Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Otevírání stránky traffic-media.co

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
craft
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 11 říj 2005 19:48

Otevírání stránky traffic-media.co

#1 Příspěvek od craft »

Prosím o kontrolu - Firefox stálé otevírá nový panel traffic-media.co (v ruštině)

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-07-2016 01
Ran by Jiri (administrator) on JIRI (12-07-2016 09:57:51)
Running from C:\Users\Jiri\Desktop
Loaded Profiles: UpdatusUser & Jiri (Available Profiles: UpdatusUser & Jiri)
Platform: Windows 8.1 (Update) (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
(DisplayLink Corp.) C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
(Intel® Corporation) C:\Program Files\Intel\CAM\bin\CAMService.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\avfaudiosw.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Condusiv Technologies) C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
(LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2016\Moldflow\bin\mitsijm.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\QuickControl\QuickControl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Password Manager\password_manager.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\Password Manager\pwm_ie_helper_desktop.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\Password Manager\pwm_ie_helper_metro.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\Password Manager\password_manager.exe
(Realtek Semiconductor Corp.) C:\Windows\RtsCM64.exe
(Akamai Technologies, Inc.) C:\Users\Jiri\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Jiri\AppData\Local\Akamai\netsession_win.exe
(otfaqsy Uolcexadka) C:\Users\Jiri\AppData\Roaming\ScreenShot\SSMaker.exe
() C:\Program Files (x86)\Lenovo\OneLink Dock\onelinkpromgn.exe
(Lenovo) C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Peer Connect\LenovoDiscoverySvc.exe
() C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Validity Sensors, Inc.) C:\Program Files\Lenovo Fingerprint Reader\ValBioService.exe
(Validity Sensors, Inc.) C:\Program Files\Lenovo Fingerprint Reader\SwipeMonitor.exe
() C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\tpknrres.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\x64\avfulsvr.exe
(Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_22_0_0_192.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_22_0_0_192.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [LenovoOptMouseUpdate] => C:\Program Files\Lenovo\HOTKEY\extapsup.exe [341448 2014-11-07] (Lenovo Group Limited)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-05] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [TpShocks] => C:\WINDOWS\system32\TpShocks.exe [556712 2015-10-30] (Lenovo.)
HKLM\...\Run: [LnvMobHotspotClient] => C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe [939976 2015-02-20] (Lenovo)
HKLM\...\Run: [PasswordManager] => C:\Program Files\Lenovo\Password Manager\password_manager.exe [1792800 2014-10-21] (Lenovo Group Limited)
HKLM\...\Run: [LMCSSTART1] => C:\Program Files\Lenovo\Communications Utility\lmcsctrl.exe [35856 2016-04-12] (Lenovo Corporation)
HKLM\...\Run: [LMCSSTART2] => C:\Program Files\Lenovo\Communications Utility\lmcsctrl.exe [35856 2016-04-12] (Lenovo Corporation)
HKLM\...\Run: [LMCSSTART3] => C:\Program Files\Lenovo\Communications Utility\lmcsctrl.exe [35856 2016-04-12] (Lenovo Corporation)
HKLM\...\Run: [RtsCM] => C:\WINDOWS\RTSCM64.EXE [147160 2013-06-19] (Realtek Semiconductor Corp.)
HKLM\...\Run: [PrnStatusMX] => C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe [1240064 2012-07-04] (Marvell Semiconductor, Inc.)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-09-16] (Intel Corporation)
HKLM-x32\...\Run: [Fastboot] => C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBConsole.exe [750320 2014-11-20] (Lenovo)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [24204648 2016-07-05] (Dropbox, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\Run: [Akamai NetSession Interface] => C:\Users\Jiri\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\Run: [SSMaker] => C:\Users\Jiri\AppData\Roaming\ScreenShot\SSMaker.exe [1709712 2016-07-08] (otfaqsy Uolcexadka)
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\Policies\Explorer: []
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\MountPoints2: {08bb5fef-a631-11e5-82be-4851b733ddb6} - "F:\Startme.exe"
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\MountPoints2: {6491909c-704a-11e4-8254-806e6f6e6963} - "D:\setup.EXE" /AUTORUN
AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [184048 2013-10-31] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\windows\SysWOW64\nvinit.dll => C:\windows\SysWOW64\nvinit.dll [156256 2013-10-31] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Jiri\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Jiri\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Jiri\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2013-02-08] (Autodesk, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.34.dll [2016-07-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Jiri\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Jiri\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Jiri\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2015-07-26]
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ThinkPad OneLink Dock Management.lnk [2014-11-20]
ShortcutTarget: ThinkPad OneLink Dock Management.lnk -> C:\Program Files (x86)\Lenovo\OneLink Dock\onelinkpromgn.exe ()
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 217.195.165.131 192.168.21.3
Tcpip\..\Interfaces\{C74BEC04-4350-45EC-9058-A33CE04D7EA5}: [DhcpNameServer] 217.195.165.131 192.168.21.3
Tcpip\..\Interfaces\{D6BE35EA-2DC6-47D5-978D-16DCD9F60FF6}: [DhcpNameServer] 192.168.1.254

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131125267129052957&GUID=7C5394D3-A112-4A36-AABF-AF3A07439F88
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131125267129074908&GUID=7C5394D3-A112-4A36-AABF-AF3A07439F88
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13-comm.msn.com/?pc=LNJB
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad
URLSearchHook: [S-1-5-21-575807751-3889215795-3316477289-1001] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-575807751-3889215795-3316477289-1002 -> DefaultScope {A29AE689-65D2-44F9-979B-41E88AE245BB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-575807751-3889215795-3316477289-1002 -> {A29AE689-65D2-44F9-979B-41E88AE245BB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-575807751-3889215795-3316477289-1002 -> {B16F599F-1754-4EA4-BB77-808146AD269F} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-07] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-07] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-07] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-07] (Oracle Corporation)
DPF: HKLM-x32 {D8950D0E-FCE7-4AE4-9370-7E4CFBC04362} hxxps://eportal.cssz.cz/fas/page/activexcab/webff_cs.cab

FireFox:
========
FF ProfilePath: C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\4cumyzf3.default-1464527530313
FF Homepage: hxxps://www.google.cz/
FF Session Restore: -> is enabled.
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_22_0_0_192.dll [2016-06-17] ()
FF Plugin: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-07] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_192.dll [2016-06-17] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1218158.dll [2015-05-07] (Adobe Systems, Inc.)
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2009-09-07] (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-07] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-07] (Oracle Corporation)
FF Plugin-x32: @software602.cz/602XML Filler -> C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll [2012-08-06] (Software602 a.s.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-27] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-575807751-3889215795-3316477289-1002: @kb-ext.cz/PKIComponent -> C:\Users\Jiri\AppData\Roaming\KB-ext\lib\x86\npPKIComponentNPAPI-kbext.dll [1749-10-20] (Komerční banka, a.s.)
FF Plugin HKU\S-1-5-21-575807751-3889215795-3316477289-1002: @kb-pkiapp.cz/PKIComponent -> C:\Users\Jiri\AppData\Roaming\KB-pkiapp\lib\x86\npPKIComponentNPAPI-kbpkiapp.dll [2015-05-20] (Komerční banka, a.s.)
FF Extension: Ghostery - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\19uzauu1.default\Extensions\firefox@ghostery.com.xpi [2016-05-29]
FF Extension: Session Manager - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\19uzauu1.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2016-05-29]
FF Extension: QuickJava - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\19uzauu1.default\Extensions\{E6C1199F-E687-42da-8C24-E7770CC3AE66}.xpi [2016-05-29]
FF Extension: Ghostery - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\4cumyzf3.default-1464527530313\Extensions\firefox@ghostery.com.xpi [2016-07-09]
FF Extension: Session Manager - C:\Users\Jiri\AppData\Roaming\Mozilla\Firefox\Profiles\4cumyzf3.default-1464527530313\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2016-05-29]
FF HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\Firefox\Extensions: [{F74D5734-46F5-4B16-96F0-1E7FBF41B750}] - C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12
FF Extension: ThinkVantage Password Manager - C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12 [2015-06-05] [not signed]

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lpdfbkehegfmedglgemnhbnpmfmioggj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [85344 2011-10-10] (Software602 a.s.)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [31192 2014-02-07] (Autodesk, Inc.)
R2 AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [566288 2016-04-12] (Lenovo Corporation)
R2 CAMService; C:\Program Files\Intel\CAM\bin\CAMService.exe [1243344 2014-09-03] (Intel® Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-05] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-05] (Dropbox, Inc.)
R2 DisplayLinkService; C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe [9954096 2014-04-01] (DisplayLink Corp.)
R2 ExpressCache; C:\Program Files\Condusiv Technologies\ExpressCache\ExpressCache.exe [828656 2013-11-19] (Condusiv Technologies)
R2 FastbootService; C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe [140016 2014-11-20] (Lenovo)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319096 2016-05-12] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-28] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-28] (Intel(R) Corporation)
S3 intelsba; C:\Program Files\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [54976 2013-09-25] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [619776 2015-01-15] (Lenovo)
R2 Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2023592 2015-09-25] (Lenovo Group Limited)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584664 2015-12-14] (LENOVO INCORPORATED.)
S3 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [631312 2016-04-12] (Lenovo Corporation)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [115184 2014-07-09] (Lenovo Group Limited)
R2 lnvDiscoveryWinSvc; C:\Program Files\Lenovo\Lenovo Peer Connect\LenovoDiscoverySvc.exe [22576 2014-02-21] (Lenovo)
S3 LnvHotSpotSvc; C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe [480712 2015-03-23] (Lenovo)
R2 LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [469720 2015-05-12] ()
S3 LSC.Services.SystemService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe [273232 2016-06-02] (Lenovo)
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [1872808 2015-11-28] (Maxthon)
R2 mitsijm2016; C:\Program Files\Autodesk\Inventor 2016\Moldflow\bin\mitsijm.exe [968480 2014-09-30] (Autodesk, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [265936 2014-10-29] ()
S2 QuickControlMasterSvc; C:\Program Files (x86)\Lenovo\QuickControl\QuickControlMasterSvc.exe [61232 2014-12-05] (Lenovo Group Limited)
R3 QuickControlService; C:\Program Files (x86)\Lenovo\QuickControl\QuickControlService.exe [328488 2014-12-05] (Lenovo Group Limited)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 ShareItSvc; C:\Program Files (x86)\Lenovo\SHAREit\Shareit.Service.exe [31176 2016-01-20] (SHAREit Technologies Co.Ltd)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [21536 2016-05-25] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7032080 2016-05-12] (TeamViewer GmbH)
R2 ValBioService; C:\Program Files\Lenovo Fingerprint Reader\ValBioService.exe [22776 2015-03-03] (Validity Sensors, Inc.)
R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [88400 2015-12-06] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3818704 2014-10-29] (Intel® Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2014-03-26] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1424184 2014-04-22] (Motorola Solutions, Inc.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [25840 2013-11-19] (Condusiv Technologies)
R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [117488 2013-11-19] (Condusiv Technologies)
R0 Fastboot; C:\Windows\System32\DRIVERS\fastboot.sys [65928 2014-11-20] (Windows (R) Win 7 DDK provider)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2011-10-24] (Huawei Technologies Co., Ltd.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [192456 2014-05-30] (Intel Corporation)
R0 IntelHSWPcc; C:\Windows\System32\drivers\IntelPcc.sys [77456 2013-08-19] (Intel Corporation)
S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [113280 2010-02-03] (ITE )
R3 LnvHIDHW; C:\Windows\System32\drivers\LnvHIDHW.sys [29496 2014-04-08] (Lenovo)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3482600 2014-11-17] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [418008 2013-06-24] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8244312 2013-06-19] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2014-11-11] (Synaptics Incorporated)
R1 SMIDriver; C:\Windows\System32\drivers\smi.sys [19664 2015-12-02] (Windows (R) Win 7 DDK provider)
S3 SWIX64; C:\Program Files (x86)\Lenovo\System Update\tvsuhd64.sys [32288 2016-05-25] (Lenovo Group Limited)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2013-08-22] (Microsoft Corporation)
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [127456 2016-03-04] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [205784 2016-03-04] (Oracle Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-07-12 09:57 - 2016-07-12 09:58 - 00031270 _____ C:\Users\Jiri\Desktop\FRST.txt
2016-07-12 09:57 - 2016-07-12 09:57 - 02390528 _____ (Farbar) C:\Users\Jiri\Desktop\FRST64.exe
2016-07-12 09:57 - 2016-07-12 09:57 - 00000000 ____D C:\FRST
2016-07-12 09:20 - 2016-07-12 09:20 - 00000000 ___SH C:\DkHyperbootSync
2016-07-12 08:59 - 2016-07-12 08:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-07-12 08:55 - 2016-07-12 08:55 - 00000000 ____D C:\AdwCleaner
2016-07-12 08:55 - 2016-07-12 08:44 - 03712064 _____ C:\Users\Jiri\Desktop\adwcleaner_5.201.exe
2016-07-11 21:39 - 2016-07-11 22:10 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-07-11 21:39 - 2016-07-11 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-07-11 21:39 - 2016-07-11 21:39 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-07-11 21:39 - 2016-07-11 21:39 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-07-11 21:39 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-07-11 21:39 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-07-11 21:39 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-07-11 19:39 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2016-07-11 19:36 - 2016-07-11 20:08 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-07-11 19:36 - 2016-07-11 19:36 - 00001414 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2016-07-11 19:36 - 2016-07-11 19:36 - 00001402 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2016-07-11 19:36 - 2016-07-11 19:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2016-07-11 19:36 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2016-07-11 19:35 - 2016-07-11 19:39 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-07-10 19:51 - 2016-07-10 19:53 - 00000000 ____D C:\Program Files\trend micro
2016-07-10 19:51 - 2016-07-10 19:51 - 00000000 ____D C:\rsit
2016-07-10 19:29 - 2016-07-10 19:29 - 00041042 _____ C:\Users\Jiri\Documents\cc_20160710_192901.reg
2016-07-10 19:29 - 2016-07-10 19:29 - 00011656 _____ C:\Users\Jiri\Documents\cc_20160710_192920.reg
2016-07-10 18:55 - 2016-07-10 20:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2016-07-10 11:37 - 2016-07-10 11:37 - 00000000 ____D C:\adb
2016-07-09 23:13 - 2016-07-09 23:13 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01007.Wdf
2016-07-09 23:13 - 2016-07-09 23:13 - 00000000 ____D C:\Program Files (x86)\Handset WinDriver
2016-07-09 23:13 - 2011-10-24 06:04 - 00223232 _____ (Huawei Technologies Co., Ltd.) C:\WINDOWS\system32\Drivers\hw_quusbmdm.sys
2016-07-09 23:13 - 2011-10-24 05:51 - 00116864 _____ (Huawei Technologies Co., Ltd.) C:\WINDOWS\system32\Drivers\hw_usbdev.sys
2016-07-09 23:13 - 2010-02-19 01:00 - 01533512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WUDFUpdate_01007.dll
2016-07-09 23:13 - 2010-02-19 01:00 - 01490656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01007.dll
2016-07-09 23:13 - 2010-02-19 01:00 - 01490656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdfCoInstaller01007.dll
2016-07-09 23:13 - 2010-02-19 01:00 - 00708168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinUSBCoInstaller.dll
2016-07-09 23:13 - 2010-02-19 01:00 - 00708168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WinUSBCoInstaller.dll
2016-07-09 10:38 - 2016-07-09 10:38 - 00000270 __RSH C:\Users\Jiri\ntuser.pol
2016-07-09 10:31 - 2016-07-11 22:03 - 00000000 ____D C:\Users\Jiri\AppData\Roaming\ScreenShot
2016-07-09 10:31 - 2016-07-09 10:31 - 00000270 __RSH C:\ProgramData\ntuser.pol
2016-07-09 10:28 - 2016-07-09 10:29 - 00000906 _____ C:\Users\Public\Desktop\Download setup.lnk
2016-06-27 01:17 - 2016-06-27 01:17 - 00000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-06-27 00:22 - 2016-06-27 00:22 - 00021713 _____ C:\Users\Jiri\Desktop\Inv160001.pdf
2016-06-26 09:45 - 2016-07-12 08:50 - 00000000 __SHD C:\Users\Jiri\IntelGraphicsProfiles
2016-06-26 09:45 - 2016-06-26 09:45 - 00000451 _____ C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2016-06-26 09:44 - 2016-06-30 00:24 - 00000000 ____D C:\WINDOWS\LastGood
2016-06-26 09:43 - 2016-05-12 09:55 - 22914040 _____ (Intel Corporation) C:\WINDOWS\system32\igdfcl64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 17846272 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdfcl32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 11051456 _____ (Intel Corporation) C:\WINDOWS\system32\igdumdim64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 08596480 _____ (Intel Corporation) C:\WINDOWS\system32\ig75icd64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 06593536 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig75icd32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 04382840 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv4_0.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 04379256 _____ (Intel Corporation) C:\WINDOWS\system32\Gfxv2_0.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 04024312 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiAAC64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 03802600 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2016-06-26 09:43 - 2016-05-12 09:55 - 02497568 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiVAD64.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 02035712 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 01995256 _____ (Intel Corporation) C:\WINDOWS\system32\igdrcl64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 01794560 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdrcl32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 01766904 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 01469936 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiSecureSourceFilter64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 01156000 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 01151840 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00959608 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUIEx.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00872432 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiWinNextAgent64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00680960 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDH.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00659448 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiAudioFilter64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00617984 _____ (Intel Corporation) C:\WINDOWS\system32\MetroIntelGenericUIFramework.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00616944 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiMux64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00545912 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyApp.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00545400 _____ (Intel Corporation) C:\WINDOWS\system32\DPTopologyAppv2_0.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00530552 _____ (Intel Corporation) C:\WINDOWS\system32\igfxEM.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00467696 _____ (Intel Corporation) C:\WINDOWS\system32\igdmd64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00433784 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUMS64.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00399992 _____ (Intel Corporation) C:\WINDOWS\system32\CustomModeApp.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00399480 _____ (Intel Corporation) C:\WINDOWS\system32\CustomModeAppv2_0.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00385536 _____ (Intel Corporation) C:\WINDOWS\system32\IntelOpenCL64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00380416 _____ (Intel Corporation) C:\WINDOWS\system32\igfxOSP.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00378824 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdmd32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00374784 _____ (Intel Corporation) C:\WINDOWS\system32\igdbcl64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00372856 _____ (Intel Corporation) C:\WINDOWS\system32\igfxTray.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00357880 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiSilenceFilter64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00330240 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdbcl32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00319096 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCUIService.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00316245 _____ C:\WINDOWS\system32\DisplayAudiox64.cab
2016-06-26 09:43 - 2016-05-12 09:55 - 00295424 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelOpenCL32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00293376 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDI.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00280696 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00264192 _____ C:\WINDOWS\system32\igfxCPL.cpl
2016-06-26 09:43 - 2016-05-12 09:55 - 00261120 _____ (Intel Corporation) C:\WINDOWS\system32\igfxLHM.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00247416 _____ (Intel Corporation) C:\WINDOWS\system32\igfxHK.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00229888 _____ C:\WINDOWS\system32\igdde64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00229664 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00223728 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiUtils64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00218112 _____ (Intel Corporation) C:\WINDOWS\system32\igfxDTCM.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00199168 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4425.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00199088 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00195192 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00194360 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00193536 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00191488 _____ C:\WINDOWS\SysWOW64\igdde32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00191476 _____ C:\WINDOWS\system32\resTHA.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00190960 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiDDEAgent64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00184036 _____ C:\WINDOWS\system32\resELL.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00179828 _____ C:\WINDOWS\system32\resRUS.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00171008 _____ C:\WINDOWS\system32\igdail64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00169368 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00165460 _____ C:\WINDOWS\system32\resARA.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00164948 _____ C:\WINDOWS\system32\resJPN.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00164884 _____ C:\WINDOWS\system32\resHEB.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00163840 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00160260 _____ C:\WINDOWS\system32\resHUN.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00160196 _____ C:\WINDOWS\system32\resFRA.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00158532 _____ C:\WINDOWS\system32\resKOR.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00158388 _____ C:\WINDOWS\system32\resDEU.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00158356 _____ C:\WINDOWS\system32\resITA.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00158148 _____ C:\WINDOWS\system32\resROM.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00158052 _____ C:\WINDOWS\system32\resESN.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00157652 _____ C:\WINDOWS\system32\resPLK.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00157492 _____ C:\WINDOWS\system32\resSKY.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00157332 _____ C:\WINDOWS\system32\resNLD.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00156708 _____ C:\WINDOWS\system32\resPTB.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00156628 _____ C:\WINDOWS\system32\resCSY.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00156596 _____ C:\WINDOWS\system32\resTRK.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00156420 _____ C:\WINDOWS\system32\resPTG.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00156280 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2016-06-26 09:43 - 2016-05-12 09:55 - 00155972 _____ C:\WINDOWS\system32\resFIN.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00155540 _____ C:\WINDOWS\system32\resHRV.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00155124 _____ C:\WINDOWS\system32\resSVE.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00154964 _____ C:\WINDOWS\system32\resSLV.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00154004 _____ C:\WINDOWS\system32\resNOR.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00153508 _____ C:\WINDOWS\system32\resDAN.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00152576 _____ C:\WINDOWS\SysWOW64\igdail32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00152164 _____ C:\WINDOWS\system32\resENU.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00150404 _____ C:\WINDOWS\system32\resCHT.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00149524 _____ C:\WINDOWS\system32\resCHS.cui
2016-06-26 09:43 - 2016-05-12 09:55 - 00141808 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiMCUMD64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00107504 _____ (Intel Corporation) C:\WINDOWS\system32\IntelWiDiLogServer64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00102912 _____ C:\WINDOWS\system32\IccLibDll_x64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00095232 _____ C:\WINDOWS\system32\igfxCUIServicePS.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00078336 _____ ( ) C:\WINDOWS\system32\igfxDHLibv2_0.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00072704 _____ (Khronos Group) C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00069120 _____ (Khronos Group) C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00068608 _____ ( ) C:\WINDOWS\system32\igfxDHLib.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00039424 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00019456 _____ ( ) C:\WINDOWS\system32\igfxDILibv2_0.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00019456 _____ ( ) C:\WINDOWS\system32\igfxDILib.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00018944 _____ ( ) C:\WINDOWS\system32\igfxEMLibv2_0.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00018944 _____ ( ) C:\WINDOWS\system32\igfxEMLib.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00013824 _____ ( ) C:\WINDOWS\system32\igfxLHMLib.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00013816 _____ ( ) C:\WINDOWS\system32\igfxLHMLibv2_0.dll
2016-06-26 09:43 - 2016-05-12 09:55 - 00002582 _____ C:\WINDOWS\system32\iglhxs64.vp
2016-06-26 09:43 - 2016-05-12 09:55 - 00000895 _____ C:\WINDOWS\system32\Gfxv2_0.exe.config
2016-06-26 09:43 - 2016-05-12 09:55 - 00000895 _____ C:\WINDOWS\system32\DPTopologyAppv2_0.exe.config
2016-06-26 09:43 - 2016-05-12 09:55 - 00000895 _____ C:\WINDOWS\system32\CustomModeAppv2_0.exe.config
2016-06-26 09:43 - 2016-05-12 09:55 - 00000889 _____ C:\WINDOWS\system32\Gfxv4_0.exe.config
2016-06-26 09:43 - 2016-05-12 09:55 - 00000889 _____ C:\WINDOWS\system32\DPTopologyApp.exe.config
2016-06-26 09:43 - 2016-05-12 09:55 - 00000889 _____ C:\WINDOWS\system32\CustomModeApp.exe.config
2016-06-26 09:39 - 2016-06-26 09:39 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-06-26 09:39 - 2016-03-13 21:32 - 00173744 _____ (Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
2016-06-26 09:39 - 2016-03-13 21:32 - 00081072 _____ (Lenovo.) C:\WINDOWS\system32\ibmpmctl.exe
2016-06-26 09:39 - 2016-03-13 21:32 - 00072784 _____ (Lenovo.) C:\WINDOWS\system32\Drivers\ibmpmdrv.sys
2016-06-26 09:39 - 2016-03-13 21:32 - 00050864 _____ (Lenovo.) C:\WINDOWS\system32\tpinspm.dll
2016-06-25 23:41 - 2016-06-25 23:41 - 00000000 ____D C:\Users\Jiri\AppData\Local\Tvsukernel
2016-06-22 09:57 - 2016-06-22 09:57 - 00169151 _____ C:\Users\Jiri\Desktop\1SDOC1706.pdf
2016-06-22 09:52 - 2016-06-22 10:11 - 02524825 _____ C:\Users\Jiri\Desktop\SDOC1706.pdf
2016-06-15 16:49 - 2016-05-12 20:38 - 00135336 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2016-06-15 16:49 - 2016-05-12 19:43 - 00115704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpapi.dll
2016-06-15 16:49 - 2016-05-12 18:17 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\polstore.dll
2016-06-15 16:49 - 2016-05-12 18:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\FwRemoteSvr.dll
2016-06-15 16:49 - 2016-05-12 18:07 - 01360896 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2016-06-15 16:49 - 2016-05-12 17:59 - 00398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPSECSVC.DLL
2016-06-15 16:49 - 2016-05-12 17:43 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\polstore.dll
2016-06-15 16:49 - 2016-05-12 17:37 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FwRemoteSvr.dll
2016-06-15 16:43 - 2016-05-21 19:28 - 25802752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-06-15 16:43 - 2016-05-21 18:57 - 20341248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-06-15 16:43 - 2016-05-21 00:09 - 00572416 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-06-15 16:43 - 2016-05-21 00:08 - 02895360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-06-15 16:43 - 2016-05-21 00:02 - 06051328 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-06-15 16:43 - 2016-05-20 23:57 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-06-15 16:43 - 2016-05-20 23:55 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2016-06-15 16:43 - 2016-05-20 23:54 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-06-15 16:43 - 2016-05-20 23:50 - 02287104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-06-15 16:43 - 2016-05-20 23:44 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-06-15 16:43 - 2016-05-20 23:29 - 13815808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-06-15 16:43 - 2016-05-20 23:27 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2016-06-15 16:43 - 2016-05-20 23:25 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2016-06-15 16:43 - 2016-05-20 23:25 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2016-06-15 16:43 - 2016-05-20 23:21 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2016-06-15 16:43 - 2016-05-20 23:21 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2016-06-15 16:43 - 2016-05-20 23:19 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-06-15 16:43 - 2016-05-20 23:16 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-06-15 16:43 - 2016-05-20 23:14 - 04610048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-06-15 16:43 - 2016-05-20 23:12 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2016-06-15 16:43 - 2016-05-20 23:11 - 15420928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-06-15 16:43 - 2016-05-20 23:11 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2016-06-15 16:43 - 2016-05-20 23:09 - 00693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-06-15 16:43 - 2016-05-20 23:09 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-06-15 16:43 - 2016-05-20 23:08 - 02055680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-06-15 16:43 - 2016-05-20 23:08 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-06-15 16:43 - 2016-05-20 23:06 - 02131968 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-06-15 16:43 - 2016-05-20 22:46 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-06-15 16:43 - 2016-05-20 22:42 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-06-15 16:43 - 2016-05-20 22:38 - 01310208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-06-15 16:43 - 2016-05-20 22:38 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-06-15 16:43 - 2016-05-20 22:34 - 01544192 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-06-15 16:43 - 2016-05-20 22:23 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-06-15 16:43 - 2016-05-18 07:31 - 00372568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-06-15 16:43 - 2016-05-18 07:31 - 00315224 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-06-15 16:43 - 2016-05-16 23:13 - 00563016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-06-15 16:43 - 2016-05-16 23:13 - 00397224 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2016-06-15 16:43 - 2016-05-16 23:13 - 00340872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2016-06-15 16:43 - 2016-05-16 23:13 - 00178008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-06-15 16:43 - 2016-05-14 01:09 - 04169216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-06-15 16:43 - 2016-05-14 01:07 - 00675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2016-06-15 16:43 - 2016-05-14 01:07 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2016-06-15 16:43 - 2016-05-14 01:06 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2016-06-15 16:43 - 2016-05-14 01:04 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-06-15 16:43 - 2016-05-14 00:34 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2016-06-15 16:43 - 2016-05-14 00:19 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-06-15 16:43 - 2016-05-13 23:58 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2016-06-15 16:43 - 2016-05-09 23:35 - 07075328 _____ (Microsoft Corporation) C:\WINDOWS\system32\glcndFilter.dll
2016-06-15 16:43 - 2016-05-09 22:56 - 05270016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glcndFilter.dll
2016-06-15 16:43 - 2016-05-09 22:45 - 07793152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-06-15 16:43 - 2016-05-09 22:23 - 05265920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-06-15 16:43 - 2016-05-06 17:45 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2016-06-15 16:43 - 2016-05-06 17:23 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2016-06-15 16:42 - 2016-05-19 01:15 - 01379040 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-06-15 16:42 - 2016-05-18 22:35 - 01097216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-06-15 16:42 - 2016-05-14 22:01 - 00363104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2016-06-15 16:42 - 2016-05-14 22:01 - 00320720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
2016-06-15 16:42 - 2016-05-14 01:07 - 00281088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2016-06-15 16:42 - 2016-05-13 23:58 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll
2016-06-15 16:42 - 2016-05-13 23:45 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-06-15 16:42 - 2016-05-13 23:35 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll
2016-06-15 16:42 - 2016-05-13 23:26 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-07-12 09:56 - 2015-06-05 10:46 - 00000914 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2016-07-12 09:46 - 2015-06-05 10:39 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-575807751-3889215795-3316477289-1002
2016-07-12 09:42 - 2015-06-17 22:48 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-07-12 09:41 - 2015-08-16 12:49 - 00000966 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-07-12 09:40 - 2015-07-19 15:30 - 00000892 _____ C:\Users\Jiri\Desktop\mrpjus.exe – zástupce.lnk
2016-07-12 09:40 - 2015-07-16 09:41 - 00000152 _____ C:\Users\Jiri\AppData\Roaming\varicad-work.ini
2016-07-12 08:59 - 2015-06-05 10:46 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-07-12 08:51 - 2014-11-20 03:26 - 832888832 ___SH C:\WINDOWS\lenovo_fastboot.img
2016-07-12 08:50 - 2015-08-16 12:49 - 00000962 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-07-12 08:50 - 2015-06-05 10:46 - 00000910 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2016-07-12 08:49 - 2015-06-05 19:42 - 00000000 ____D C:\ProgramData\Synaptics
2016-07-12 08:49 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-07-11 22:11 - 2014-11-20 03:10 - 00739924 _____ C:\WINDOWS\system32\perfh005.dat
2016-07-11 22:11 - 2014-11-20 03:10 - 00151610 _____ C:\WINDOWS\system32\perfc005.dat
2016-07-11 22:11 - 2014-03-18 11:53 - 01745984 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-07-11 22:11 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\Inf
2016-07-11 22:04 - 2015-06-14 12:57 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-11 19:39 - 2015-06-09 22:27 - 00000000 ____D C:\Program Files\Common Files\AV
2016-07-11 19:33 - 2015-06-05 13:57 - 00000000 ____D C:\Users\Jiri\AppData\Local\CrashDumps
2016-07-10 19:26 - 2015-08-23 11:34 - 00000000 ____D C:\WINDOWS\Minidump
2016-07-10 19:26 - 2015-06-27 08:46 - 00000000 ____D C:\Users\Jiri\AppData\Roaming\uTorrent
2016-07-10 19:26 - 2015-06-16 11:14 - 00000000 ____D C:\Users\Jiri\AppData\Roaming\TeamViewer
2016-07-10 15:31 - 2015-06-15 12:47 - 00000000 ____D C:\Users\Jiri\AppData\Roaming\vlc
2016-07-09 10:38 - 2015-06-05 10:32 - 00000000 ____D C:\Users\Jiri
2016-07-09 10:31 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2016-07-07 02:39 - 2015-07-04 22:31 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-07-06 22:04 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-07-06 01:40 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-07-05 18:27 - 2014-11-20 02:50 - 00000000 ____D C:\Users\UpdatusUser
2016-06-27 00:04 - 2015-06-05 10:33 - 00000000 ____D C:\Users\Jiri\AppData\Roaming\Adobe
2016-06-27 00:01 - 2014-11-20 03:25 - 00000000 ____D C:\ProgramData\Adobe
2016-06-26 09:45 - 2014-11-20 03:05 - 00019070 _____ C:\WINDOWS\system32\results.xml
2016-06-26 09:45 - 2014-11-20 02:50 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2016-06-26 09:45 - 2014-11-20 02:50 - 00000000 ____D C:\WINDOWS\system32\NV
2016-06-26 09:41 - 2015-06-05 10:47 - 00000018 _____ C:\WINDOWS\SysWOW64\taskSchedularLog.txt
2016-06-25 23:42 - 2016-05-02 18:52 - 00002112 _____ C:\Users\Public\Desktop\Lenovo Solution Center.lnk
2016-06-25 23:42 - 2014-11-20 03:25 - 00000000 ____D C:\WINDOWS\System32\Tasks\Lenovo
2016-06-25 23:42 - 2014-11-20 03:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo ThinkVantage Tools
2016-06-25 23:42 - 2014-11-20 03:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lenovo
2016-06-25 23:42 - 2014-11-20 03:21 - 00000000 ____D C:\WINDOWS\Downloaded Installations
2016-06-25 23:42 - 2014-11-20 02:52 - 00000000 ____D C:\Program Files\Lenovo
2016-06-25 23:40 - 2014-11-20 03:26 - 00000000 ____D C:\WINDOWS\System32\Tasks\TVT
2016-06-25 23:40 - 2014-11-20 02:51 - 00000000 ____D C:\Program Files (x86)\Lenovo
2016-06-25 23:40 - 2014-11-19 10:40 - 00000000 ____D C:\ProgramData\Lenovo
2016-06-21 22:31 - 2015-06-16 10:41 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-06-18 06:43 - 2013-08-22 17:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-06-17 19:42 - 2015-06-17 22:48 - 00003802 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-06-16 18:54 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2016-06-15 18:57 - 2013-08-22 16:44 - 00604992 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-06-15 18:11 - 2015-06-07 11:50 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-06-15 18:09 - 2015-06-07 11:49 - 142482544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-06-14 19:13 - 2013-08-22 17:38 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-06-14 19:13 - 2013-08-22 17:38 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2015-07-16 09:41 - 2016-07-12 09:40 - 0000152 _____ () C:\Users\Jiri\AppData\Roaming\varicad-work.ini
2015-06-10 00:02 - 2015-06-10 00:02 - 0007605 _____ () C:\Users\Jiri\AppData\Local\Resmon.ResmonCfg
2014-11-20 02:56 - 2014-11-20 02:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-06-05 13:58 - 2015-06-05 13:58 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2014-11-20 03:32 - 2014-11-20 03:32 - 0000107 _____ () C:\ProgramData\{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}.log
2014-11-20 03:30 - 2014-11-20 03:31 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2014-11-20 03:31 - 2014-11-20 03:32 - 0000110 _____ () C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log
2014-11-20 03:32 - 2014-11-20 03:32 - 0000115 _____ () C:\ProgramData\{D6E853EC-8960-4D44-AF03-7361BB93227C}.log

Some zero byte size files/folders:
==========================
C:\Windows\SysWOW64\dlumd10.dll
C:\Windows\SysWOW64\dlumd11.dll
C:\Windows\SysWOW64\dlumd9.dll
C:\Windows\System32\dlumd10.dll
C:\Windows\System32\dlumd11.dll
C:\Windows\System32\dlumd9.dll

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-07-04 08:36

==================== End of FRST.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Otevírání stránky traffic-media.co

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

craft
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 11 říj 2005 19:48

Re: Otevírání stránky traffic-media.co

#3 Příspěvek od craft »

ADW Cleaner napsal, že v počítači nejsou škodlivé kódy nebo tak něco.
LOG:
# AdwCleaner v5.201 - Log vytvořen 12/07/2016 v 21:40:44
# Aktualizováno 30/06/2016 by ToolsLib
# Databáze : 2016-07-12.1 [Server]
# Operační system : Windows 8.1 (X64)
# Uživatelské jméno : Jiri - JIRI
# Spuštěno z : C:\Users\Jiri\Desktop\adwcleaner_5.201.exe
# Nastavení : Sken
# Podpora : https://toolslib.net/forum

***** [ Služby ] *****


***** [ Složky ] *****


***** [ Soubory ] *****


***** [ DLL ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****


***** [ Naplánované úlohy ] *****


***** [ Registry ] *****


***** [ Prohlížeče ] *****


*************************

C:\AdwCleaner\AdwCleaner[S1].txt - [795 bytů] - [12/07/2016 08:55:48]
C:\AdwCleaner\AdwCleaner[S2].txt - [717 bytů] - [12/07/2016 21:40:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [789 bytů] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Otevírání stránky traffic-media.co

#4 Příspěvek od Rudy »

Toto je OK. Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\Policies\Explorer: []
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\MountPoints2: {08bb5fef-a631-11e5-82be-4851b733ddb6} - "F:\Startme.exe"
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\MountPoints2: {6491909c-704a-11e4-8254-806e6f6e6963} - "D:\setup.EXE" /AUTORUN
URLSearchHook: [S-1-5-21-575807751-3889215795-3316477289-1001] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-575807751-3889215795-3316477289-1002 -> DefaultScope {A29AE689-65D2-44F9-979B-41E88AE245BB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-575807751-3889215795-3316477289-1002 -> {A29AE689-65D2-44F9-979B-41E88AE245BB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-575807751-3889215795-3316477289-1002 -> {B16F599F-1754-4EA4-BB77-808146AD269F} URL =
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\ProgramData\DP45977C.lfl
C:\Windows\SysWOW64\dlumd10.dll
C:\Windows\SysWOW64\dlumd11.dll
C:\Windows\SysWOW64\dlumd9.dll
C:\Windows\System32\dlumd10.dll
C:\Windows\System32\dlumd11.dll
C:\Windows\System32\dlumd9.dll
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

craft
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 11 říj 2005 19:48

Re: Otevírání stránky traffic-media.co

#5 Příspěvek od craft »

Fix result of Farbar Recovery Scan Tool (x64) Version: 10-07-2016 01
Ran by Jiri (2016-07-12 23:23:30) Run:1
Running from C:\Users\Jiri\Desktop
Loaded Profiles: UpdatusUser & Jiri (Available Profiles: UpdatusUser & Jiri)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\Policies\Explorer: []
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\MountPoints2: {08bb5fef-a631-11e5-82be-4851b733ddb6} - "F:\Startme.exe"
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\...\MountPoints2: {6491909c-704a-11e4-8254-806e6f6e6963} - "D:\setup.EXE" /AUTORUN
URLSearchHook: [S-1-5-21-575807751-3889215795-3316477289-1001] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-575807751-3889215795-3316477289-1002 -> DefaultScope {A29AE689-65D2-44F9-979B-41E88AE245BB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-575807751-3889215795-3316477289-1002 -> {A29AE689-65D2-44F9-979B-41E88AE245BB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-575807751-3889215795-3316477289-1002 -> {B16F599F-1754-4EA4-BB77-808146AD269F} URL =
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\ProgramData\DP45977C.lfl
C:\Windows\SysWOW64\dlumd10.dll
C:\Windows\SysWOW64\dlumd11.dll
C:\Windows\SysWOW64\dlumd9.dll
C:\Windows\System32\dlumd10.dll
C:\Windows\System32\dlumd11.dll
C:\Windows\System32\dlumd9.dll
End
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => value removed successfully
"HKU\S-1-5-21-575807751-3889215795-3316477289-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{08bb5fef-a631-11e5-82be-4851b733ddb6}" => key removed successfully
HKCR\CLSID\{08bb5fef-a631-11e5-82be-4851b733ddb6} => key not found.
"HKU\S-1-5-21-575807751-3889215795-3316477289-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6491909c-704a-11e4-8254-806e6f6e6963}" => key removed successfully
HKCR\CLSID\{6491909c-704a-11e4-8254-806e6f6e6963} => key not found.
Could not restore Default URLSearchHook.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKU\S-1-5-21-575807751-3889215795-3316477289-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-575807751-3889215795-3316477289-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A29AE689-65D2-44F9-979B-41E88AE245BB}" => key removed successfully
HKCR\CLSID\{A29AE689-65D2-44F9-979B-41E88AE245BB} => key not found.
"HKU\S-1-5-21-575807751-3889215795-3316477289-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B16F599F-1754-4EA4-BB77-808146AD269F}" => key removed successfully
HKCR\CLSID\{B16F599F-1754-4EA4-BB77-808146AD269F} => key not found.
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully
C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
Could not move "C:\ProgramData\DP45977C.lfl" => Scheduled to move on reboot.
C:\Windows\SysWOW64\dlumd10.dll => moved successfully
C:\Windows\SysWOW64\dlumd11.dll => moved successfully
C:\Windows\SysWOW64\dlumd9.dll => moved successfully
C:\Windows\System32\dlumd10.dll => moved successfully
C:\Windows\System32\dlumd11.dll => moved successfully
C:\Windows\System32\dlumd9.dll => moved successfully

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2016-07-12 23:24:37)

"C:\ProgramData\DP45977C.lfl" => Could not move

==== End of Fixlog 23:24:37 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Otevírání stránky traffic-media.co

#6 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

craft
Návštěvník
Návštěvník
Příspěvky: 55
Registrován: 11 říj 2005 19:48

Re: Otevírání stránky traffic-media.co

#7 Příspěvek od craft »

Ta potvora (traffic-media.co) vyskakovala v nepravidelných intervalech dále, tak jsem odinstaloval původní antivir a podle doporučení na fóru instaloval AVAST+ZoneAlarm. Poinstalační scan nalezl "špatné" doplňky pro Firefox a po automatickém smazání promlém ustal. Takže snad vyřešeno.
Děkuji za pomoc.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Otevírání stránky traffic-media.co

#8 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno