKLM -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://search.sweetim.com/search.asp?src=6&st=1&barid={BB7FACEB-A8AB-11E1-8E74-0017C47F128F}&q={searchTerms}&barid={BB7FACEB-A8AB-11E1-8E74-0017C47F128F}
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/?q={searchTerms}&affID=111881&tt=220512_53all&babsrc=SP_ss&mntrId=b43d344d0000000000000017c47f128f
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=706&systemid=406&v=a12712-116&apn_uid=7196297405484503&apn_dtid=BND406&o=APN10645&apn_ptnrs=AG6&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=HJxdm073YYcz&ptnrS=HJxdm073YYcz&si=pconverter&ptb=29106EB8-4981-4A14-87D1-AA745792C1B4&ind=2013010811&n=77fc1b7b&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {DF526375-5AAD-4789-9628-1BD97832C3D0} URL = hxxp://search.sweetim.com/search.asp?src=6&st=1&barid={BB7FACEB-A8AB-11E1-8E74-0017C47F128F}&q={searchTerms}&barid={BB7FACEB-A8AB-11E1-8E74-0017C47F128F}
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://www.bing.com/search?FORM=UP21DF&PC=UP21 ... -SearchBox
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-06-04] (AVAST Software)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Toolbar: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
Toolbar: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> No Name - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - No File
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1237837155955
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default
FF DefaultSearchEngine: Ask.com
FF DefaultSearchUrl:
FF SearchEngineOrder.1: Ask.com
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Ask.com
FF Homepage: hxxp://www.search.ask.com/?o=APN10645A&gct=hp& ... 12-116&t=4
FF Keyword.URL: hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=29106EB8-4981-4A14-87D1-AA745792C1B4&n=77ee6815&ind=2012112917&id=HJxdm073YYcz&ptnrS=HJxdm073YYcz&si=pconverter&searchfor=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll [2014-09-09] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2014-08-13] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @software602.cz/602XML Filler -> C:\Program Files\Software602\602XML\Filler\npfiller.dll [2011-11-24] (Software602 a.s.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-05-10] (Adobe Systems Inc.)
FF Plugin: TorchVLC -> C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Plugins\Video\VLC\npvlc.dll [2013-07-31] (VideoLAN)
FF Plugin HKU\S-1-5-21-2463987481-3256626589-3986830351-1009: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-2463987481-3256626589-3986830351-1009: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-04] (Google Inc.)
FF user.js: detected! => C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\user.js [2012-05-28]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2013-05-10] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2011-01-23] (Apple Inc.)
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\Ask.xml [2014-05-20]
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\bingp.xml [2013-04-18]
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\my-web-search.xml [2012-11-29]
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\Search_Results.xml [2013-01-17]
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\sweetim.xml [2012-11-04]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Ask.xml [2014-07-22]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\babylon.xml [2012-05-28]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml [2011-03-11]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml [2013-01-17]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\Ask.xml [2014-07-22]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml [2013-10-04]
FF Extension: samfind Bookmarks Bar - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\extensions\sam@samfind.com [2013-10-03] [not signed]
FF Extension: No Name - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com [2016-06-04] [not signed]
FF Extension: Ask New Tabs - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\extensions\{0AF2132C-D508-1D6C-F240-7AAAB6C9E66D} [2014-05-20] [not signed]
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-07-20] [not signed]
FF Extension: SweetPacks Toolbar for Firefox - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi [2013-01-06] [not signed]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-11-20] [not signed]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-11-20] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-05] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-06-04]
FF HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\Firefox\Extensions: [{1650a312-02bc-40ee-977e-83f158701739}] - C:\Program Files\SiteAdvisor\6172\FF => not found
FF HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\Firefox\Extensions: [rebate_informer_wp@rebateblast.com] - C:\PROGRA~1\REBATE~1\Firefox
FF Extension: Rebate Informer Firefox - C:\PROGRA~1\REBATE~1\Firefox [2014-08-18] [not signed]
FF HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi => not found
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2013-10-25]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.search.ask.com/?o=APN10645A&gct=hp& ... 12-116&t=4"
CHR Session Restore: Default -> is enabled.
CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll => No File
CHR Plugin: (Native Client) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\49.0.2623.112\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Google Update) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Update\1.3.21.123\npGoogleUpdate3.dll => No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (602XML Filler) - C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll => No File
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (AdBlock) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-06-04]
CHR Extension: (Avast Online Security) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-04]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-04]
CHR HKLM\...\Chrome\Extension: [apgjagobplilmcdfelodhgefiidomnfl] - C:\Program Files\Inbox Toolbar\Chrome\ibxtoolbar_chr.crx [2013-09-16]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-06-04]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2012-05-28]
CHR HKLM\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Plugins\TorchPlugin.crx [2013-01-03]
StartMenuInternet: chrome.exe - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
StartMenuInternet: Google Chrome - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 602XML Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 ACS; C:\WINDOWS\system32\acs.exe [475220 2009-01-05] (Atheros) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-06-04] (AVAST Software)
S4 BUNAgentSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [16384 2008-03-03] (NewTech Infosystems, Inc.) [File not signed]
S4 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [131072 2008-04-04] () [File not signed]
S4 o2flash; C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe [65536 2007-02-13] (O2Micro International) [File not signed]
S4 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [657408 2009-10-27] (Nokia) [File not signed]
S4 Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
S4 TorchCrashHandler; C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Update\TorchCrashHandler.exe [X] <==== ATTENTION

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 abp480n5; C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation)
R3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [1346464 2008-12-29] (Atheros Communications, Inc.)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [32792 2016-06-04] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [91168 2016-06-04] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [64272 2016-06-04] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [58776 2016-06-04] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [815792 2016-06-04] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [449640 2016-06-04] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [187208 2016-06-04] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [67216 2016-06-04] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [221368 2016-06-04] (AVAST Software)
S3 AtiHdmiService; C:\WINDOWS\System32\drivers\AtiHdmi.sys [93696 2008-05-21] (ATI Research Inc.) [File not signed]
R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [539072 2007-03-23] (Broadcom Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37424 2007-03-23] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [876384 2007-03-31] (Broadcom Corporation.)
S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [149123 2007-03-23] (Broadcom Corporation.)
S3 btwhid; C:\WINDOWS\System32\DRIVERS\btwhid.sys [55352 2007-03-31] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [67960 2007-03-23] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 e1yexpress; C:\WINDOWS\System32\DRIVERS\e1y5132.sys [244368 2008-03-27] (Intel Corporation)
S3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [209664 2006-12-22] (Conexant Systems, Inc.)
S3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [988800 2006-12-22] (Conexant Systems, Inc.)
S3 IFXTPM; C:\WINDOWS\System32\DRIVERS\IFXTPM.SYS [41216 2008-05-08] (Infineon Technologies AG)
R2 Int15; C:\WINDOWS\System32\drivers\int15.sys [69632 2007-01-26] () [File not signed]
R3 Iviaspi; C:\WINDOWS\System32\drivers\iviaspi.sys [10368 2005-09-21] (InterVideo, Inc.) [File not signed]
R3 k57w2k; C:\WINDOWS\System32\DRIVERS\k57xp32.sys [186880 2008-09-03] (Broadcom Corporation)
S3 KMWDFILTER; C:\WINDOWS\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
R3 MarvinBus; C:\WINDOWS\System32\DRIVERS\MarvinBus.sys [171008 2005-06-02] (Pinnacle Systems GmbH) [File not signed]
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 O2SCBUS; C:\WINDOWS\System32\DRIVERS\ozscr.sys [101848 2008-06-12] (O2Micro)
R1 PCLEPCI; C:\WINDOWS\system32\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) [File not signed]
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 RSUSBSTOR; C:\WINDOWS\System32\Drivers\RTS5121.sys [158720 2008-10-07] (Realtek Semiconductor Corp.)
R3 WSIMD; C:\WINDOWS\System32\DRIVERS\wsimd.sys [57408 2008-02-08] (Atheros Communications, Inc.) [File not signed]
S3 ASAPIW2K; \??\C:\WINDOWS\system32\Drivers\asapiW2k.sys [X]
S1 F06DEFF2-5B9C-490D-910F-35D3A91196222; \??\C:\Program Files\Movies Toolbar\Datamngr\setmgrc2.cfg [X]
S3 NETw5x32; system32\DRIVERS\NETw5x32.sys [X]
S3 Rts516xIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 SNP2UVC; system32\DRIVERS\snp2uvc.sys [X]
S3 SymIM; system32\DRIVERS\SymIM.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X]
S3 USBCCID; system32\DRIVERS\Rts5161ccid.sys [X]
U1 WS2IFSL; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-05 18:36 - 2016-06-05 18:36 - 00032770 _____ C:\Documents and Settings\Martina Martinkova\Plocha\FRST.txt
2016-06-05 18:36 - 2016-06-05 18:36 - 00000000 ____D C:\FRST
2016-06-05 18:35 - 2016-06-05 18:34 - 01735680 _____ (Farbar) C:\Documents and Settings\Martina Martinkova\Plocha\FRST.exe
2016-06-04 02:59 - 2016-06-04 03:01 - 00000000 ____D C:\WINDOWS\system32\config\RC Backup
2016-06-04 02:30 - 2016-06-04 02:30 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Plocha\NETGATE.Registry.Cleaner.v14.0.405.0-BEAN
2016-06-04 02:24 - 2016-06-04 02:24 - 00000000 ____D C:\WINDOWS\system32\oodag
2016-06-04 02:22 - 2016-06-04 02:22 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\O&O
2016-06-04 01:43 - 2016-06-04 01:43 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\OO Software
2016-06-04 01:42 - 2016-06-04 01:42 - 00000686 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2016-06-04 01:42 - 2016-06-04 01:42 - 00000000 ____D C:\Program Files\CCleaner
2016-06-04 01:42 - 2016-06-04 01:42 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
2016-06-04 01:33 - 2016-06-04 01:33 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Plocha\backups
2016-06-04 01:27 - 2016-06-04 01:27 - 00000000 __SHD C:\Documents and Settings\Administrator\PrivacIE
2016-06-04 01:23 - 2016-06-04 01:23 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Data aplikací\AVG
2016-06-04 01:23 - 2016-06-04 01:23 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\AVG
2016-06-04 01:17 - 2016-06-04 01:17 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Mozilla
2016-06-04 01:17 - 2016-06-04 01:17 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\Mozilla
2016-06-04 01:13 - 2016-06-04 01:13 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Data aplikací\AVAST Software
2016-06-04 01:12 - 2016-06-04 01:12 - 00001693 _____ C:\Documents and Settings\All Users\Plocha\Avast Free Antivirus.lnk
2016-06-04 01:12 - 2016-06-04 01:12 - 00000000 __HDC C:\WINDOWS\$NtUninstallWdf01009$
2016-06-04 01:12 - 2016-06-04 01:12 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\AVAST Software
2016-06-04 01:12 - 2008-11-07 18:55 - 00016928 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsgXP_2k3.dll
2016-06-04 01:11 - 2016-06-05 18:00 - 00000388 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2016-06-04 01:11 - 2016-06-04 01:11 - 00815792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00449640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00334280 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2016-06-04 01:11 - 2016-06-04 01:11 - 00221368 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00187208 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00091168 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00067216 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00064272 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00058776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00052184 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2016-06-04 01:11 - 2016-06-04 01:11 - 00032792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2016-06-04 01:10 - 2016-06-04 01:10 - 00000000 ____D C:\Program Files\Nová složka
2016-06-04 01:06 - 2016-05-12 11:42 - 00388608 _____ (Trend Micro Inc.) C:\Documents and Settings\Martina Martinkova\Plocha\hijackthis.exe
2016-06-04 00:38 - 2016-06-04 00:38 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\Adobe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-05 18:36 - 2009-08-04 16:19 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Plocha
2016-06-05 18:36 - 2009-08-04 16:19 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Local Settings\Temp
2016-06-05 18:34 - 2009-09-16 16:05 - 00000492 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{0B7D00A6-798F-4FF7-A1C1-E39533791E0A}.job
2016-06-05 18:32 - 2011-05-11 19:40 - 00001078 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2463987481-3256626589-3986830351-1009UA.job
2016-06-05 18:31 - 2012-10-03 16:05 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-06-05 17:44 - 2012-03-31 07:20 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-06-05 17:24 - 2008-09-08 20:10 - 00032156 _____ C:\WINDOWS\SchedLgU.Txt
2016-06-05 16:59 - 2014-01-30 22:21 - 00000495 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2016-06-05 16:59 - 2009-08-04 16:19 - 00004176 _____ C:\WINDOWS\ModemLog_Agere Systems HDA Modem.txt
2016-06-05 16:59 - 2008-09-08 20:10 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2016-06-05 16:58 - 2014-03-24 19:59 - 00000248 _____ C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2016-06-05 16:58 - 2012-10-03 16:05 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-06-05 16:58 - 2008-09-08 20:10 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-06-05 16:57 - 2009-08-05 18:12 - 00524288 _____ C:\WINDOWS\system32\config\ACS.evt
2016-06-05 16:57 - 2009-08-04 16:19 - 00000178 ___SH C:\Documents and Settings\Martina Martinkova\ntuser.ini
2016-06-05 16:57 - 2009-08-04 16:19 - 00000000 ____D C:\Documents and Settings\Martina Martinkova
2016-06-05 16:57 - 2008-09-08 20:10 - 00000211 __RSH C:\boot.ini
2016-06-05 16:57 - 2008-09-08 19:28 - 00000582 _____ C:\WINDOWS\win.ini
2016-06-05 16:57 - 2008-07-10 04:29 - 00000240 _____ C:\WINDOWS\system.ini
2016-06-05 16:53 - 2009-08-04 16:19 - 00000000 __RHD C:\Documents and Settings\Martina Martinkova\Data aplikací
2016-06-05 16:53 - 2008-09-08 19:41 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2016-06-05 16:53 - 2008-09-08 19:38 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2016-06-05 16:53 - 2008-09-08 19:38 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2016-06-05 16:48 - 2009-08-04 16:19 - 00000000 ___HD C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací
2016-06-04 20:36 - 2008-09-08 19:48 - 01183876 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-06-04 20:36 - 2008-09-08 19:48 - 00494042 _____ C:\WINDOWS\system32\perfh005.dat
2016-06-04 20:36 - 2008-09-08 19:48 - 00109542 _____ C:\WINDOWS\system32\perfc005.dat
2016-06-04 20:30 - 2008-07-10 04:29 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
2016-06-04 16:33 - 2013-01-17 16:11 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\iLivid
2016-06-04 16:24 - 2013-01-17 16:12 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Wincert
2016-06-04 15:42 - 2011-05-11 19:41 - 00002362 _____ C:\Documents and Settings\Martina Martinkova\Nabídka Start\Programy\Google Chrome.lnk
2016-06-04 15:42 - 2011-05-11 19:41 - 00002356 _____ C:\Documents and Settings\Martina Martinkova\Plocha\Google Chrome.lnk
2016-06-04 15:42 - 2009-08-04 16:19 - 00000000 ___RD C:\Documents and Settings\Martina Martinkova\Nabídka Start\Programy
2016-06-04 15:33 - 2012-03-22 17:18 - 00000000 ____D C:\WINDOWS\pss
2016-06-04 15:31 - 2011-05-11 19:40 - 00001026 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2463987481-3256626589-3986830351-1009Core.job
2016-06-04 11:09 - 2009-03-23 23:03 - 00003187 _____ C:\WINDOWS\wincmd.ini
2016-06-04 02:45 - 2013-09-26 07:16 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Data aplikací\Seznam.cz
2016-06-04 02:39 - 2012-12-11 22:55 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\TEMP
2016-06-04 02:38 - 2012-12-11 22:55 - 00000000 ____D C:\Program Files\Common Files\PC Tools
2016-06-04 02:37 - 2014-06-19 18:41 - 00000000 ____D C:\Program Files\Sweet Home 3D
2016-06-04 02:31 - 2012-05-28 11:58 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\SweetIM
2016-06-04 02:25 - 2008-07-10 02:38 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start
2016-06-04 01:55 - 2008-09-08 19:44 - 00000000 ___HD C:\WINDOWS\inf
2016-06-04 01:55 - 2008-09-08 19:14 - 00000000 ____D C:\WINDOWS\system32\ReinstallBackups
2016-06-04 01:50 - 2009-05-06 21:36 - 00000000 ____D C:\WINDOWS\Minidump
2016-06-04 01:35 - 2011-01-30 20:02 - 00000000 ____D C:\Program Files\Centauri
2016-06-04 01:34 - 2014-06-19 18:43 - 00065536 _____ C:\WINDOWS\system32\config\TuneUp.evt
2016-06-04 01:33 - 2013-09-17 18:50 - 00000000 ____D C:\Program Files\RebateInformer
2016-06-04 01:32 - 2012-11-30 17:00 - 00000000 ____D C:\Program Files\NortonInstaller
2016-06-04 01:27 - 2008-09-08 20:04 - 00000000 ____D C:\Documents and Settings\Administrator
2016-06-04 01:25 - 2009-12-16 03:05 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Norton
2016-06-04 01:23 - 2008-09-08 19:35 - 00000000 ___HD C:\Documents and Settings\Administrator\Local Settings\Data aplikací
2016-06-04 01:15 - 2012-11-14 16:23 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Temp
2016-06-04 01:11 - 2012-03-22 20:40 - 00000000 ____D C:\Program Files\AVAST Software
2016-06-04 01:10 - 2010-04-27 21:04 - 00000000 ____D C:\Program Files\AVG
2016-06-04 01:07 - 2012-03-22 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2016-06-04 01:00 - 2008-09-08 20:10 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2016-06-04 00:47 - 2008-09-08 20:10 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Temp
2016-06-04 00:43 - 2008-07-10 02:36 - 00002504 _____ C:\WINDOWS\system32\CONFIG.NT
2016-06-04 00:38 - 2008-09-08 19:38 - 00000000 __RHD C:\Documents and Settings\Administrator\Data aplikací

==================== Files in the root of some directories =======

2009-09-10 17:57 - 2014-06-02 19:57 - 0020992 _____ () C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-08-04 16:19 - 2009-08-04 16:19 - 0000138 _____ () C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\fusioncache.dat
2010-08-10 15:10 - 2014-09-10 18:01 - 0000952 ___SH () C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
2014-09-14 17:01 - 2014-09-14 17:01 - 0003865 _____ () C:\Documents and Settings\All Users\Data aplikací\lpm.dat

Some files in TEMP:
====================
C:\Documents and Settings\Administrator\Local Settings\Temp\DseShExt-x86.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\SDShelEx-win32.dll
C:\Documents and Settings\Martina Martinkova\Local Settings\Temp\listicka-partner-16194-1.1.8-offline.exe
C:\Documents and Settings\Martina Martinkova\Local Settings\Temp\SQLite.dll
C:\Documents and Settings\Martina Martinkova\Local Settings\Temp\SRAssetsHelper.dll
C:\Documents and Settings\Martina Martinkova\Local Settings\Temp\SweetEEISetup.exe
C:\Documents and Settings\Martina Martinkova\Local Settings\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Odvirované pc - pomalejší než předtím

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Tony182
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 05 čer 2016 17:14

Re: Odvirované pc - pomalejší než předtím

#3 Příspěvek od Tony182 »

# AdwCleaner v5.119 - Log vytvořen 05/06/2016 v 19:45:41
# Aktualizováno 30/05/2016 by Xplode
# Databáze : 2016-05-25.2 [Místní]
# Operační system : Microsoft Windows XP Service Pack 3 (X86)
# Uživatelské jméno : Martina Martinkova - MARTINA
# Spuštěno z : C:\Documents and Settings\Martina Martinkova\Plocha\adwcleaner_5.119.exe
# Nastavení : Sken
# Podpora : http://toolslib.net/forum

***** [ Služby ] *****

Služba Nalezeno : torchcrashhandler
Služba Nalezeno : F06DEFF2-5B9C-490D-910F-35D3A91196222

***** [ Složky ] *****

Složka Nalezeno : C:\Documents and Settings\All Users\Data aplikací\Babylon
Složka Nalezeno : C:\Documents and Settings\All Users\Data aplikací\SweetIM
Složka Nalezeno : C:\Documents and Settings\All Users\Data aplikací\Tarma Installer
Složka Nalezeno : C:\Documents and Settings\All Users\Data aplikací\torchcrashhandler
Složka Nalezeno : C:\Documents and Settings\All Users\Data aplikací\wincert
Složka Nalezeno : C:\Documents and Settings\All Users\Nabídka Start\Programy\Inbox Toolbar
Složka Nalezeno : C:\Documents and Settings\All Users\Nabídka Start\Programy\RebateInformer
Složka Nalezeno : C:\Program Files\~BabylonToolbar
Složka Nalezeno : C:\Program Files\Inbox Toolbar
Složka Nalezeno : C:\Program Files\Inbox.com
Složka Nalezeno : C:\Program Files\OnlineVault
Složka Nalezeno : C:\Program Files\RebateInformer
Složka Nalezeno : C:\Program Files\Search Results Toolbar
Složka Nalezeno : C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\BabylonToolbar

***** [ Soubory ] *****

Soubor Nalezeno : C:\Documents and Settings\All Users\Plocha\Get The Best Facebook Chat Messenger.lnk
Soubor Nalezeno : C:\Documents and Settings\All Users\Plocha\RebateInformer.lnk
Soubor Nalezeno : C:\Program Files\Mozilla Firefox\searchplugins\Ask.xml
Soubor Nalezeno : C:\Program Files\Mozilla Firefox\browser\searchplugins\Ask.xml
Soubor Nalezeno : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml
Soubor Nalezeno : C:\Program Files\Mozilla Firefox\searchplugins\Search_Results.xml
Soubor Nalezeno : C:\user.js

***** [ DLL ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****

Zástupce Infikováno : C:\Documents and Settings\All Users\Nabídka Start\Programy\Inbox Toolbar\Inbox.com.lnk ( /showurl hxxp://www.inbox.com/homepage.aspx?tbid=80067&iwk=273&lng=cs )
Zástupce Infikováno : C:\Documents and Settings\All Users\Nabídka Start\Programy\Inbox Toolbar\Nápověda.lnk ( /showurl hxxp://toolbar.inbox.com/faq.aspx )

***** [ Naplánované úlohy ] *****


***** [ Registry ] *****

Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Applications\Torch.exe
Klíč Nalezeno : HKLM\SOFTWARE\Clients\StartMenuInternet\Torch
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\torch.exe
Klíč Nalezeno : HKLM\SOFTWARE\MozillaPlugins\TorchVLC
Hodnota Nalezeno : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Hodnota Nalezeno : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Klíč Nalezeno : HKLM\SOFTWARE\CLASSES\b
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Applications\iLividSetup(10).exe
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Applications\iLividSetup(5).exe
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Applications\iLividSetup-r706-n-bc.exe
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Applications\iLividSetup.exe
Hodnota Nalezeno : HKCU\Software\Mozilla\Firefox\Extensions [rebate_informer_wp@rebateblast.com]
Klíč Nalezeno : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Klíč Nalezeno : HKLM\SOFTWARE\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Babylon.dskBnd
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
Klíč Nalezeno : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Klíč Nalezeno : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Klíč Nalezeno : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Klíč Nalezeno : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CShared.TB4Client
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CShared.TB4Script
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CShared.TB4Server
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CShared.TB4Server2
Klíč Nalezeno : HKLM\SOFTWARE\Classes\driverscanner
Klíč Nalezeno : HKLM\SOFTWARE\Classes\escort.escortIEPane
Klíč Nalezeno : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Klíč Nalezeno : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Inbox.AppServer
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Inbox.IBX404
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Inbox.JSServer
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Inbox.Toolbar
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Prod.cap
Klíč Nalezeno : HKLM\SOFTWARE\Classes\RebateI.Rebate Informer BHO
Klíč Nalezeno : HKLM\SOFTWARE\Classes\RebateI.RebateInformImageGen
Klíč Nalezeno : HKLM\SOFTWARE\Classes\RebateInf.RebateInfObj
Klíč Nalezeno : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
Klíč Nalezeno : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
Klíč Nalezeno : HKLM\SOFTWARE\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook
Klíč Nalezeno : HKLM\SOFTWARE\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Toolbar3.SWEETIE
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Toolbar3.SWEETIE.1
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{042DA63B-0933-403D-9395-B49307691690}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{37540F19-DD4C-478B-B2DF-C19281BCAF27}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{612AD33D-9824-4E87-8396-92374E91C4BB}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{DB35C569-5624-4CFC-8043-E5139F55A073}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\CLSID\{91355F74-D76B-11DF-91F3-0FB0DFD72085}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{28C3737A-32D1-492D-B76B-8D75EBBFB887}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{438B047C-C041-4D15-98CF-A97C6B366C28}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{615E8AA1-6BB8-4A3D-A1CC-373194DB612C}
Klíč Nalezeno : HKLM\SOFTWARE\Classes\TypeLib\{CBEF8724-D080-4737-88DA-111EEC6651AA}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48586425-6BB7-4F51-8DC6-38C88E3EBB58}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EC2BAE47-25AF-4CE9-9E78-10627A49C9EA}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{48586425-6BB7-4F51-8DC6-38C88E3EBB58}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EC2BAE47-25AF-4CE9-9E78-10627A49C9EA}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Hodnota Nalezeno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Hodnota Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved [{91355F74-D76B-11DF-91F3-0FB0DFD72085}]
Klíč Nalezeno : HKCU\Software\APN DTX
Klíč Nalezeno : HKCU\Software\BabylonToolbar
Klíč Nalezeno : HKCU\Software\CToolbar
Klíč Nalezeno : HKCU\Software\DataMngr
Klíč Nalezeno : HKCU\Software\DataMngr_Toolbar
Klíč Nalezeno : HKCU\Software\ilivid
Klíč Nalezeno : HKCU\Software\ilividmoviestoolbardla
Klíč Nalezeno : HKCU\Software\ilividtoolbarguid
Klíč Nalezeno : HKCU\Software\OnlineVault
Klíč Nalezeno : HKCU\Software\Rebate Informer
Klíč Nalezeno : HKCU\Software\SweetIM
Klíč Nalezeno : HKCU\Software\torch
Klíč Nalezeno : HKCU\Software\systweak
Klíč Nalezeno : HKLM\SOFTWARE\Babylon
Klíč Nalezeno : HKLM\SOFTWARE\BabylonToolbar
Klíč Nalezeno : HKLM\SOFTWARE\CToolbar
Klíč Nalezeno : HKLM\SOFTWARE\DataMngr
Klíč Nalezeno : HKLM\SOFTWARE\iLividSRTB
Klíč Nalezeno : HKLM\SOFTWARE\Inbox Toolbar
Klíč Nalezeno : HKLM\SOFTWARE\OnlineVault
Klíč Nalezeno : HKLM\SOFTWARE\SweetIM
Klíč Nalezeno : HKLM\SOFTWARE\Tarma Installer
Klíč Nalezeno : HKLM\SOFTWARE\torch
Klíč Nalezeno : HKLM\SOFTWARE\Uniblue
Klíč Nalezeno : HKLM\SOFTWARE\Uniblue\DriverScanner
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}_is1
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{612AD33D-9824-4E87-8396-92374E91C4BB}_is1
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FE60B87C-63A2-4A45-AC06-FFEFD5DB7846}_is1
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar
Klíč Nalezeno : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\torch
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}_is1
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{612AD33D-9824-4E87-8396-92374E91C4BB}_is1
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{FE60B87C-63A2-4A45-AC06-FFEFD5DB7846}_is1
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilivid
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\APN DTX
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\BabylonToolbar
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\CToolbar
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\DataMngr
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\DataMngr_Toolbar
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\ilivid
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\ilividmoviestoolbardla
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\ilividtoolbarguid
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\OnlineVault
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Rebate Informer
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\SweetIM
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\torch
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\systweak
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\torch
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch
Data Nalezeno : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&ptnrS=HJxdm073YYcz&ptb=29106EB8-4981-4A14-87D1-AA745792C1B4&si=pconverter
Data Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://home.sweetim.com/?crg=3.1010000&st=18&barid={BB7FACEB-A8AB-11E1-8E74-0017C47F128F}
Data Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://home.mywebsearch.com/index.jhtml?n=77DE8857&ptnrS=HJxdm073YYcz&ptb=29106EB8-4981-4A14-87D1-AA745792C1B4&si=pconverter
Hodnota Nalezeno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List [C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Application\torch.exe]
Hodnota Nalezeno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List [C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Plugins\Hola\hola_plugin.exe]
Hodnota Nalezeno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Application\torch.exe]
Hodnota Nalezeno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Plugins\Hola\hola_plugin.exe]
Klíč Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Klíč Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Klíč Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
Klíč Nalezeno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DF526375-5AAD-4789-9628-1BD97832C3D0}
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
Klíč Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Data Nalezeno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {EEE6C360-6118-11DC-9C72-001320C79847}
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
Klíč Nalezeno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\SearchScopes\{DF526375-5AAD-4789-9628-1BD97832C3D0}

***** [ Prohlížeče ] *****


*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [21163 bytů] - [05/06/2016 19:45:41]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [21237 bytů] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Odvirované pc - pomalejší než předtím

#4 Příspěvek od Rudy »

Neklikl jste na mazání, ADW nemazal. Zkuste ještě jednou.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Tony182
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 05 čer 2016 17:14

Re: Odvirované pc - pomalejší než předtím

#5 Příspěvek od Tony182 »

Máte pravdu :) lehce se to zlepšilo :thumbsup:

# AdwCleaner v5.119 - Log vytvořen 05/06/2016 v 20:58:21
# Aktualizováno 30/05/2016 by Xplode
# Databáze : 2016-05-25.2 [Místní]
# Operační system : Microsoft Windows XP Service Pack 3 (X86)
# Uživatelské jméno : Martina Martinkova - MARTINA
# Spuštěno z : C:\Documents and Settings\Martina Martinkova\Plocha\adwcleaner_5.119.exe
# Nastavení : Čištění
# Podpora : http://toolslib.net/forum

***** [ Služby ] *****

[-] Služba Smazáno : torchcrashhandler
[-] Služba Smazáno : F06DEFF2-5B9C-490D-910F-35D3A91196222

***** [ Složky ] *****

[-] Složka Smazáno : C:\Documents and Settings\All Users\Data aplikací\Babylon
[-] Složka Smazáno : C:\Documents and Settings\All Users\Data aplikací\SweetIM
[-] Složka Smazáno : C:\Documents and Settings\All Users\Data aplikací\Tarma Installer
[-] Složka Smazáno : C:\Documents and Settings\All Users\Data aplikací\torchcrashhandler
[-] Složka Smazáno : C:\Documents and Settings\All Users\Data aplikací\wincert
[-] Složka Smazáno : C:\Documents and Settings\All Users\Nabídka Start\Programy\Inbox Toolbar
[-] Složka Smazáno : C:\Documents and Settings\All Users\Nabídka Start\Programy\RebateInformer
[-] Složka Smazáno : C:\Program Files\~BabylonToolbar
[-] Složka Smazáno : C:\Program Files\Inbox Toolbar
[-] Složka Smazáno : C:\Program Files\Inbox.com
[-] Složka Smazáno : C:\Program Files\OnlineVault
[-] Složka Smazáno : C:\Program Files\RebateInformer
[-] Složka Smazáno : C:\Program Files\Search Results Toolbar
[-] Složka Smazáno : C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\BabylonToolbar

***** [ Soubory ] *****

[-] Soubor Smazáno : C:\Documents and Settings\All Users\Plocha\Get The Best Facebook Chat Messenger.lnk
[-] Soubor Smazáno : C:\Documents and Settings\All Users\Plocha\RebateInformer.lnk
[-] Soubor Smazáno : C:\Program Files\Mozilla Firefox\searchplugins\Ask.xml
[-] Soubor Smazáno : C:\Program Files\Mozilla Firefox\browser\searchplugins\Ask.xml
[-] Soubor Smazáno : C:\Program Files\Mozilla Firefox\searchplugins\Babylon.xml
[-] Soubor Smazáno : C:\Program Files\Mozilla Firefox\searchplugins\Search_Results.xml
[-] Soubor Smazáno : C:\user.js

***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****

[!] Zástupce Ne Vyléčeno : C:\Documents and Settings\All Users\Nabídka Start\Programy\Inbox Toolbar\Inbox.com.lnk
[!] Zástupce Ne Vyléčeno : C:\Documents and Settings\All Users\Nabídka Start\Programy\Inbox Toolbar\Nápověda.lnk

***** [ Naplánované úlohy ] *****


***** [ Registry ] *****

[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Applications\Torch.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Clients\StartMenuInternet\Torch
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\torch.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\MozillaPlugins\TorchVLC
[-] Hodnota Smazáno : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
[#] Hodnota Smazáno : HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls [x64]
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
[-] Klíč Smazáno : HKLM\SOFTWARE\CLASSES\b
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Applications\iLividSetup(10).exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Applications\iLividSetup(5).exe
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Applications\iLividSetup-r706-n-bc.exe
[-] Hodnota Smazáno : HKCU\Software\Mozilla\Firefox\Extensions [rebate_informer_wp@rebateblast.com]
[-] Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
[-] Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Babylon.dskBnd
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\bbylnApp.appCore
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CShared.TB4Client
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CShared.TB4Script
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CShared.TB4Server
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CShared.TB4Server2
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\driverscanner
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\escort.escortIEPane
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Inbox.AppServer
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Inbox.IBX404
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Inbox.JSServer
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Inbox.Toolbar
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Prod.cap
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\RebateI.Rebate Informer BHO
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\RebateI.RebateInformImageGen
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\RebateInf.RebateInfObj
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Toolbar3.SWEETIE
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Toolbar3.SWEETIE.1
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{042DA63B-0933-403D-9395-B49307691690}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{183643C8-EE67-4574-9A38-927852E34163}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{37540F19-DD4C-478B-B2DF-C19281BCAF27}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{54ECA872-DB2A-4C6B-BBB2-F3777C6786CC}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{612AD33D-9824-4E87-8396-92374E91C4BB}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{8736C681-37A0-40C6-A0F0-4C083409151C}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{DB35C569-5624-4CFC-8043-E5139F55A073}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{91355F74-D76B-11DF-91F3-0FB0DFD72085}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{01C78433-6FDF-4E5A-A82D-B535C32E03DF}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{28C3737A-32D1-492D-B76B-8D75EBBFB887}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{41349826-5C7F-4BF0-8279-5DAF1DE6E9AE}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{604EA016-1EDE-41E6-A23E-76CF8F2A4808}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{B3BA5582-79A9-464D-A7FA-711C5888C6E9}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{E9BBD270-4B87-4EE2-912F-6635674986C0}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{438B047C-C041-4D15-98CF-A97C6B366C28}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{506F578A-91E1-46CE-830F-E2F4268E9966}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{615E8AA1-6BB8-4A3D-A1CC-373194DB612C}
[-] Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{CBEF8724-D080-4737-88DA-111EEC6651AA}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48586425-6BB7-4F51-8DC6-38C88E3EBB58}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A86782D8-7B41-452F-A217-1854F72DBA54}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EC2BAE47-25AF-4CE9-9E78-10627A49C9EA}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{48586425-6BB7-4F51-8DC6-38C88E3EBB58}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1ED9DA0-AFD0-4B90-AC6A-D3874F591014}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C547C6C2-561B-4169-A2A5-20BA771CA93B}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EC2BAE47-25AF-4CE9-9E78-10627A49C9EA}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F34C9277-6577-4DFF-B2D7-7D58092F272F}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{312F84FB-8970-4FD3-BDDB-7012EAC4AFC9}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
[-] Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
[-] Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved [{91355F74-D76B-11DF-91F3-0FB0DFD72085}]
[-] Klíč Smazáno : HKCU\Software\APN DTX
[-] Klíč Smazáno : HKCU\Software\BabylonToolbar
[-] Klíč Smazáno : HKCU\Software\CToolbar
[-] Klíč Smazáno : HKCU\Software\DataMngr
[-] Klíč Smazáno : HKCU\Software\DataMngr_Toolbar
[-] Klíč Smazáno : HKCU\Software\ilivid
[-] Klíč Smazáno : HKCU\Software\ilividmoviestoolbardla
[-] Klíč Smazáno : HKCU\Software\ilividtoolbarguid
[-] Klíč Smazáno : HKCU\Software\OnlineVault
[-] Klíč Smazáno : HKCU\Software\Rebate Informer
[-] Klíč Smazáno : HKCU\Software\SweetIM
[-] Klíč Smazáno : HKCU\Software\torch
[-] Klíč Smazáno : HKCU\Software\systweak
[-] Klíč Smazáno : HKLM\SOFTWARE\Babylon
[-] Klíč Smazáno : HKLM\SOFTWARE\BabylonToolbar
[-] Klíč Smazáno : HKLM\SOFTWARE\CToolbar
[-] Klíč Smazáno : HKLM\SOFTWARE\DataMngr
[-] Klíč Smazáno : HKLM\SOFTWARE\iLividSRTB
[-] Klíč Smazáno : HKLM\SOFTWARE\Inbox Toolbar
[-] Klíč Smazáno : HKLM\SOFTWARE\OnlineVault
[-] Klíč Smazáno : HKLM\SOFTWARE\SweetIM
[-] Klíč Smazáno : HKLM\SOFTWARE\Tarma Installer
[-] Klíč Smazáno : HKLM\SOFTWARE\torch
[-] Klíč Smazáno : HKLM\SOFTWARE\Uniblue
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\torch
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}_is1
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{612AD33D-9824-4E87-8396-92374E91C4BB}_is1
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FE60B87C-63A2-4A45-AC06-FFEFD5DB7846}_is1
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ilivid
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar
[-] Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\torch
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4EF645BD-65B0-4F98-AD56-D0437B7045F6}_is1
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{612AD33D-9824-4E87-8396-92374E91C4BB}_is1
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{FE60B87C-63A2-4A45-AC06-FFEFD5DB7846}_is1
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ilivid
[-] Data Obnoveno : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Obnoveno : HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Hodnota Smazáno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List [C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Application\torch.exe]
[-] Hodnota Smazáno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List [C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Plugins\Hola\hola_plugin.exe]
[-] Hodnota Smazáno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Application\torch.exe]
[-] Hodnota Smazáno : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Torch\Plugins\Hola\hola_plugin.exe]
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
[-] Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DF526375-5AAD-4789-9628-1BD97832C3D0}
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
[-] Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
[-] Data Obnoveno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope]

***** [ Prohlížeče ] *****


*************************

:: "Tracing" klíče smazány
:: Nastavení Winsock vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [19346 bytů] - [05/06/2016 20:58:21]
C:\AdwCleaner\AdwCleaner[S1].txt - [21317 bytů] - [05/06/2016 20:57:13]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [19494 bytů] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Odvirované pc - pomalejší než předtím

#6 Příspěvek od Rudy »

Dejte nový log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Tony182
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 05 čer 2016 17:14

Re: Odvirované pc - pomalejší než předtím

#7 Příspěvek od Tony182 »

FRST log 2

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-06-2016 02
Ran by Martina Martinkova (administrator) on MARTINA (06-06-2016 08:36:36)
Running from C:\Documents and Settings\Martina Martinkova\Plocha
Loaded Profiles: Martina Martinkova (Available Profiles: Martina Martinkova & Áňulína & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
(Atheros) C:\WINDOWS\system32\acs.exe
(Agere Systems) C:\WINDOWS\system32\agrsmsvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(NewTech InfoSystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
() C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
(Atheros Communications, Inc.) C:\Program Files\Atheros\ACU.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(Acer Inc.) C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IMJPMIG8.1] => C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [208952 2008-04-14] (Microsoft Corporation)
HKLM\...\Run: [MSPY2002] => C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [59392 2008-04-14] ()
HKLM\...\Run: [PHIME2002ASync] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2008-04-14] (Microsoft Corporation)
HKLM\...\Run: [PHIME2002A] => C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [455168 2008-04-14] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1032192 2008-02-22] (Synaptics, Inc.)
HKLM\...\Run: [AzMixerSel] => C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe [53248 2006-07-18] (Realtek Semiconductor Corp.)
HKLM\...\Run: [ePower_DMC] => C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [466944 2008-07-08] ()
HKLM\...\Run: [Boot] => C:\Program Files\Acer\Empowering Technology\ePower\Boot.exe [579584 2007-12-25] ()
HKLM\...\Run: [eRecoveryService] => C:\Program Files\Acer\Empowering Technology\eRecovery\eRAgent.exe [421888 2007-07-11] (Acer Inc.)
HKLM\...\Run: [ACU] => C:\Program Files\Atheros\ACU.exe [450648 2009-01-05] (Atheros Communications, Inc.)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7400064 2016-06-04] (AVAST Software)
HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe
Winlogon\Notify\AtiExtEvent:
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6690520 2016-06-01] (Piriform Ltd)
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {186c18d6-8b03-11de-943d-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {186c18d7-8b03-11de-943d-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {228aa30a-82ae-11de-9433-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {228aa30b-82ae-11de-9433-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {228aa30c-82ae-11de-9433-001f169596b8} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {48784602-a490-11de-9449-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {48784603-a490-11de-9449-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {49f17f3e-b028-11de-9455-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {49f17f3f-b028-11de-9455-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {703dc3eb-5537-11df-94e1-00242cd50c53} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {703dc3ec-5537-11df-94e1-00242cd50c53} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {b093fb10-8a6d-11de-943c-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {b093fb11-8a6d-11de-943c-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {c358eb34-5a5b-11df-94e4-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {c358eb35-5a5b-11df-94e4-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9ae-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9af-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9b0-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9b1-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {ccb383ed-5230-11df-94dd-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {ccb38f68-5230-11df-94dd-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-18\...\Run: [DWQueuedReporting] => C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [434080 2011-07-27] (Microsoft Corporation)
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-06-04] (AVAST Software)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Acer Empowering Technology.lnk [2009-03-23]
ShortcutTarget: Acer Empowering Technology.lnk -> C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe (Acer Inc.)
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk [2009-03-23]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{C1B65846-1D2F-41CE-BA61-AFBBDA0CBC03}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0405&s=0&o=xpp&d=0309&m=travelmate_6593
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... lz=1I7ACAW
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://www.bing.com/search?FORM=UP21DF&PC=UP21 ... -SearchBox
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-06-04] (AVAST Software)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Toolbar: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> No Name - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - No File
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1237837155955
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default
FF DefaultSearchEngine: Ask.com
FF DefaultSearchUrl:
FF SearchEngineOrder.1: Ask.com
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Ask.com
FF Homepage: hxxp://www.search.ask.com/?o=APN10645A&gct=hp& ... 12-116&t=4
FF Keyword.URL: hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=29106EB8-4981-4A14-87D1-AA745792C1B4&n=77ee6815&ind=2012112917&id=HJxdm073YYcz&ptnrS=HJxdm073YYcz&si=pconverter&searchfor=
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll [2014-09-09] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2013-10-01] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2014-08-13] (DivX, LLC)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @software602.cz/602XML Filler -> C:\Program Files\Software602\602XML\Filler\npfiller.dll [2011-11-24] (Software602 a.s.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2013-05-10] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2463987481-3256626589-3986830351-1009: @tools.google.com/Google Update;version=3 -> C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-2463987481-3256626589-3986830351-1009: @tools.google.com/Google Update;version=9 -> C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-04] (Google Inc.)
FF user.js: detected! => C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\user.js [2012-05-28]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2013-05-10] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2011-01-23] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2011-01-23] (Apple Inc.)
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\Ask.xml [2014-05-20]
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\bingp.xml [2013-04-18]
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\my-web-search.xml [2012-11-29]
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\Search_Results.xml [2013-01-17]
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\sweetim.xml [2012-11-04]
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\mall-cz.xml [2011-03-11]
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml [2013-10-04]
FF Extension: samfind Bookmarks Bar - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\extensions\sam@samfind.com [2013-10-03] [not signed]
FF Extension: No Name - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\extensions\4zffxtbr@VideoDownloadConverter_4z.com [2016-06-04] [not signed]
FF Extension: Ask New Tabs - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\extensions\{0AF2132C-D508-1D6C-F240-7AAAB6C9E66D} [2014-05-20] [not signed]
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-07-20] [not signed]
FF Extension: SweetPacks Toolbar for Firefox - C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi [2013-01-06] [not signed]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-11-20] [not signed]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-11-20] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-05] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-06-04]
FF HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\Firefox\Extensions: [{1650a312-02bc-40ee-977e-83f158701739}] - C:\Program Files\SiteAdvisor\6172\FF => not found
FF HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi => not found
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2013-10-25]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.search.ask.com/?o=APN10645A&gct=hp& ... 12-116&t=4"
CHR Session Restore: Default -> is enabled.
CHR Plugin: (Shockwave Flash) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll => No File
CHR Plugin: (Native Client) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\49.0.2623.112\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\49.0.2623.112\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npdrmv2.dll (Microsoft Corporation)
CHR Plugin: (Microsoft® DRM) - C:\Program Files\Windows Media Player\npwmsdrm.dll (Microsoft Corporation)
CHR Plugin: (Windows Media Player Plug-in Dynamic Link Library) - C:\Program Files\Windows Media Player\npdsplay.dll (Microsoft Corporation (written by Digital Renaissance Inc.))
CHR Plugin: (Google Update) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Update\1.3.21.123\npGoogleUpdate3.dll => No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (602XML Filler) - C:\Program Files\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll => No File
CHR Plugin: (Windows Presentation Foundation) - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (AdBlock) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-06-04]
CHR Extension: (Avast Online Security) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-04]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-04]
CHR HKLM\...\Chrome\Extension: [apgjagobplilmcdfelodhgefiidomnfl] - C:\Program Files\Inbox Toolbar\Chrome\ibxtoolbar_chr.crx <not found>
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-06-04]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: chrome.exe - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
StartMenuInternet: Google Chrome - C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 602XML Updater; C:\Program Files\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 ACS; C:\WINDOWS\system32\acs.exe [475220 2009-01-05] (Atheros) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-06-04] (AVAST Software)
S4 BUNAgentSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [16384 2008-03-03] (NewTech Infosystems, Inc.) [File not signed]
S4 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [61440 2007-01-17] (Hewlett-Packard Company) [File not signed]
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [131072 2008-04-04] () [File not signed]
S4 o2flash; C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe [65536 2007-02-13] (O2Micro International) [File not signed]
S4 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [657408 2009-10-27] (Nokia) [File not signed]
S4 Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 abp480n5; C:\WINDOWS\System32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation)
R3 AR5416; C:\WINDOWS\System32\DRIVERS\athw.sys [1346464 2008-12-29] (Atheros Communications, Inc.)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [32792 2016-06-04] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [91168 2016-06-04] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [64272 2016-06-04] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [58776 2016-06-04] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [815792 2016-06-04] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [449640 2016-06-04] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [187208 2016-06-04] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [67216 2016-06-04] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [221368 2016-06-04] (AVAST Software)
S3 AtiHdmiService; C:\WINDOWS\System32\drivers\AtiHdmi.sys [93696 2008-05-21] (ATI Research Inc.) [File not signed]
R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [539072 2007-03-23] (Broadcom Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37424 2007-03-23] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [876384 2007-03-31] (Broadcom Corporation.)
S3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [149123 2007-03-23] (Broadcom Corporation.)
S3 btwhid; C:\WINDOWS\System32\DRIVERS\btwhid.sys [55352 2007-03-31] (Broadcom Corporation.)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [67960 2007-03-23] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
S3 e1yexpress; C:\WINDOWS\System32\DRIVERS\e1y5132.sys [244368 2008-03-27] (Intel Corporation)
S3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [209664 2006-12-22] (Conexant Systems, Inc.)
S3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [988800 2006-12-22] (Conexant Systems, Inc.)
S3 IFXTPM; C:\WINDOWS\System32\DRIVERS\IFXTPM.SYS [41216 2008-05-08] (Infineon Technologies AG)
R2 Int15; C:\WINDOWS\System32\drivers\int15.sys [69632 2007-01-26] () [File not signed]
R3 Iviaspi; C:\WINDOWS\System32\drivers\iviaspi.sys [10368 2005-09-21] (InterVideo, Inc.) [File not signed]
R3 k57w2k; C:\WINDOWS\System32\DRIVERS\k57xp32.sys [186880 2008-09-03] (Broadcom Corporation)
S3 KMWDFILTER; C:\WINDOWS\System32\DRIVERS\KMWDFILTER.sys [17408 2008-10-09] (Windows (R) Codename Longhorn DDK provider)
R3 MarvinBus; C:\WINDOWS\System32\DRIVERS\MarvinBus.sys [171008 2005-06-02] (Pinnacle Systems GmbH) [File not signed]
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 O2SCBUS; C:\WINDOWS\System32\DRIVERS\ozscr.sys [101848 2008-06-12] (O2Micro)
R1 PCLEPCI; C:\WINDOWS\system32\drivers\pclepci.sys [14165 2005-02-09] (Pinnacle Systems GmbH) [File not signed]
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 RSUSBSTOR; C:\WINDOWS\System32\Drivers\RTS5121.sys [158720 2008-10-07] (Realtek Semiconductor Corp.)
R3 WSIMD; C:\WINDOWS\System32\DRIVERS\wsimd.sys [57408 2008-02-08] (Atheros Communications, Inc.) [File not signed]
S3 ASAPIW2K; \??\C:\WINDOWS\system32\Drivers\asapiW2k.sys [X]
S3 NETw5x32; system32\DRIVERS\NETw5x32.sys [X]
S3 Rts516xIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 SNP2UVC; system32\DRIVERS\snp2uvc.sys [X]
S3 SymIM; system32\DRIVERS\SymIM.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
S3 upperdev; system32\DRIVERS\usbser_lowerflt.sys [X]
S3 USBCCID; system32\DRIVERS\Rts5161ccid.sys [X]
U1 WS2IFSL; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-06 08:31 - 2016-06-06 08:31 - 00000000 ____D C:\_OTM
2016-06-06 08:30 - 2016-06-06 08:23 - 00522240 _____ (OldTimer Tools) C:\Documents and Settings\Martina Martinkova\Plocha\OTM.exe
2016-06-05 21:02 - 2016-06-05 21:02 - 00019577 _____ C:\Documents and Settings\Martina Martinkova\Plocha\AdwCleaner[C1].txt
2016-06-05 20:57 - 2016-06-05 20:58 - 00000000 ____D C:\AdwCleaner
2016-06-05 20:55 - 2016-06-05 19:44 - 03677248 _____ C:\Documents and Settings\Martina Martinkova\Plocha\adwcleaner_5.119.exe
2016-06-05 18:37 - 2016-06-05 18:40 - 00084402 _____ C:\Documents and Settings\Martina Martinkova\Plocha\Addition.txt
2016-06-05 18:36 - 2016-06-06 08:37 - 00027949 _____ C:\Documents and Settings\Martina Martinkova\Plocha\FRST.txt
2016-06-05 18:36 - 2016-06-06 08:36 - 00000000 ____D C:\FRST
2016-06-05 18:35 - 2016-06-05 18:34 - 01735680 _____ (Farbar) C:\Documents and Settings\Martina Martinkova\Plocha\FRST.exe
2016-06-04 02:59 - 2016-06-04 03:01 - 00000000 ____D C:\WINDOWS\system32\config\RC Backup
2016-06-04 02:30 - 2016-06-04 02:30 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Plocha\NETGATE.Registry.Cleaner.v14.0.405.0-BEAN
2016-06-04 02:24 - 2016-06-04 02:24 - 00000000 ____D C:\WINDOWS\system32\oodag
2016-06-04 02:22 - 2016-06-04 02:22 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\O&O
2016-06-04 01:43 - 2016-06-04 01:43 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\OO Software
2016-06-04 01:42 - 2016-06-04 01:42 - 00000686 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2016-06-04 01:42 - 2016-06-04 01:42 - 00000000 ____D C:\Program Files\CCleaner
2016-06-04 01:42 - 2016-06-04 01:42 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\CCleaner
2016-06-04 01:33 - 2016-06-04 01:33 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Plocha\backups
2016-06-04 01:27 - 2016-06-04 01:27 - 00000000 __SHD C:\Documents and Settings\Administrator\PrivacIE
2016-06-04 01:23 - 2016-06-04 01:23 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Data aplikací\AVG
2016-06-04 01:23 - 2016-06-04 01:23 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\AVG
2016-06-04 01:17 - 2016-06-04 01:17 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Mozilla
2016-06-04 01:17 - 2016-06-04 01:17 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\Mozilla
2016-06-04 01:13 - 2016-06-04 01:13 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Data aplikací\AVAST Software
2016-06-04 01:12 - 2016-06-04 01:12 - 00001693 _____ C:\Documents and Settings\All Users\Plocha\Avast Free Antivirus.lnk
2016-06-04 01:12 - 2016-06-04 01:12 - 00000000 __HDC C:\WINDOWS\$NtUninstallWdf01009$
2016-06-04 01:12 - 2016-06-04 01:12 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy\AVAST Software
2016-06-04 01:12 - 2008-11-07 18:55 - 00016928 ____N (Microsoft Corporation) C:\WINDOWS\system32\spmsgXP_2k3.dll
2016-06-04 01:11 - 2016-06-06 08:36 - 00000388 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2016-06-04 01:11 - 2016-06-04 01:11 - 00815792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00449640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00334280 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2016-06-04 01:11 - 2016-06-04 01:11 - 00221368 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00187208 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00091168 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00067216 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00064272 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00058776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2016-06-04 01:11 - 2016-06-04 01:11 - 00052184 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2016-06-04 01:11 - 2016-06-04 01:11 - 00032792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2016-06-04 01:10 - 2016-06-04 01:10 - 00000000 ____D C:\Program Files\Nová složka
2016-06-04 01:06 - 2016-05-12 11:42 - 00388608 _____ (Trend Micro Inc.) C:\Documents and Settings\Martina Martinkova\Plocha\hijackthis.exe
2016-06-04 00:38 - 2016-06-04 00:38 - 00000000 ____D C:\Documents and Settings\Administrator\Data aplikací\Adobe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-06 08:37 - 2009-08-04 16:19 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Local Settings\Temp
2016-06-06 08:35 - 2014-01-30 22:21 - 00000492 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2016-06-06 08:35 - 2008-09-08 20:10 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2016-06-06 08:34 - 2014-03-24 19:59 - 00000248 _____ C:\WINDOWS\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
2016-06-06 08:34 - 2009-08-04 16:19 - 00004176 _____ C:\WINDOWS\ModemLog_Agere Systems HDA Modem.txt
2016-06-06 08:34 - 2008-09-08 20:10 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-06-06 08:33 - 2009-08-05 18:12 - 00524288 _____ C:\WINDOWS\system32\config\ACS.evt
2016-06-06 08:33 - 2009-08-04 16:19 - 00000178 ___SH C:\Documents and Settings\Martina Martinkova\ntuser.ini
2016-06-06 08:33 - 2009-08-04 16:19 - 00000000 ____D C:\Documents and Settings\Martina Martinkova
2016-06-06 08:33 - 2008-09-08 20:10 - 00032476 _____ C:\WINDOWS\SchedLgU.Txt
2016-06-06 08:32 - 2012-03-12 19:44 - 00000000 ____D C:\Documents and Settings\Áňulína\Local Settings\Temp
2016-06-06 08:31 - 2012-02-27 18:10 - 00000000 ____D C:\Documents and Settings\Anička\Local Settings\Temp
2016-06-06 08:31 - 2011-05-11 19:40 - 00001078 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2463987481-3256626589-3986830351-1009UA.job
2016-06-06 08:31 - 2008-09-08 20:10 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Temp
2016-06-06 08:30 - 2009-08-04 16:19 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Plocha
2016-06-06 08:29 - 2009-09-16 16:05 - 00000492 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{0B7D00A6-798F-4FF7-A1C1-E39533791E0A}.job
2016-06-05 21:44 - 2012-03-31 07:20 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-06-05 20:58 - 2008-09-08 19:41 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2016-06-05 20:58 - 2008-09-08 19:38 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2016-06-05 20:58 - 2008-09-08 19:38 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2016-06-05 16:57 - 2008-09-08 20:10 - 00000211 __RSH C:\boot.ini
2016-06-05 16:57 - 2008-09-08 19:28 - 00000582 _____ C:\WINDOWS\win.ini
2016-06-05 16:57 - 2008-07-10 04:29 - 00000240 _____ C:\WINDOWS\system.ini
2016-06-05 16:53 - 2009-08-04 16:19 - 00000000 __RHD C:\Documents and Settings\Martina Martinkova\Data aplikací
2016-06-05 16:48 - 2009-08-04 16:19 - 00000000 ___HD C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací
2016-06-04 20:36 - 2008-09-08 19:48 - 01183876 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-06-04 20:36 - 2008-09-08 19:48 - 00494042 _____ C:\WINDOWS\system32\perfh005.dat
2016-06-04 20:36 - 2008-09-08 19:48 - 00109542 _____ C:\WINDOWS\system32\perfc005.dat
2016-06-04 20:30 - 2008-07-10 04:29 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
2016-06-04 16:33 - 2013-01-17 16:11 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\iLivid
2016-06-04 15:42 - 2011-05-11 19:41 - 00002362 _____ C:\Documents and Settings\Martina Martinkova\Nabídka Start\Programy\Google Chrome.lnk
2016-06-04 15:42 - 2011-05-11 19:41 - 00002356 _____ C:\Documents and Settings\Martina Martinkova\Plocha\Google Chrome.lnk
2016-06-04 15:42 - 2009-08-04 16:19 - 00000000 ___RD C:\Documents and Settings\Martina Martinkova\Nabídka Start\Programy
2016-06-04 15:33 - 2012-03-22 17:18 - 00000000 ____D C:\WINDOWS\pss
2016-06-04 15:31 - 2011-05-11 19:40 - 00001026 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2463987481-3256626589-3986830351-1009Core.job
2016-06-04 11:09 - 2009-03-23 23:03 - 00003187 _____ C:\WINDOWS\wincmd.ini
2016-06-04 02:45 - 2013-09-26 07:16 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Data aplikací\Seznam.cz
2016-06-04 02:39 - 2012-12-11 22:55 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\TEMP
2016-06-04 02:38 - 2012-12-11 22:55 - 00000000 ____D C:\Program Files\Common Files\PC Tools
2016-06-04 02:37 - 2014-06-19 18:41 - 00000000 ____D C:\Program Files\Sweet Home 3D
2016-06-04 02:25 - 2008-07-10 02:38 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start
2016-06-04 01:55 - 2008-09-08 19:44 - 00000000 ___HD C:\WINDOWS\inf
2016-06-04 01:55 - 2008-09-08 19:14 - 00000000 ____D C:\WINDOWS\system32\ReinstallBackups
2016-06-04 01:50 - 2009-05-06 21:36 - 00000000 ____D C:\WINDOWS\Minidump
2016-06-04 01:35 - 2011-01-30 20:02 - 00000000 ____D C:\Program Files\Centauri
2016-06-04 01:34 - 2014-06-19 18:43 - 00065536 _____ C:\WINDOWS\system32\config\TuneUp.evt
2016-06-04 01:32 - 2012-11-30 17:00 - 00000000 ____D C:\Program Files\NortonInstaller
2016-06-04 01:27 - 2008-09-08 20:04 - 00000000 ____D C:\Documents and Settings\Administrator
2016-06-04 01:25 - 2009-12-16 03:05 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Norton
2016-06-04 01:23 - 2008-09-08 19:35 - 00000000 ___HD C:\Documents and Settings\Administrator\Local Settings\Data aplikací
2016-06-04 01:15 - 2012-11-14 16:23 - 00000000 ____D C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\Temp
2016-06-04 01:11 - 2012-03-22 20:40 - 00000000 ____D C:\Program Files\AVAST Software
2016-06-04 01:10 - 2010-04-27 21:04 - 00000000 ____D C:\Program Files\AVG
2016-06-04 01:07 - 2012-03-22 20:40 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2016-06-04 01:00 - 2008-09-08 20:10 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2016-06-04 00:43 - 2008-07-10 02:36 - 00002504 _____ C:\WINDOWS\system32\CONFIG.NT
2016-06-04 00:38 - 2008-09-08 19:38 - 00000000 __RHD C:\Documents and Settings\Administrator\Data aplikací

==================== Files in the root of some directories =======

2009-09-10 17:57 - 2014-06-02 19:57 - 0020992 _____ () C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-08-04 16:19 - 2009-08-04 16:19 - 0000138 _____ () C:\Documents and Settings\Martina Martinkova\Local Settings\Data aplikací\fusioncache.dat
2010-08-10 15:10 - 2014-09-10 18:01 - 0000952 ___SH () C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
2014-09-14 17:01 - 2014-09-14 17:01 - 0003865 _____ () C:\Documents and Settings\All Users\Data aplikací\lpm.dat

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Odvirované pc - pomalejší než předtím

#8 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {186c18d6-8b03-11de-943d-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {186c18d7-8b03-11de-943d-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {228aa30a-82ae-11de-9433-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {228aa30b-82ae-11de-9433-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {228aa30c-82ae-11de-9433-001f169596b8} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {48784602-a490-11de-9449-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {48784603-a490-11de-9449-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {49f17f3e-b028-11de-9455-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {49f17f3f-b028-11de-9455-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {703dc3eb-5537-11df-94e1-00242cd50c53} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {703dc3ec-5537-11df-94e1-00242cd50c53} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {b093fb10-8a6d-11de-943c-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {b093fb11-8a6d-11de-943c-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {c358eb34-5a5b-11df-94e4-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {c358eb35-5a5b-11df-94e4-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9ae-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9af-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9b0-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {cbacb9b1-4481-11df-94d9-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {ccb383ed-5230-11df-94dd-0017c47f128f} - F:\StartVMCLite.exe
HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\MountPoints2: {ccb38f68-5230-11df-94dd-0017c47f128f} - F:\StartVMCLite.exe
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL =
SearchScopes: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> {EEE6C360-6118-11DC-9C72-001320C79847} URL = hxxp://www.bing.com/search?FORM=UP21DF& ... =041813&q={searchTerms}&src=IE-SearchBox
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-10-09] (Skype Technologies S.A.)
C:\Program Files\Skype\Toolbars
Toolbar: HKU\S-1-5-21-2463987481-3256626589-3986830351-1009 -> No Name - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - No File
FF DefaultSearchEngine: Ask.com
FF DefaultSearchUrl:
FF SearchEngineOrder.1: Ask.com
FF SearchEngineOrder.3: Bing
FF SelectedSearchEngine: Ask.com
FF Homepage: hxxp://www.search.ask.com/?o=APN10645A& ... 12-116&t=4
FF Keyword.URL: hxxp://search.mywebsearch.com/mywebsear ... searchfor=
FF SearchPlugin: C:\Documents and Settings\Martina Martinkova\Data aplikací\Mozilla\Firefox\Profiles\a5sa9qwh.default\searchplugins\sweetim.xml [2012-11-04]
FF HKU\S-1-5-21-2463987481-3256626589-3986830351-1009\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\Documents and Settings\All Users\Data aplikací\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi => not found
S4 Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3275136 2013-10-09] (Skype Technologies S.A.)
U1 WS2IFSL; no ImagePath
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2463987481-3256626589-3986830351-1009UA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2463987481-3256626589-3986830351-1009Core.job
C:\Documents and Settings\All Users\Data aplikací\KGyGaAvL.sys
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Tony182
Návštěvník
Návštěvník
Příspěvky: 78
Registrován: 05 čer 2016 17:14

Re: Odvirované pc - pomalejší než předtím

#9 Příspěvek od Tony182 »

PC už je pryč, velmi děkuji za pomoc :thumbsup:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Odvirované pc - pomalejší než předtím

#10 Příspěvek od Rudy »

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno