Stránka 2 z 3

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 13 led 2014 21:45
od jurcja1
Složka bingdesktop, nelze smazat, je otevřena v jiném programu, píše. Není to systémová součást?
díval jsem se na log, vcelku amatérsky, jen se mi nezná a zeptám se na toto:

U3 iscFlash; \??\C:\Users\Jakub\AppData\Local\Temp\7zSCD98.tmp\iscflashx64.sys [x]
2014-01-08 11:21 - 2014-01-09 22:58 - 00000000 ____D C:\WINDOWS\LastGood
2014-01-13 21:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru

Jinak tady je log:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-01-2014 02
Ran by Jakub (administrator) on KUBA-SCHOOL on 13-01-2014 21:32:53
Running from C:\Users\Jakub\Desktop
Windows 8.1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Inventor 2014\Moldflow\bin\mitsijm.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Atheros) C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Flux Software LLC) C:\Users\Jakub\AppData\Local\FluxSoftware\Flux\flux.exe
(Autodesk, Inc.) C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Dropbox, Inc.) C:\Users\Jakub\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe
(QIP) C:\Program Files (x86)\QIP 2012\qip.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclUSBSrv64.exe
(Nokia) C:\Program Files (x86)\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Box Inc.) C:\Program Files\Box\Box Sync\SyncUpdaterService.exe
(Pepak) E:\Download\ytd-1.35\ytd.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20315_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(forum.viry.cz) C:\Users\Jakub\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13653208 2013-09-13] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM\...\Run: [ShadowPlay] - C:\WINDOWS\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [BoxSync] - c:\Program Files\Box\Box Sync\BoxSync.exe [12918720 2014-01-10] (Box, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [RadioController] - C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2014-01-12] (Dritek System Inc.)
HKLM-x32\...\Run: [LManager] - [x]
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Qualcomm®Atheros®))
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKCU\...\Run: [Appset Update] - C:\Users\Jakub\AppData\Local\Appset\AppsetUpdater\AppSetManager.exe [1340032 2013-09-30] ()
HKCU\...\Run: [IDMan] - C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3825232 2013-11-24] (Tonec Inc.)
HKCU\...\Run: [f.lux] - C:\Users\Jakub\AppData\Local\FluxSoftware\Flux\flux.exe [1016712 2013-10-16] (Flux Software LLC)
HKCU\...\Run: [Zoner Photo Studio Service 16] - C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe [27648 2013-12-13] ()
HKCU\...\Run: [] - [x]
HKCU\...\Run: [Autodesk Sync] - C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1317256 2013-08-12] (Autodesk, Inc.)
HKCU\...\Run: [avichannel] - C:\Program Files (x86)\Evaer\videochannel.exe [1752576 2013-11-14] (Evaer Technology)
HKCU\...\Policies\Explorer: []
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll [168616 2013-12-19] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll [141336 2013-12-19] (NVIDIA Corporation)
Startup: C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Jakub\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
SearchScopes: HKLM - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKCU - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL =
SearchScopes: HKCU - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL =
BHO: IDM integration (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: IDM integration (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.co ... 5.15.0.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{254019C0-65F2-4B47-A61D-83D39585447D}: [NameServer]208.67.222.222,208.67.220.220

FireFox:
========
FF ProfilePath: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default
FF user.js: detected! => C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\user.js
FF DefaultSearchEngine: ICQ Search
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Homepage: hxxp://www.seznam.cz/
FF Keyword.URL: hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.7&q=
FF NetworkProxy: "backup.ftp", "88.146.243.17"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.socks", "88.146.243.17"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "88.146.243.17"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "88.146.243.17"
FF NetworkProxy: "ftp_port", 8080
FF NetworkProxy: "http", "88.146.243.17"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "88.146.243.17"
FF NetworkProxy: "socks_port", 8080
FF NetworkProxy: "socks_version", 4
FF NetworkProxy: "ssl", "88.146.243.17"
FF NetworkProxy: "ssl_port", 8080
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin - c:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: @parallelgraphics.com/Cortona - C:\Program Files (x86)\Common Files\ParallelGraphics\Cortona\npcortona.dll (ParallelGraphics)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Jakub\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Jakub\AppData\Roaming\mozilla\plugins\npgtpo3dautoplugin.dll ()
FF SearchPlugin: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\abz-slovnik-cizich-slov.xml
FF SearchPlugin: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\icq-invisible-check.xml
FF SearchPlugin: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\qip-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\cs@dictionaries.addons.mozilla.org [2013-10-23]
FF Extension: HTTPS-Everywhere - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\https-everywhere@eff.org [2014-01-04]
FF Extension: Nokia Maps 3D browser plugin - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\maps@ovi.com [2013-10-23]
FF Extension: MinimizeToTray revived (MinTrayR) - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\mintrayr@tn123.ath.cx [2013-10-23]
FF Extension: IDM CC - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\mozilla_cc@internetdownloadmanager.com [2013-12-12]
FF Extension: NASA Night Launch - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\nasanightlaunch@example(2).com [2013-10-23]
FF Extension: Vista-aero - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}(2) [2013-10-23]
FF Extension: Flagfox - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b} [2014-01-02]
FF Extension: Garmin Communicator - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-01-02]
FF Extension: Flashblock - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2013-10-23]
FF Extension: Aero Fox - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}(2) [2013-10-23]
FF Extension: DownloadHelper - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-01-02]
FF Extension: myFireFox - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}(2) [2013-10-23]
FF Extension: QuickDrag - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\quickdrag@mozilla.ktechcomputing.com.xpi [2013-10-23]
FF Extension: Undo Closed Tabs Button - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\undoclosedtabsbutton@supernova00.biz.xpi [2014-01-02]
FF Extension: Image Zoom - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2014-01-02]
FF Extension: NoScript - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-10-23]
FF Extension: Fasterfox - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi [2014-01-02]
FF Extension: Adblock Plus - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-23]
FF Extension: Download Statusbar - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2014-01-02]
FF Extension: Tab Mix Plus - C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-10-23]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-11-06]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2013-11-24]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013-11-06]
FF HKCU\...\Firefox\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Jakub\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Jakub\AppData\Roaming\IDM\idmmzcc5 [2013-11-24]
FF HKCU\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Jakub\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\Jakub\AppData\Roaming\IDM\idmmzcc5 [2013-11-24]

==================== Services (Whitelisted) =================

U2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider)
U2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [12288 2012-12-13] (Autodesk, Inc.)
U2 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [21504 2013-12-26] (Box Inc.)
U3 CoordinatorServiceHost; C:\Program Files\SolidWorks Corp\SolidWorks (2)\swScheduler\DTSCoordinatorService.exe [76328 2013-09-21] (Dassault Systèmes SolidWorks Corp.)
U3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-23] (Acer Incorporated)
U2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET)
U2 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-22] (Acer Incorporated)
U2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-05-22] (ELAN Microelectronics Corp.)
U3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
U2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
U2 mitsijm2014; C:\Program Files\Autodesk\Inventor 2014\Moldflow\bin\mitsijm.exe [952608 2013-01-25] (Autodesk, Inc.)
U2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-23] (NTI Corporation)
U2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
U2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
U2 RfButtonDriverService; C:\WINDOWS\RfBtnSvc64.exe [96880 2014-01-12] (Dritek System INC.)
U3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [346872 2013-08-22] (Microsoft Corporation)
U3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23840 2013-08-22] (Microsoft Corporation)
U2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe [81536 2012-08-01] (Atheros)

==================== Drivers (Whitelisted) ====================

U0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
U3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.)
U3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
U3 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-10-23] (Disc Soft Ltd)
U1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [239320 2013-09-17] (ESET)
U0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [239296 2013-09-17] (ESET)
U1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [168256 2013-09-17] (ESET)
U2 epfw; C:\Windows\system32\DRIVERS\epfw.sys [220232 2013-09-17] (ESET)
U1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
U0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [62136 2013-09-17] (ESET)
U3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
U3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
U0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
U0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
U0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
U3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation)
U3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
U3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
U3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
U3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2014-01-12] (Dritek System Inc.)
U3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
U3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
U3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-08-28] (Synaptics Incorporated)
U0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
U3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
U0 vsock; C:\Windows\System32\drivers\vsock.sys [73296 2013-08-15] (VMware, Inc.)
U3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124256 2013-08-22] (Microsoft Corporation)
U3 iscFlash; \??\C:\Users\Jakub\AppData\Local\Temp\7zSCD98.tmp\iscflashx64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-13 21:32 - 2014-01-13 21:33 - 00027556 _____ C:\Users\Jakub\Desktop\FRST.txt
2014-01-13 21:32 - 2014-01-13 21:32 - 00000000 ____D C:\FRST
2014-01-13 21:31 - 2014-01-13 21:31 - 02075648 _____ (Farbar) C:\Users\Jakub\Desktop\FRST64.exe
2014-01-13 21:31 - 2014-01-13 21:31 - 00112640 _____ (forum.viry.cz) C:\Users\Jakub\Desktop\FRSTLauncher.exe
2014-01-13 15:28 - 2014-01-13 15:28 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-13 15:28 - 2014-01-13 15:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-13 15:28 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-01-13 15:02 - 2014-01-13 15:27 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-01-13 14:58 - 2014-01-13 14:58 - 00089304 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-01-13 14:57 - 2014-01-13 15:27 - 00000000 ____D C:\Users\Jakub\Desktop\mbar
2014-01-13 14:53 - 2014-01-13 14:56 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\Jakub\Desktop\mbam-setup.exe
2014-01-13 14:52 - 2014-01-13 14:55 - 12582688 _____ (Malwarebytes Corp.) C:\Users\Jakub\Desktop\mbar-1.07.0.1008.exe
2014-01-12 22:31 - 2014-01-12 22:33 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\lm
2014-01-12 22:31 - 2014-01-12 22:31 - 00284240 _____ (Dritek System Inc.) C:\WINDOWS\UnInstRfBtn.EXE
2014-01-12 22:31 - 2014-01-12 22:31 - 00026736 _____ (Dritek System Inc.) C:\WINDOWS\system32\Drivers\aPs2Kb2Hid.sys
2014-01-12 22:31 - 2014-01-12 22:31 - 00000186 _____ C:\WINDOWS\UnInstRfBtn.UNI
2014-01-12 22:31 - 2014-01-12 22:31 - 00000184 _____ C:\WINDOWS\LMv7.UNI
2014-01-12 22:31 - 2014-01-12 22:31 - 00000000 ____D C:\Program Files (x86)\RadioController
2014-01-12 22:31 - 2014-01-12 22:31 - 00000000 ____D C:\Program Files (x86)\Launch Manager
2014-01-12 22:30 - 2012-11-09 09:15 - 00284016 _____ (Dritek System Inc.) C:\WINDOWS\UNINSTLMv7.EXE
2014-01-12 22:13 - 2014-01-13 20:48 - 00072894 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-12 22:06 - 2014-01-12 22:06 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2014-01-12 22:06 - 2014-01-12 22:06 - 00000000 ____D C:\WINDOWS\system32\NV
2014-01-12 11:28 - 2014-01-12 11:28 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-12 11:28 - 2013-12-19 19:53 - 06671648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2014-01-12 11:28 - 2013-12-19 19:53 - 03490080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2014-01-12 11:28 - 2013-12-19 19:53 - 02559776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2014-01-12 11:28 - 2013-12-19 19:53 - 01065248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2014-01-12 11:28 - 2013-12-19 19:53 - 00922912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2014-01-12 11:28 - 2013-12-19 19:53 - 00386336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2014-01-12 11:28 - 2013-12-19 19:53 - 00067072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2014-01-12 11:28 - 2013-12-19 19:53 - 00063776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2014-01-12 11:28 - 2013-12-19 06:01 - 03539040 _____ C:\WINDOWS\system32\nvcoproc.bin
2014-01-12 11:27 - 2014-01-12 11:53 - 00000000 ____D C:\Users\Jakub\Desktop\vir
2014-01-12 11:15 - 2014-01-13 13:46 - 00000000 ____D C:\rsit
2014-01-12 11:15 - 2014-01-13 13:46 - 00000000 ____D C:\Program Files\trend micro
2014-01-12 11:14 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 18310112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 15877216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 15230352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2014-01-12 11:14 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvenc.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 03071656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvenc.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 02698272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6433221.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6433221.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 01436528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 01242400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 00168616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 00141336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2014-01-12 11:14 - 2013-12-19 21:33 - 00032544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2014-01-12 11:14 - 2013-12-19 21:33 - 00023754 _____ C:\WINDOWS\system32\nvinfo.pb
2014-01-09 22:54 - 2014-01-09 22:54 - 00000000 ____D C:\Users\Jakub\SystemRequirementsLab
2014-01-08 11:21 - 2014-01-09 22:58 - 00000000 ____D C:\WINDOWS\LastGood
2014-01-06 17:35 - 2014-01-06 17:35 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Malwarebytes
2014-01-06 17:35 - 2014-01-06 17:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-06 16:42 - 2014-01-06 16:42 - 00000000 ____D C:\Program Files (x86)\SysTools PDF Unlocker - v3.0 (Demo Version)
2014-01-02 15:18 - 2014-01-13 21:10 - 00000000 ____D C:\Users\Jakub\AppData\Local\Box Sync
2014-01-02 15:09 - 2014-01-02 15:09 - 00000000 ____D C:\Users\Jakub\Box Sync
2014-01-02 14:26 - 2014-01-02 14:26 - 00000000 ____D C:\Users\Jakub\AppData\Local\jwProgramy
2014-01-01 22:01 - 2014-01-01 22:01 - 00000000 ____D C:\Program Files (x86)\jwDuplFiles
2013-12-29 16:08 - 2013-12-29 16:08 - 00000000 ____D C:\Program Files\Box
2013-12-29 11:59 - 2013-12-29 12:19 - 01002728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinUSBCoInstaller2.dll
2013-12-27 21:56 - 2013-12-27 22:18 - 00000600 _____ C:\Users\Jakub\AppData\Roaming\winscp.rnd
2013-12-25 13:48 - 2013-12-25 13:48 - 00027760 _____ (Sony Ericsson Mobile Communications) C:\WINDOWS\system32\Drivers\ggsemc.sys
2013-12-25 13:48 - 2013-12-25 13:48 - 00014448 _____ (Sony Ericsson Mobile Communications) C:\WINDOWS\system32\Drivers\ggflt.sys
2013-12-25 13:47 - 2013-12-25 13:47 - 00000000 ____D C:\ProgramData\Sony Mobile
2013-12-25 13:46 - 2013-12-25 13:46 - 00000000 ____D C:\Program Files (x86)\Sony Mobile
2013-12-19 12:10 - 2013-12-19 12:10 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-12-19 12:10 - 2013-12-05 09:42 - 00039200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2013-12-19 12:10 - 2013-12-05 09:42 - 00032544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2013-12-15 09:23 - 2013-11-12 00:27 - 00701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-12-15 09:23 - 2013-11-12 00:24 - 00840704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-12-15 09:23 - 2013-11-08 11:26 - 00358896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2013-12-15 09:23 - 2013-11-08 05:28 - 13177344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2013-12-15 09:23 - 2013-11-08 05:26 - 11674624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2013-12-15 09:23 - 2013-11-08 04:14 - 00922624 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2013-12-15 09:23 - 2013-11-05 15:03 - 00637952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2013-12-15 09:23 - 2013-11-04 18:13 - 01530200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2013-12-15 09:23 - 2013-11-04 11:32 - 02570240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2013-12-15 09:23 - 2013-10-31 01:58 - 00372568 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2013-12-15 09:23 - 2013-10-31 01:42 - 07399256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2013-12-15 09:22 - 2013-11-12 00:41 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-12-15 09:22 - 2013-11-12 00:40 - 00249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-12-15 09:22 - 2013-11-11 03:48 - 00039768 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2013-12-15 09:22 - 2013-11-09 12:55 - 00325464 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2013-12-15 09:22 - 2013-11-09 07:37 - 01756160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2013-12-15 09:22 - 2013-11-09 06:56 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2013-12-15 09:22 - 2013-11-08 05:43 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2013-12-15 09:22 - 2013-11-08 05:16 - 00225792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2013-12-15 09:22 - 2013-11-08 05:15 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2013-12-15 09:22 - 2013-11-08 05:07 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbici.dll
2013-12-15 09:22 - 2013-11-08 04:41 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2013-12-15 09:22 - 2013-11-05 15:19 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2013-12-15 09:22 - 2013-11-05 14:57 - 00479744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2013-12-15 09:22 - 2013-11-05 14:33 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2013-12-15 09:22 - 2013-11-05 14:32 - 00744448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2013-12-15 09:22 - 2013-11-04 18:13 - 00382808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2013-12-15 09:22 - 2013-11-04 14:07 - 01843712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2013-12-15 09:22 - 2013-11-04 12:50 - 02143744 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2013-12-15 09:22 - 2013-11-04 03:28 - 01816576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2013-12-15 09:22 - 2013-11-04 02:30 - 01765376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2013-12-15 09:22 - 2013-11-01 12:39 - 00086872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2013-12-15 09:22 - 2013-11-01 07:08 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2013-12-15 09:22 - 2013-11-01 06:57 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2013-12-15 09:22 - 2013-10-31 01:33 - 01642016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2013-12-15 09:22 - 2013-10-31 01:33 - 01506680 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2013-12-15 09:22 - 2013-10-31 01:33 - 01476184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2013-12-15 09:22 - 2013-10-31 01:33 - 01345536 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2013-12-15 09:22 - 2013-10-26 02:54 - 00146776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\SerCx2.sys
2013-12-15 09:22 - 2013-10-24 10:31 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialMigrationHandler.dll
2013-12-15 09:22 - 2013-10-24 10:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredentialMigrationHandler.dll
2013-12-15 09:22 - 2013-10-17 12:21 - 02896896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2013-12-15 09:22 - 2013-10-17 11:36 - 02266624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2013-12-15 09:22 - 2013-10-05 15:21 - 02140888 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2013-12-15 09:22 - 2013-10-05 15:21 - 00516496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2013-12-15 09:22 - 2013-10-05 13:05 - 01765384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2013-12-15 09:22 - 2013-10-05 13:05 - 00406400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll

==================== One Month Modified Files and Folders =======

2014-01-13 21:33 - 2014-01-13 21:32 - 00027556 _____ C:\Users\Jakub\Desktop\FRST.txt
2014-01-13 21:33 - 2013-10-23 10:36 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-01-13 21:32 - 2014-01-13 21:32 - 00000000 ____D C:\FRST
2014-01-13 21:32 - 2013-10-23 10:40 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Skype
2014-01-13 21:31 - 2014-01-13 21:31 - 02075648 _____ (Farbar) C:\Users\Jakub\Desktop\FRST64.exe
2014-01-13 21:31 - 2014-01-13 21:31 - 00112640 _____ (forum.viry.cz) C:\Users\Jakub\Desktop\FRSTLauncher.exe
2014-01-13 21:29 - 2013-10-23 09:41 - 00003982 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{40AAA70A-6C71-45DE-9CC9-AB9A62BF0D7A}
2014-01-13 21:28 - 2013-10-22 22:47 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3183305281-3245747581-804917388-1002
2014-01-13 21:10 - 2014-01-02 15:18 - 00000000 ____D C:\Users\Jakub\AppData\Local\Box Sync
2014-01-13 21:02 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\sru
2014-01-13 20:48 - 2014-01-12 22:13 - 00072894 _____ C:\WINDOWS\WindowsUpdate.log
2014-01-13 19:25 - 2013-10-23 10:43 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\DMCache
2014-01-13 15:38 - 2013-11-14 16:17 - 00000605 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2014-01-13 15:28 - 2014-01-13 15:28 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-13 15:28 - 2014-01-13 15:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-13 15:27 - 2014-01-13 15:02 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-01-13 15:27 - 2014-01-13 14:57 - 00000000 ____D C:\Users\Jakub\Desktop\mbar
2014-01-13 14:58 - 2014-01-13 14:58 - 00089304 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-01-13 14:56 - 2014-01-13 14:53 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\Jakub\Desktop\mbam-setup.exe
2014-01-13 14:56 - 2013-10-23 10:55 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\esmska
2014-01-13 14:55 - 2014-01-13 14:52 - 12582688 _____ (Malwarebytes Corp.) C:\Users\Jakub\Desktop\mbar-1.07.0.1008.exe
2014-01-13 13:46 - 2014-01-12 11:15 - 00000000 ____D C:\rsit
2014-01-13 13:46 - 2014-01-12 11:15 - 00000000 ____D C:\Program Files\trend micro
2014-01-13 13:05 - 2013-10-23 10:43 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\IDM
2014-01-13 10:22 - 2013-10-23 10:29 - 00000000 ____D C:\Users\Jakub\AppData\Local\Adobe
2014-01-12 22:38 - 2013-10-23 10:47 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Dropbox
2014-01-12 22:38 - 2013-10-23 09:35 - 00000000 __RDO C:\Users\Jakub\SkyDrive
2014-01-12 22:33 - 2014-01-12 22:31 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\lm
2014-01-12 22:33 - 2013-10-23 13:41 - 00000000 ____D C:\ProgramData\VMware
2014-01-12 22:32 - 2013-08-22 15:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2014-01-12 22:32 - 2013-08-22 14:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2014-01-12 22:31 - 2014-01-12 22:31 - 00284240 _____ (Dritek System Inc.) C:\WINDOWS\UnInstRfBtn.EXE
2014-01-12 22:31 - 2014-01-12 22:31 - 00026736 _____ (Dritek System Inc.) C:\WINDOWS\system32\Drivers\aPs2Kb2Hid.sys
2014-01-12 22:31 - 2014-01-12 22:31 - 00000186 _____ C:\WINDOWS\UnInstRfBtn.UNI
2014-01-12 22:31 - 2014-01-12 22:31 - 00000184 _____ C:\WINDOWS\LMv7.UNI
2014-01-12 22:31 - 2014-01-12 22:31 - 00000000 ____D C:\Program Files (x86)\RadioController
2014-01-12 22:31 - 2014-01-12 22:31 - 00000000 ____D C:\Program Files (x86)\Launch Manager
2014-01-12 22:31 - 2012-11-28 09:47 - 00096880 _____ (Dritek System INC.) C:\WINDOWS\RfBtnSvc64.exe
2014-01-12 22:20 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2014-01-12 22:12 - 2013-10-23 08:43 - 01754102 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2014-01-12 22:12 - 2013-09-30 04:56 - 00742608 _____ C:\WINDOWS\system32\perfh005.dat
2014-01-12 22:12 - 2013-09-30 04:56 - 00152820 _____ C:\WINDOWS\system32\perfc005.dat
2014-01-12 22:06 - 2014-01-12 22:06 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2014-01-12 22:06 - 2014-01-12 22:06 - 00000000 ____D C:\WINDOWS\system32\NV
2014-01-12 21:16 - 2013-10-23 10:51 - 00000000 ____D C:\Users\Jakub\AppData\Local\CrashDumps
2014-01-12 19:06 - 2013-10-23 14:49 - 00000000 ____D C:\Users\Jakub\AppData\Local\Deployment
2014-01-12 16:29 - 2013-10-22 22:39 - 00000000 ___RD C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-12 11:53 - 2014-01-12 11:27 - 00000000 ____D C:\Users\Jakub\Desktop\vir
2014-01-12 11:28 - 2014-01-12 11:28 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-12 11:28 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Help
2014-01-12 11:28 - 2012-11-28 09:36 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2014-01-12 11:25 - 2013-10-23 10:31 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2014-01-12 11:25 - 2012-11-28 09:37 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2014-01-11 12:11 - 2013-10-23 10:55 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\vlc
2014-01-11 11:52 - 2013-11-17 13:06 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\VMware
2014-01-11 11:52 - 2013-11-17 13:06 - 00000000 ____D C:\Users\Jakub\AppData\Local\VMware
2014-01-10 21:10 - 2013-12-05 15:39 - 00007622 _____ C:\Users\Jakub\AppData\Local\Resmon.ResmonCfg
2014-01-10 19:13 - 2013-10-22 22:37 - 00000000 ____D C:\Users\Jakub\AppData\Local\Packages
2014-01-10 14:42 - 2013-10-23 21:01 - 00000000 ____D C:\Users\Jakub\AppData\Local\TempAdresářZálohySW
2014-01-09 23:02 - 2012-11-28 09:27 - 00016582 _____ C:\WINDOWS\system32\results.xml
2014-01-09 23:00 - 2013-10-23 08:33 - 00000000 ____D C:\Users\Jakub
2014-01-09 22:58 - 2014-01-08 11:21 - 00000000 ____D C:\WINDOWS\LastGood
2014-01-09 22:54 - 2014-01-09 22:54 - 00000000 ____D C:\Users\Jakub\SystemRequirementsLab
2014-01-09 21:55 - 2013-10-23 13:11 - 00000000 ____D C:\Users\Jakub\Desktop\potvrzení o platbách
2014-01-09 19:11 - 2013-10-23 16:40 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\SolidWorks
2014-01-08 12:01 - 2013-10-23 10:38 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\uTorrent
2014-01-06 17:35 - 2014-01-06 17:35 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Malwarebytes
2014-01-06 17:35 - 2014-01-06 17:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-06 16:42 - 2014-01-06 16:42 - 00000000 ____D C:\Program Files (x86)\SysTools PDF Unlocker - v3.0 (Demo Version)
2014-01-03 23:40 - 2013-10-23 13:10 - 00000000 ____D C:\Users\Jakub\Desktop\foto směs
2014-01-02 15:09 - 2014-01-02 15:09 - 00000000 ____D C:\Users\Jakub\Box Sync
2014-01-02 15:08 - 2013-11-08 19:22 - 00001480 _____ C:\Users\Jakub\AppData\Local\Adobe Uložit pro web 13.0 Prefs
2014-01-02 14:26 - 2014-01-02 14:26 - 00000000 ____D C:\Users\Jakub\AppData\Local\jwProgramy
2014-01-01 22:01 - 2014-01-01 22:01 - 00000000 ____D C:\Program Files (x86)\jwDuplFiles
2013-12-29 16:09 - 2013-12-05 21:30 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-29 16:08 - 2013-12-29 16:08 - 00000000 ____D C:\Program Files\Box
2013-12-29 12:19 - 2013-12-29 11:59 - 01002728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinUSBCoInstaller2.dll
2013-12-27 22:18 - 2013-12-27 21:56 - 00000600 _____ C:\Users\Jakub\AppData\Roaming\winscp.rnd
2013-12-26 20:06 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\system32\NDF
2013-12-26 12:55 - 2013-08-22 15:44 - 05203488 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-12-25 13:58 - 2013-10-25 20:47 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2013-12-25 13:48 - 2013-12-25 13:48 - 00027760 _____ (Sony Ericsson Mobile Communications) C:\WINDOWS\system32\Drivers\ggsemc.sys
2013-12-25 13:48 - 2013-12-25 13:48 - 00014448 _____ (Sony Ericsson Mobile Communications) C:\WINDOWS\system32\Drivers\ggflt.sys
2013-12-25 13:47 - 2013-12-25 13:47 - 00000000 ____D C:\ProgramData\Sony Mobile
2013-12-25 13:46 - 2013-12-25 13:46 - 00000000 ____D C:\Program Files (x86)\Sony Mobile
2013-12-23 15:43 - 2013-10-23 12:50 - 00000000 ____D C:\Program Files (x86)\Esmska
2013-12-23 11:56 - 2013-10-23 13:46 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft ICE
2013-12-19 21:50 - 2013-10-23 10:48 - 00000000 ____D C:\Users\Jakub\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-12-19 21:33 - 2014-01-12 11:14 - 30372640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 25257248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 22960416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 18310112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 18222008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 17560352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 15877216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 15230352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 12645664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2013-12-19 21:33 - 2014-01-12 11:14 - 11605752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 11554264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 09700224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 09657464 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 03132704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 03125024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvenc.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 03071656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 02947872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 02747680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvenc.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 02698272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 01884448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6433221.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 01511712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6433221.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 01436528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 01242400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 00882464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 00879392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 00852768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 00847648 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 00317472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 00266984 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 00168616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 00141336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2013-12-19 21:33 - 2014-01-12 11:14 - 00032544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2013-12-19 21:33 - 2014-01-12 11:14 - 00023754 _____ C:\WINDOWS\system32\nvinfo.pb
2013-12-19 19:53 - 2014-01-12 11:28 - 06671648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2013-12-19 19:53 - 2014-01-12 11:28 - 03490080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2013-12-19 19:53 - 2014-01-12 11:28 - 02559776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2013-12-19 19:53 - 2014-01-12 11:28 - 01065248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2013-12-19 19:53 - 2014-01-12 11:28 - 00922912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2013-12-19 19:53 - 2014-01-12 11:28 - 00386336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2013-12-19 19:53 - 2014-01-12 11:28 - 00067072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2013-12-19 19:53 - 2014-01-12 11:28 - 00063776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2013-12-19 12:10 - 2013-12-19 12:10 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2013-12-19 06:01 - 2014-01-12 11:28 - 03539040 _____ C:\WINDOWS\system32\nvcoproc.bin
2013-12-17 11:28 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\rescache
2013-12-16 21:06 - 2013-08-22 16:36 - 00000000 ___RD C:\WINDOWS\ToastData
2013-12-16 21:06 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\WinStore
2013-12-16 21:06 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\MediaViewer
2013-12-16 21:06 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\FileManager
2013-12-16 21:06 - 2013-08-22 16:36 - 00000000 ____D C:\WINDOWS\Camera
2013-12-16 10:42 - 2013-10-23 00:10 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-12-16 10:36 - 2013-10-23 00:10 - 90708896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\Jakub\AppData\Local\Temp\log4net.dll
C:\Users\Jakub\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Jakub\AppData\Local\Temp\SyncRestarter.exe
C:\Users\Jakub\AppData\Local\Temp\sync_upgrader.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Users\Jakub\SkyDrive:ms-properties
AlternateDataStreams: C:\Users\Jakub\Desktop\Studijni-Skupina-UPL06_EDIT5.png:com.dropbox.attributes

==================== Security Center ==================

AV: ESET Smart Security 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personální firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Jakub\Desktop" je 1127 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 14 led 2014 16:34
od vyosek
:arrow: U3 iscFlash; \??\C:\Users\Jakub\AppData\Local\Temp\7zSCD98.tmp\iscflashx64.sys [x] pozustatek po nejakem ovladaci

:arrow: C:\WINDOWS\LastGood a C:\WINDOWS\system32\sru soucasti systemu - nastroje na obnovu

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
    HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [] - [x]
    HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-09-05] (Adobe Systems Inc.)
    HKLM-x32\...\Run: [LManager] - [x]
    HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
    HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
    HKCU\...\Run: [Appset Update] - C:\Users\Jakub\AppData\Local\Appset\AppsetUpdater\AppSetManager.exe [1340032 2013-09-30] ()
    HKCU\...\Run: [IDMan] - C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3825232 2013-11-24] (Tonec Inc.)
    HKCU\...\Run: [Zoner Photo Studio Service 16] - C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe [27648 2013-12-13] ()
    HKCU\...\Run: [] - [x]
    HKCU\...\Policies\Explorer: [] 
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
    SearchScopes: HKLM - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
    SearchScopes: HKLM - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
    SearchScopes: HKLM-x32 - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
    SearchScopes: HKLM-x32 - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
    SearchScopes: HKCU - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL =
    SearchScopes: HKCU - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = 
    
    FF DefaultSearchEngine: ICQ Search
    FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
    FF NetworkProxy: "backup.ftp", "88.146.243.17"
    FF NetworkProxy: "backup.ftp_port", 8080
    FF NetworkProxy: "backup.socks", "88.146.243.17"
    FF NetworkProxy: "backup.socks_port", 8080
    FF NetworkProxy: "backup.ssl", "88.146.243.17"
    FF NetworkProxy: "backup.ssl_port", 8080
    FF NetworkProxy: "ftp", "88.146.243.17"
    FF NetworkProxy: "ftp_port", 8080
    FF NetworkProxy: "http", "88.146.243.17"
    FF NetworkProxy: "http_port", 8080
    FF NetworkProxy: "share_proxy_settings", true
    FF NetworkProxy: "socks", "88.146.243.17"
    FF NetworkProxy: "socks_port", 8080
    FF NetworkProxy: "socks_version", 4
    FF NetworkProxy: "ssl", "88.146.243.17"
    FF NetworkProxy: "ssl_port", 8080
    FF NetworkProxy: "type", 0
    FF SearchPlugin: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\icq-invisible-check.xml
    FF SearchPlugin: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\qip-search.xml
    FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
    
    U3 iscFlash; \??\C:\Users\Jakub\AppData\Local\Temp\7zSCD98.tmp\iscflashx64.sys [x]
    
    C:\ProgramData\Microsoft\BingDesktop
    2014-01-13 14:57 - 2014-01-13 15:27 - 00000000 ____D C:\Users\Jakub\Desktop\mbar
    2014-01-13 14:53 - 2014-01-13 14:56 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\Jakub\Desktop\mbam-setup.exe
    2014-01-13 14:52 - 2014-01-13 14:55 - 12582688 _____ (Malwarebytes Corp.) C:\Users\Jakub\Desktop\mbar-1.07.0.1008.exe
    C:\Users\Jakub\AppData\Local\Temp\log4net.dll
    C:\Users\Jakub\AppData\Local\Temp\NOSEventMessages.dll
    C:\Users\Jakub\AppData\Local\Temp\SyncRestarter.exe
    C:\Users\Jakub\AppData\Local\Temp\sync_upgrader.exe
    
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    
    Hosts:
    CMD: shutdown /r /f /t 2
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 14 led 2014 18:36
od jurcja1
Provedu jen se ještě zeptám. Vidím ve fixlistu části, které se primárně spouštějí po startu systému jako je prvky nvidia - experience, update atd. Internet download manager, což je download manager, který využívám. atd.. Co s tím FRST provede?, jen pro info. Děkuji.

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 14 led 2014 18:38
od vyosek
Pouzivate je pokazdy a ihned po startu?? FRST jen omezi jen jejich spousteni po startu = nabeh systemu tak bude rychlejsi...

Ja razim teorii ze po startu se ma spustit system, antivir a tim koncime. Co dal potrebuji si spustim.

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 14 led 2014 18:45
od jurcja1
Ano, ale mám to nastaveno takto:
Obrázek

S tím, že malwarebytes je tam teď pouze po instalaci a léčení.

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 14 led 2014 18:54
od vyosek
:arrow: MBAM neni potreba aby vubec bezel, je vhodny jen na jednorazovy sken = spustim, aktualizuji, proskenuju, vypnu

:arrow: Neco mate Disable, nevo Vam bezi, ten FRST to upravi - ono toto jeste CCleaner nema tak dobre vychytane

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 14 led 2014 19:04
od jurcja1
Takhle bych to chtěl mít, resp. to co je povoleno, aby se po startu spouštělo, jelikož to jsou služby, které primárně potřebuji mít spuštěny a využívám je. Tudíž aktuální fixlist upraví do následující podoby?

Obrázek

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 14 led 2014 20:20
od vyosek
:arrow: Oba ty update od NVIDIA jsou zbytecne, jelikoz jGPU pri vsem spusteni zjistuje verzi ovladace a neni tudiz nutne neustale monitororvat jeho aktualnost, nevydava se co hodinu

:arrow: Fixlist tedy bude mit tuto podobu

Kód: Vybrat vše

Start
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [LManager] - [x]
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKCU\...\Run: [Appset Update] - C:\Users\Jakub\AppData\Local\Appset\AppsetUpdater\AppSetManager.exe [1340032 2013-09-30] ()
HKCU\...\Run: [Zoner Photo Studio Service 16] - C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe [27648 2013-12-13] ()
HKCU\...\Run: [] - [x]
HKCU\...\Policies\Explorer: []

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
SearchScopes: HKLM - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM-x32 - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM-x32 - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKCU - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL =
SearchScopes: HKCU - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL =

FF DefaultSearchEngine: ICQ Search
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF NetworkProxy: "backup.ftp", "88.146.243.17"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.socks", "88.146.243.17"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "88.146.243.17"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "88.146.243.17"
FF NetworkProxy: "ftp_port", 8080
FF NetworkProxy: "http", "88.146.243.17"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "88.146.243.17"
FF NetworkProxy: "socks_port", 8080
FF NetworkProxy: "socks_version", 4
FF NetworkProxy: "ssl", "88.146.243.17"
FF NetworkProxy: "ssl_port", 8080
FF NetworkProxy: "type", 0
FF SearchPlugin: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\icq-invisible-check.xml
FF SearchPlugin: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\qip-search.xml
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK

U3 iscFlash; \??\C:\Users\Jakub\AppData\Local\Temp\7zSCD98.tmp\iscflashx64.sys [x]

C:\ProgramData\Microsoft\BingDesktop
2014-01-13 14:57 - 2014-01-13 15:27 - 00000000 ____D C:\Users\Jakub\Desktop\mbar
2014-01-13 14:53 - 2014-01-13 14:56 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\Jakub\Desktop\mbam-setup.exe
2014-01-13 14:52 - 2014-01-13 14:55 - 12582688 _____ (Malwarebytes Corp.) C:\Users\Jakub\Desktop\mbar-1.07.0.1008.exe
C:\Users\Jakub\AppData\Local\Temp\log4net.dll
C:\Users\Jakub\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Jakub\AppData\Local\Temp\SyncRestarter.exe
C:\Users\Jakub\AppData\Local\Temp\sync_upgrader.exe

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Hosts:
CMD: shutdown /r /f /t 2

End

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 14 led 2014 22:30
od jurcja1
Tady chyba od aplikace BoxSync po startu:
Obrázek


Tady fixlog:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-01-2014 02
Ran by Jakub at 2014-01-14 22:20:36 Run:2
Running from C:\Users\Jakub\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-08] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [LManager] - [x]
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673184 2013-07-03] (Disc Soft Ltd)
HKCU\...\Run: [Appset Update] - C:\Users\Jakub\AppData\Local\Appset\AppsetUpdater\AppSetManager.exe [1340032 2013-09-30] ()
HKCU\...\Run: [Zoner Photo Studio Service 16] - C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSService.exe [27648 2013-12-13] ()
HKCU\...\Run: [] - [x]
HKCU\...\Policies\Explorer: []

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
SearchScopes: HKLM - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKLM-x32 - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL = http://www.bing.com/search?q={searchTer ... &pc=MAARJS
SearchScopes: HKCU - DefaultScope {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL =
SearchScopes: HKCU - {C30384F3-1AC0-478C-A419-AD35E4C0C1D0} URL =

FF DefaultSearchEngine: ICQ Search
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF NetworkProxy: "backup.ftp", "88.146.243.17"
FF NetworkProxy: "backup.ftp_port", 8080
FF NetworkProxy: "backup.socks", "88.146.243.17"
FF NetworkProxy: "backup.socks_port", 8080
FF NetworkProxy: "backup.ssl", "88.146.243.17"
FF NetworkProxy: "backup.ssl_port", 8080
FF NetworkProxy: "ftp", "88.146.243.17"
FF NetworkProxy: "ftp_port", 8080
FF NetworkProxy: "http", "88.146.243.17"
FF NetworkProxy: "http_port", 8080
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "88.146.243.17"
FF NetworkProxy: "socks_port", 8080
FF NetworkProxy: "socks_version", 4
FF NetworkProxy: "ssl", "88.146.243.17"
FF NetworkProxy: "ssl_port", 8080
FF NetworkProxy: "type", 0
FF SearchPlugin: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\icq-invisible-check.xml
FF SearchPlugin: C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\qip-search.xml
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK

U3 iscFlash; \??\C:\Users\Jakub\AppData\Local\Temp\7zSCD98.tmp\iscflashx64.sys [x]

C:\ProgramData\Microsoft\BingDesktop
2014-01-13 14:57 - 2014-01-13 15:27 - 00000000 ____D C:\Users\Jakub\Desktop\mbar
2014-01-13 14:53 - 2014-01-13 14:56 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\Jakub\Desktop\mbam-setup.exe
2014-01-13 14:52 - 2014-01-13 14:55 - 12582688 _____ (Malwarebytes Corp.) C:\Users\Jakub\Desktop\mbar-1.07.0.1008.exe
C:\Users\Jakub\AppData\Local\Temp\log4net.dll
C:\Users\Jakub\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Jakub\AppData\Local\Temp\SyncRestarter.exe
C:\Users\Jakub\AppData\Local\Temp\sync_upgrader.exe

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

Hosts:
CMD: shutdown /r /f /t 2

End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NvBackend => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Nvtmru => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Acrobat Assistant 8.0 => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\LManager => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\Malwarebytes Anti-Malware => Value not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Appset Update => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Zoner Photo Studio Service 16 => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\ => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C30384F3-1AC0-478C-A419-AD35E4C0C1D0} => Key deleted successfully.
HKCR\CLSID\{C30384F3-1AC0-478C-A419-AD35E4C0C1D0} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{C30384F3-1AC0-478C-A419-AD35E4C0C1D0} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{C30384F3-1AC0-478C-A419-AD35E4C0C1D0} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C30384F3-1AC0-478C-A419-AD35E4C0C1D0} => Key deleted successfully.
HKCR\CLSID\{C30384F3-1AC0-478C-A419-AD35E4C0C1D0} => Key not found.
Firefox DefaultSearchEngine deleted successfully.
Firefox SelectedSearchEngine deleted successfully.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
Firefox Proxy settings were reset.
C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\icq-invisible-check.xml => Moved successfully.
C:\Users\Jakub\AppData\Roaming\Mozilla\Firefox\Profiles\a5sqwe0s.default\searchplugins\qip-search.xml => Moved successfully.
HKLM\Software\Wow6432Node\Mozilla\Thunderbird\Extensions\\msktbird@mcafee.com => Value deleted successfully.
iscFlash => Service not found.

"C:\ProgramData\Microsoft\BingDesktop" directory move:

C:\ProgramData\Microsoft\BingDesktop\BingCore\BingDesktopCore.dll => Moved successfully.
Could not move "C:\ProgramData\Microsoft\BingDesktop\BingCore\BingDesktopOverlays.dll" => Scheduled to move on reboot.
C:\ProgramData\Microsoft\BingDesktop\BingCore\temp\tmp942A.tmp => Moved successfully.
C:\ProgramData\Microsoft\BingDesktop\BingCore\temp\tmp9B21.tmp => Moved successfully.
C:\ProgramData\Microsoft\BingDesktop\BingCore\DesktopSearchCache\zepplauncher.mif => Moved successfully.
Could not move "C:\ProgramData\Microsoft\BingDesktop" directory. => Scheduled to move on reboot.

"C:\Users\Jakub\Desktop\mbar" => File/Directory not found.
"C:\Users\Jakub\Desktop\mbam-setup.exe" => File/Directory not found.
"C:\Users\Jakub\Desktop\mbar-1.07.0.1008.exe" => File/Directory not found.
C:\Users\Jakub\AppData\Local\Temp\log4net.dll => Moved successfully.
C:\Users\Jakub\AppData\Local\Temp\NOSEventMessages.dll => Moved successfully.
C:\Users\Jakub\AppData\Local\Temp\SyncRestarter.exe => Moved successfully.
C:\Users\Jakub\AppData\Local\Temp\sync_upgrader.exe => Moved successfully.
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= shutdown /r /f /t 2 =========


========= End of CMD: =========


=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-01-14 22:23:57)<=

C:\ProgramData\Microsoft\BingDesktop\BingCore\BingDesktopOverlays.dll => Is moved successfully.
C:\ProgramData\Microsoft\BingDesktop => Is moved successfully.

==== End of Fixlog ====

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 15 led 2014 16:51
od vyosek
:arrow: Fixlist ale neobsahoval zadny prikaz pro BoxSync, to bude chyba primo v nem

:arrow: Jak se chova jinak PC?

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 15 led 2014 17:04
od jurcja1
Ok, zkusím přeinstalovat, ale toto byl jeho soubor..
C:\Users\Jakub\AppData\Local\Temp\SyncRestarter.exe => Moved successfully.
Tento možná.
C:\Users\Jakub\AppData\Local\Temp\sync_upgrader.exe => Moved successfully.

Pc jinak v pořádku, takže asi vyřešeno, nebo mám ještě nějak postupovat?
Děkuji

EDIT: BoxSync přeinstalován, funguje.

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 16 led 2014 06:18
od vyosek
Tak jeste uklidime :James008:

:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner http://forum.viry.cz/viewtopic.php?t=7478
Panel èistiè
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 16 led 2014 11:55
od jurcja1
Hotovo.
Vše jede. Děkuji mnohokrát za věnovaný čas a pomoc s úspěšným koncem.

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 16 led 2014 16:15
od jurcja1
Nastal problém. Přestaly fungovat veškeré METRO aplikace ve windowsu. Aplikaci spustím, zobrazí se, ale nenačte a zavře se.

EDIT: Přidávám log z SFC scanu.

Re: Prosím pomoc Virus - jeden za druhým

Napsal: 17 led 2014 06:16
od vyosek
S Metrem bych se obratil na technickou podporu microsoftu