Re: POmaly beh pc
Napsal: 23 bře 2017 11:25
ComboFix 17-03-21.01 - s 23.03.2017 11:30:45.1.8 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3557.2016 [GMT 1:00]
Spuštěný z: c:\users\s\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1451306107.bdinstall.bin
c:\programdata\Adobe\conhost.exe
c:\programdata\Adobe\explorer.exe
c:\programdata\Adobe\hansa.exe
c:\programdata\Adobe\rundll32.exe
c:\programdata\Adobe\wget.exe
c:\programdata\Adobe\winlogon.exe
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\kubaa\AppData\Roaming\12729244.tmp-shm
c:\users\kubaa\AppData\Roaming\12729244.tmp-wal
c:\users\kubaa\AppData\Roaming\12729244.tmp
c:\users\kubaa\AppData\Roaming\12736748.tmp-shm
c:\users\kubaa\AppData\Roaming\12736748.tmp-wal
c:\users\kubaa\AppData\Roaming\12736748.tmp
c:\users\kubaa\AppData\Roaming\12743456.tmp-shm
c:\users\kubaa\AppData\Roaming\12743456.tmp-wal
c:\users\kubaa\AppData\Roaming\12743456.tmp
c:\users\kubaa\AppData\Roaming\12750211.tmp-shm
c:\users\kubaa\AppData\Roaming\12750211.tmp-wal
c:\users\kubaa\AppData\Roaming\12750211.tmp
c:\users\kubaa\AppData\Roaming\12756794.tmp-shm
c:\users\kubaa\AppData\Roaming\12756794.tmp-wal
c:\users\kubaa\AppData\Roaming\12756794.tmp
c:\users\kubaa\AppData\Roaming\12763455.tmp-shm
c:\users\kubaa\AppData\Roaming\12763455.tmp-wal
c:\users\kubaa\AppData\Roaming\12763455.tmp
c:\users\kubaa\AppData\Roaming\12770148.tmp-shm
c:\users\kubaa\AppData\Roaming\12770148.tmp-wal
c:\users\kubaa\AppData\Roaming\12770148.tmp
c:\users\kubaa\AppData\Roaming\12771521.tmp-shm
c:\users\kubaa\AppData\Roaming\12771521.tmp-wal
c:\users\kubaa\AppData\Roaming\12771521.tmp
c:\users\kubaa\AppData\Roaming\12776871.tmp-shm
c:\users\kubaa\AppData\Roaming\12776871.tmp-wal
c:\users\kubaa\AppData\Roaming\12776871.tmp
c:\users\kubaa\AppData\Roaming\12784313.tmp-shm
c:\users\kubaa\AppData\Roaming\12784313.tmp-wal
c:\users\kubaa\AppData\Roaming\12784313.tmp
c:\users\kubaa\AppData\Roaming\12790740.tmp-shm
c:\users\kubaa\AppData\Roaming\12790740.tmp-wal
c:\users\kubaa\AppData\Roaming\12790740.tmp
c:\users\kubaa\AppData\Roaming\12797120.tmp-shm
c:\users\kubaa\AppData\Roaming\12797120.tmp-wal
c:\users\kubaa\AppData\Roaming\12797120.tmp
c:\users\kubaa\AppData\Roaming\12803594.tmp-shm
c:\users\kubaa\AppData\Roaming\12803594.tmp-wal
c:\users\kubaa\AppData\Roaming\12803594.tmp
c:\users\kubaa\AppData\Roaming\12809959.tmp-shm
c:\users\kubaa\AppData\Roaming\12809959.tmp-wal
c:\users\kubaa\AppData\Roaming\12809959.tmp
c:\users\kubaa\AppData\Roaming\12816402.tmp-shm
c:\users\kubaa\AppData\Roaming\12816402.tmp-wal
c:\users\kubaa\AppData\Roaming\12816402.tmp
c:\users\kubaa\AppData\Roaming\12822907.tmp-shm
c:\users\kubaa\AppData\Roaming\12822907.tmp-wal
c:\users\kubaa\AppData\Roaming\12822907.tmp
c:\users\kubaa\AppData\Roaming\12829335.tmp-shm
c:\users\kubaa\AppData\Roaming\12829335.tmp-wal
c:\users\kubaa\AppData\Roaming\12829335.tmp
c:\users\kubaa\AppData\Roaming\12835824.tmp-shm
c:\users\kubaa\AppData\Roaming\12835824.tmp-wal
c:\users\kubaa\AppData\Roaming\12835824.tmp
c:\users\kubaa\AppData\Roaming\12842423.tmp-shm
c:\users\kubaa\AppData\Roaming\12842423.tmp-wal
c:\users\kubaa\AppData\Roaming\12842423.tmp
c:\users\kubaa\AppData\Roaming\12848866.tmp-shm
c:\users\kubaa\AppData\Roaming\12848866.tmp-wal
c:\users\kubaa\AppData\Roaming\12848866.tmp
c:\users\kubaa\AppData\Roaming\12855527.tmp-shm
c:\users\kubaa\AppData\Roaming\12855527.tmp-wal
c:\users\kubaa\AppData\Roaming\12855527.tmp
c:\users\kubaa\AppData\Roaming\12862001.tmp-shm
c:\users\kubaa\AppData\Roaming\12862001.tmp-wal
c:\users\kubaa\AppData\Roaming\12862001.tmp
c:\users\kubaa\AppData\Roaming\12868974.tmp-shm
c:\users\kubaa\AppData\Roaming\12868974.tmp-wal
c:\users\kubaa\AppData\Roaming\12868974.tmp
c:\users\kubaa\AppData\Roaming\12875433.tmp-shm
c:\users\kubaa\AppData\Roaming\12875433.tmp-wal
c:\users\kubaa\AppData\Roaming\12875433.tmp
c:\users\kubaa\AppData\Roaming\12882063.tmp-shm
c:\users\kubaa\AppData\Roaming\12882063.tmp-wal
c:\users\kubaa\AppData\Roaming\12882063.tmp
c:\users\kubaa\AppData\Roaming\12888553.tmp-shm
c:\users\kubaa\AppData\Roaming\12888553.tmp-wal
c:\users\kubaa\AppData\Roaming\12888553.tmp
c:\users\kubaa\AppData\Roaming\12895541.tmp-shm
c:\users\kubaa\AppData\Roaming\12895541.tmp-wal
c:\users\kubaa\AppData\Roaming\12895541.tmp
c:\users\kubaa\AppData\Roaming\12902593.tmp-shm
c:\users\kubaa\AppData\Roaming\12902593.tmp-wal
c:\users\kubaa\AppData\Roaming\12902593.tmp
c:\users\kubaa\AppData\Roaming\12909503.tmp-shm
c:\users\kubaa\AppData\Roaming\12909503.tmp-wal
c:\users\kubaa\AppData\Roaming\12909503.tmp
c:\users\kubaa\AppData\Roaming\12915962.tmp-shm
c:\users\kubaa\AppData\Roaming\12915962.tmp-wal
c:\users\kubaa\AppData\Roaming\12915962.tmp
c:\users\kubaa\AppData\Roaming\12922420.tmp-shm
c:\users\kubaa\AppData\Roaming\12922420.tmp-wal
c:\users\kubaa\AppData\Roaming\12922420.tmp
c:\users\kubaa\AppData\Roaming\66908.tmp
c:\users\kubaa\AppData\Roaming\86658.tmp
c:\users\kubaa\AppData\Roaming\95847.tmp
c:\users\s\AppData\Local\MSGBOX.EXE
c:\windows\msdownld.tmp
c:\windows\system32\tmp4598.tmp
c:\windows\system32\tmp7734.tmp
c:\windows\system32\tmp7745.tmp
C:\Windupdt
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETHFDRV
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2017-02-23 do 2017-03-23 )))))))))))))))))))))))))))))))
.
.
2017-03-23 10:37 . 2017-03-23 10:37 -------- d-----w- c:\users\me\AppData\Local\temp
2017-03-23 10:37 . 2017-03-23 10:37 -------- d-----w- c:\users\kubaa\AppData\Local\temp
2017-03-23 10:37 . 2017-03-23 10:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-03-23 07:04 . 2017-03-23 07:04 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E89BDF05-000A-4623-8368-72AC59FA8CA8}\offreg.3940.dll
2017-03-23 05:13 . 2017-03-23 10:18 170200 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-03-23 05:13 . 2017-03-23 10:38 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2017-03-23 05:13 . 2017-03-23 05:13 -------- d-----w- c:\programdata\Malwarebytes
2017-03-23 05:13 . 2016-03-10 13:09 53120 ----a-w- c:\windows\system32\drivers\mwac.sys
2017-03-23 05:13 . 2016-03-10 13:08 126336 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2017-03-23 05:13 . 2016-03-10 13:08 24448 ----a-w- c:\windows\system32\drivers\mbam.sys
2017-03-22 18:08 . 2017-03-22 18:08 -------- d-----w- c:\users\s\AppData\Local\Apps
2017-03-22 18:08 . 2017-03-22 18:09 -------- d-----w- c:\users\s\AppData\Local\Deployment
2017-03-22 18:07 . 2017-03-22 18:07 -------- d-----w- c:\program files\Common Files\Java
2017-03-22 18:07 . 2017-03-22 18:07 95808 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2017-03-22 18:07 . 2017-03-22 18:07 -------- d-----w- c:\program files\Java
2017-03-22 17:58 . 2017-03-22 17:58 -------- d-----w- c:\program files\reports
2017-03-22 16:45 . 2017-03-22 16:45 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E89BDF05-000A-4623-8368-72AC59FA8CA8}\offreg.2436.dll
2017-03-22 16:34 . 2017-02-22 11:48 9992952 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E89BDF05-000A-4623-8368-72AC59FA8CA8}\mpengine.dll
2017-03-22 13:51 . 2017-03-22 16:41 -------- d-----w- C:\FRST
2017-03-22 12:19 . 2017-03-21 10:55 103424 ----a-w- c:\programdata\Microsoft\Phone Tools\CoreCon\12.0\addons\SDKFilesVer.dll
2017-03-20 16:57 . 2017-02-18 14:05 1331200 ----a-w- c:\windows\system32\appraiser.dll
2017-03-20 16:57 . 2017-02-22 23:29 71400 ----a-w- c:\windows\system32\CompatTelRunner.exe
2017-03-20 16:57 . 2017-02-22 23:24 971776 ----a-w- c:\windows\system32\aeinv.dll
2017-03-20 16:57 . 2017-02-18 14:05 505344 ----a-w- c:\windows\system32\generaltel.dll
2017-03-20 16:57 . 2016-12-31 15:36 442368 ----a-w- c:\windows\system32\devinv.dll
2017-03-20 16:57 . 2016-12-31 15:36 270848 ----a-w- c:\windows\system32\invagent.dll
2017-03-20 16:57 . 2016-12-31 15:36 212480 ----a-w- c:\windows\system32\centel.dll
2017-03-20 16:57 . 2016-12-31 15:36 183808 ----a-w- c:\windows\system32\aepic.dll
2017-03-20 16:57 . 2016-12-31 15:36 104960 ----a-w- c:\windows\system32\acmigration.dll
2017-03-20 12:19 . 2017-03-20 12:19 -------- d-----w- c:\programdata\SWCUTemp
2017-03-15 16:20 . 2017-03-20 12:52 -------- d-----w- c:\users\s\AppData\Roaming\SmartSteamEmu
2017-03-14 15:27 . 2017-03-20 12:52 -------- d-----w- c:\users\s\AppData\Roaming\vlc
2017-03-13 07:27 . 2017-03-13 10:39 -------- d-----w- c:\users\s\AppData\Roaming\Mount&Blade Warband
2017-03-06 15:02 . 2017-03-13 08:55 -------- d-----w- c:\program files\MK
2017-03-05 18:31 . 2017-03-05 18:31 -------- d-----w- C:\$AV_ASW
2017-03-05 18:25 . 2017-03-05 18:25 -------- d-----w- c:\users\s\AppData\Roaming\AVAST Software
2017-03-05 17:42 . 2017-03-05 18:26 -------- d-----w- c:\program files\AVAST Software
2017-03-01 22:01 . 2017-03-20 12:52 -------- d-----w- c:\program files\GTA San Andreas
2017-03-01 17:06 . 2017-03-01 17:06 -------- d-----w- c:\windows\IObit
2017-03-01 17:06 . 2017-03-04 15:01 -------- d-----w- c:\users\s\AppData\Roaming\IObit
2017-03-01 17:01 . 2017-03-01 17:01 -------- d-----w- c:\users\s\AppData\Roaming\Profiles
2017-02-24 00:07 . 2017-02-24 00:07 -------- d-----w- c:\windows\system32\{F18D63B5-F945-4736-825F-70129CBFE9C3}
2017-02-23 13:41 . 2017-02-23 13:41 -------- d-----w- c:\programdata\Apple
2017-02-22 12:08 . 2017-03-13 05:58 -------- d-----w- c:\users\s\AppData\Roaming\The Creative Assembly
2017-02-21 11:18 . 2017-02-21 11:18 -------- d-----w- c:\windows\system32\{9571F033-E27D-48CC-917F-4DC705F1B23A}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-03-22 13:12 . 2015-12-10 13:34 802904 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2017-03-22 13:12 . 2015-12-10 13:34 144472 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2017-02-09 16:14 . 2017-03-20 16:59 254464 ----a-w- c:\windows\system32\schannel.dll
2017-02-09 16:14 . 2017-03-20 16:59 141312 ----a-w- c:\windows\system32\rpchttp.dll
2017-01-24 14:31 . 2014-01-19 14:50 281688 ----a-w- c:\windows\system32\PnkBstrB.xtr
2017-01-24 14:29 . 2014-01-19 14:51 281688 ----a-w- c:\windows\system32\PnkBstrB.exe
2017-01-24 07:17 . 2014-01-19 14:51 281688 ----a-w- c:\windows\system32\PnkBstrB.ex0
2017-01-22 19:30 . 2014-01-19 14:51 138032 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2017-01-13 21:02 . 2015-02-14 21:37 395536 ----a-w- c:\windows\system32\EasyAntiCheat.exe
2017-01-09 21:45 . 2017-01-09 21:45 1243391 ----a-w- c:\windows\unins000.exe
2016-12-28 05:17 . 2016-12-29 18:50 475648 ----a-w- c:\programdata\Microsoft\Phone Tools\CoreCon\12.0\1042\NonSDKAddonLangVer.dll
2010-08-03 10:11 819200 --sha-w- c:\windows\System32\xvidcore.dll
2010-08-03 10:11 180224 --sha-w- c:\windows\System32\xvidvfw.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IEService"="c:\users\s\AppData\Local\Microsoft Windows\taskhost.exe" [2017-01-13 89600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2012-04-24 1433692]
"BeatsOSDApp"="c:\program files\IDT\WDM\beats.exe" [2011-08-24 30208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2016-12-12 587288]
.
c:\users\kubaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2017-1-9 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
.
[HKLM\~\startupfolder\C:^Users^kuba^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
path=c:\users\kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe RGB Color]
2014-06-30 07:10 105 ----a-w- c:\programdata\adobe\Color.vbs
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BeatsOSDApp]
2011-08-24 02:04 30208 ----a-w- c:\program files\IDT\WDM\beats.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2010-03-25 02:50 2516296 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
2010-04-02 09:18 1185112 ----a-w- c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
c:\users\s\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2012-10-23 08:25 3108480 ----a-w- c:\program files\DAEMON Tools Pro\DTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 17:36 30040 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MouseDriver]
2012-12-19 07:42 241152 ----a-w- c:\windows\System32\TiltWheelMouse.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvBackend]
2013-12-10 02:22 2279712 ----a-w- c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShadowPlay]
2013-12-10 02:15 982232 ----a-w- c:\windows\System32\nvspcap.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2016-12-12 18:21 587288 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
2012-04-24 18:38 1433692 ----a-w- c:\program files\IDT\WDM\sttray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB3MON]
2011-12-05 01:14 291096 ----a-w- c:\program files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2017-02-02 06:11 2143936 ----a-w- c:\users\s\AppData\Roaming\uTorrent\uTorrent.exe
.
2;2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files\IObit\LiveUpdate\LiveUpdate.exe [2015-08-06 2909472]
R3 BEService;BattlEye Service;c:\program files\Common Files\BattlEye\BEService.exe [2016-01-23 1056288]
R3 BRDriver;BRDriver;c:\programdata\BitRaider\BRDriver.sys [x]
R3 BRDriver_1_3_3_E02B25FC;BRDriver_1_3_3_E02B25FC;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver.sys [x]
R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe [2017-01-13 395536]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-01-31 102912]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2017-03-23 170200]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2016-05-15 5741064]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2011-12-05 13592]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2016-03-13 242240]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2011-12-08 423136]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-04-11 128280]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-04-11 161560]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-19 411936]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-04-11 363800]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys [2011-12-05 347928]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys [2011-12-05 788248]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2011-09-19 91760]
S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECI.sys [2012-04-11 46080]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
utcsvc REG_MULTI_SZ DiagTrack
Hecerry REG_MULTI_SZ Hecerry
bilibiliGroupEx REG_MULTI_SZ bilibili
apple_config REG_MULTI_SZ Apple_Cfg
WinSAPSvc REG_MULTI_SZ WinSAPSvc
WPDService REG_MULTI_SZ WPDTSrv
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2017-03-22 18:09 1319256 ----a-w- c:\program files\Google\Chrome\Application\57.0.2987.110\Installer\chrmstp.exe
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 85.132.180.62
.
.
------- Asociace souborů -------
.
inifile="%SystemRoot%\system32\NOTEPAD.EXE" %1
txtfile="%SystemRoot%\system32\NOTEPAD.EXE" %1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-InstallerLauncher - c:\program files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe
MSConfigStartUp-4StoryPrePatch - c:\program files\GameforgeLive\Games\CZE_ces\4Story\PrePatch.exe
MSConfigStartUp-AvastUI - c:\program files\AVAST Software\Avast\AvastUI.exe
MSConfigStartUp-cz.seznam.software - c:\users\s\AppData\Roaming\Seznam.cz\szninstall.exe
MSConfigStartUp-DivXMediaServer - c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
MSConfigStartUp-seznam-listicka-distribuce - c:\program files\Seznam.cz\distribution\szninstall.exe
MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe
MSConfigStartUp-Steam - c:\program files (x86)\Steam\steam.exe
HKLM_ActiveSetup-installed components - c:\program files\Crossbrowse\Crossbrowse\Application\39.6.2171.95\Installer\chrmstp.exe
AddRemove-1430740694_is1 - c:\gog games\Saints Row 3\unins000.exe
AddRemove-Medieval II - Total War_is1 - c:\program files\SEGA\Medieval II - Total War\unins000.exe
AddRemove-Mozilla Firefox 42.0 (x86 cs) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-MozillaMaintenanceService - c:\program files\Mozilla Maintenance Service\uninstall.exe
AddRemove-Need For Speed Hot Pursuit_is1 - c:\program files\Mr DJ\Need For Speed Hot Pursuit\Uninstall\unins000.exe
AddRemove-Need For Speed Most Wanted Black Edition_is1 - c:\program files\Mr DJ\Need For Speed Most Wanted Black Edition\Uninstall\unins000.exe
AddRemove-Splinter Cell Conviction_is1 - c:\program files\Mr DJ\Splinter Cell Conviction\Uninstall\unins000.exe
AddRemove-Tomb Raider GOTY_is1 - c:\program files\Mr DJ\Tomb Raider GOTY\Uninstall\unins000.exe
AddRemove-U25pcGVyRWxpdGUz_is1 - c:\program files\Sniper Elite 3\unins000.exe
AddRemove-{65BE85A8-13BB-4B4A-B1AF-EC6054292C00}_is1 - c:\program files\The Walking Dead Epizody 1-5\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\IDT\WDM\STacSV.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\conhost.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\taskhost.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\DAEMON Tools Pro\DTShellHlp.exe
.
**************************************************************************
.
Celkový čas: 2017-03-23 11:43:24 - počítač byl restartován
ComboFix-quarantined-files.txt 2017-03-23 10:43
.
Před spuštěním: Volných bajtů: 658 097 127 424
Po spuštění: Volných bajtů: 657 846 476 800
.
- - End Of File - - C9F7C9205F5DC52561857EA5F81146B7
A36C5E4F47E84449FF07ED3517B43A31
Microsoft Windows 7 Professional 6.1.7601.1.1250.420.1029.18.3557.2016 [GMT 1:00]
Spuštěný z: c:\users\s\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\1451306107.bdinstall.bin
c:\programdata\Adobe\conhost.exe
c:\programdata\Adobe\explorer.exe
c:\programdata\Adobe\hansa.exe
c:\programdata\Adobe\rundll32.exe
c:\programdata\Adobe\wget.exe
c:\programdata\Adobe\winlogon.exe
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Administrator\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\Guest\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\DJSs.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\gihecdmkdbidbaceiknlbajmmomnpeee\1.1\manifest.json
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\background.html
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\content.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\lsdb.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\MVXl.js
c:\users\HomeGroupUser$\AppData\Local\Torch\User Data\Default\Extensions\jpkandnmeoelnplgpbcdjdjmcahdbfpi\2.1\newtab.html
c:\users\kubaa\AppData\Roaming\12729244.tmp-shm
c:\users\kubaa\AppData\Roaming\12729244.tmp-wal
c:\users\kubaa\AppData\Roaming\12729244.tmp
c:\users\kubaa\AppData\Roaming\12736748.tmp-shm
c:\users\kubaa\AppData\Roaming\12736748.tmp-wal
c:\users\kubaa\AppData\Roaming\12736748.tmp
c:\users\kubaa\AppData\Roaming\12743456.tmp-shm
c:\users\kubaa\AppData\Roaming\12743456.tmp-wal
c:\users\kubaa\AppData\Roaming\12743456.tmp
c:\users\kubaa\AppData\Roaming\12750211.tmp-shm
c:\users\kubaa\AppData\Roaming\12750211.tmp-wal
c:\users\kubaa\AppData\Roaming\12750211.tmp
c:\users\kubaa\AppData\Roaming\12756794.tmp-shm
c:\users\kubaa\AppData\Roaming\12756794.tmp-wal
c:\users\kubaa\AppData\Roaming\12756794.tmp
c:\users\kubaa\AppData\Roaming\12763455.tmp-shm
c:\users\kubaa\AppData\Roaming\12763455.tmp-wal
c:\users\kubaa\AppData\Roaming\12763455.tmp
c:\users\kubaa\AppData\Roaming\12770148.tmp-shm
c:\users\kubaa\AppData\Roaming\12770148.tmp-wal
c:\users\kubaa\AppData\Roaming\12770148.tmp
c:\users\kubaa\AppData\Roaming\12771521.tmp-shm
c:\users\kubaa\AppData\Roaming\12771521.tmp-wal
c:\users\kubaa\AppData\Roaming\12771521.tmp
c:\users\kubaa\AppData\Roaming\12776871.tmp-shm
c:\users\kubaa\AppData\Roaming\12776871.tmp-wal
c:\users\kubaa\AppData\Roaming\12776871.tmp
c:\users\kubaa\AppData\Roaming\12784313.tmp-shm
c:\users\kubaa\AppData\Roaming\12784313.tmp-wal
c:\users\kubaa\AppData\Roaming\12784313.tmp
c:\users\kubaa\AppData\Roaming\12790740.tmp-shm
c:\users\kubaa\AppData\Roaming\12790740.tmp-wal
c:\users\kubaa\AppData\Roaming\12790740.tmp
c:\users\kubaa\AppData\Roaming\12797120.tmp-shm
c:\users\kubaa\AppData\Roaming\12797120.tmp-wal
c:\users\kubaa\AppData\Roaming\12797120.tmp
c:\users\kubaa\AppData\Roaming\12803594.tmp-shm
c:\users\kubaa\AppData\Roaming\12803594.tmp-wal
c:\users\kubaa\AppData\Roaming\12803594.tmp
c:\users\kubaa\AppData\Roaming\12809959.tmp-shm
c:\users\kubaa\AppData\Roaming\12809959.tmp-wal
c:\users\kubaa\AppData\Roaming\12809959.tmp
c:\users\kubaa\AppData\Roaming\12816402.tmp-shm
c:\users\kubaa\AppData\Roaming\12816402.tmp-wal
c:\users\kubaa\AppData\Roaming\12816402.tmp
c:\users\kubaa\AppData\Roaming\12822907.tmp-shm
c:\users\kubaa\AppData\Roaming\12822907.tmp-wal
c:\users\kubaa\AppData\Roaming\12822907.tmp
c:\users\kubaa\AppData\Roaming\12829335.tmp-shm
c:\users\kubaa\AppData\Roaming\12829335.tmp-wal
c:\users\kubaa\AppData\Roaming\12829335.tmp
c:\users\kubaa\AppData\Roaming\12835824.tmp-shm
c:\users\kubaa\AppData\Roaming\12835824.tmp-wal
c:\users\kubaa\AppData\Roaming\12835824.tmp
c:\users\kubaa\AppData\Roaming\12842423.tmp-shm
c:\users\kubaa\AppData\Roaming\12842423.tmp-wal
c:\users\kubaa\AppData\Roaming\12842423.tmp
c:\users\kubaa\AppData\Roaming\12848866.tmp-shm
c:\users\kubaa\AppData\Roaming\12848866.tmp-wal
c:\users\kubaa\AppData\Roaming\12848866.tmp
c:\users\kubaa\AppData\Roaming\12855527.tmp-shm
c:\users\kubaa\AppData\Roaming\12855527.tmp-wal
c:\users\kubaa\AppData\Roaming\12855527.tmp
c:\users\kubaa\AppData\Roaming\12862001.tmp-shm
c:\users\kubaa\AppData\Roaming\12862001.tmp-wal
c:\users\kubaa\AppData\Roaming\12862001.tmp
c:\users\kubaa\AppData\Roaming\12868974.tmp-shm
c:\users\kubaa\AppData\Roaming\12868974.tmp-wal
c:\users\kubaa\AppData\Roaming\12868974.tmp
c:\users\kubaa\AppData\Roaming\12875433.tmp-shm
c:\users\kubaa\AppData\Roaming\12875433.tmp-wal
c:\users\kubaa\AppData\Roaming\12875433.tmp
c:\users\kubaa\AppData\Roaming\12882063.tmp-shm
c:\users\kubaa\AppData\Roaming\12882063.tmp-wal
c:\users\kubaa\AppData\Roaming\12882063.tmp
c:\users\kubaa\AppData\Roaming\12888553.tmp-shm
c:\users\kubaa\AppData\Roaming\12888553.tmp-wal
c:\users\kubaa\AppData\Roaming\12888553.tmp
c:\users\kubaa\AppData\Roaming\12895541.tmp-shm
c:\users\kubaa\AppData\Roaming\12895541.tmp-wal
c:\users\kubaa\AppData\Roaming\12895541.tmp
c:\users\kubaa\AppData\Roaming\12902593.tmp-shm
c:\users\kubaa\AppData\Roaming\12902593.tmp-wal
c:\users\kubaa\AppData\Roaming\12902593.tmp
c:\users\kubaa\AppData\Roaming\12909503.tmp-shm
c:\users\kubaa\AppData\Roaming\12909503.tmp-wal
c:\users\kubaa\AppData\Roaming\12909503.tmp
c:\users\kubaa\AppData\Roaming\12915962.tmp-shm
c:\users\kubaa\AppData\Roaming\12915962.tmp-wal
c:\users\kubaa\AppData\Roaming\12915962.tmp
c:\users\kubaa\AppData\Roaming\12922420.tmp-shm
c:\users\kubaa\AppData\Roaming\12922420.tmp-wal
c:\users\kubaa\AppData\Roaming\12922420.tmp
c:\users\kubaa\AppData\Roaming\66908.tmp
c:\users\kubaa\AppData\Roaming\86658.tmp
c:\users\kubaa\AppData\Roaming\95847.tmp
c:\users\s\AppData\Local\MSGBOX.EXE
c:\windows\msdownld.tmp
c:\windows\system32\tmp4598.tmp
c:\windows\system32\tmp7734.tmp
c:\windows\system32\tmp7745.tmp
C:\Windupdt
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETHFDRV
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2017-02-23 do 2017-03-23 )))))))))))))))))))))))))))))))
.
.
2017-03-23 10:37 . 2017-03-23 10:37 -------- d-----w- c:\users\me\AppData\Local\temp
2017-03-23 10:37 . 2017-03-23 10:37 -------- d-----w- c:\users\kubaa\AppData\Local\temp
2017-03-23 10:37 . 2017-03-23 10:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-03-23 07:04 . 2017-03-23 07:04 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E89BDF05-000A-4623-8368-72AC59FA8CA8}\offreg.3940.dll
2017-03-23 05:13 . 2017-03-23 10:18 170200 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2017-03-23 05:13 . 2017-03-23 10:38 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2017-03-23 05:13 . 2017-03-23 05:13 -------- d-----w- c:\programdata\Malwarebytes
2017-03-23 05:13 . 2016-03-10 13:09 53120 ----a-w- c:\windows\system32\drivers\mwac.sys
2017-03-23 05:13 . 2016-03-10 13:08 126336 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2017-03-23 05:13 . 2016-03-10 13:08 24448 ----a-w- c:\windows\system32\drivers\mbam.sys
2017-03-22 18:08 . 2017-03-22 18:08 -------- d-----w- c:\users\s\AppData\Local\Apps
2017-03-22 18:08 . 2017-03-22 18:09 -------- d-----w- c:\users\s\AppData\Local\Deployment
2017-03-22 18:07 . 2017-03-22 18:07 -------- d-----w- c:\program files\Common Files\Java
2017-03-22 18:07 . 2017-03-22 18:07 95808 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2017-03-22 18:07 . 2017-03-22 18:07 -------- d-----w- c:\program files\Java
2017-03-22 17:58 . 2017-03-22 17:58 -------- d-----w- c:\program files\reports
2017-03-22 16:45 . 2017-03-22 16:45 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E89BDF05-000A-4623-8368-72AC59FA8CA8}\offreg.2436.dll
2017-03-22 16:34 . 2017-02-22 11:48 9992952 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E89BDF05-000A-4623-8368-72AC59FA8CA8}\mpengine.dll
2017-03-22 13:51 . 2017-03-22 16:41 -------- d-----w- C:\FRST
2017-03-22 12:19 . 2017-03-21 10:55 103424 ----a-w- c:\programdata\Microsoft\Phone Tools\CoreCon\12.0\addons\SDKFilesVer.dll
2017-03-20 16:57 . 2017-02-18 14:05 1331200 ----a-w- c:\windows\system32\appraiser.dll
2017-03-20 16:57 . 2017-02-22 23:29 71400 ----a-w- c:\windows\system32\CompatTelRunner.exe
2017-03-20 16:57 . 2017-02-22 23:24 971776 ----a-w- c:\windows\system32\aeinv.dll
2017-03-20 16:57 . 2017-02-18 14:05 505344 ----a-w- c:\windows\system32\generaltel.dll
2017-03-20 16:57 . 2016-12-31 15:36 442368 ----a-w- c:\windows\system32\devinv.dll
2017-03-20 16:57 . 2016-12-31 15:36 270848 ----a-w- c:\windows\system32\invagent.dll
2017-03-20 16:57 . 2016-12-31 15:36 212480 ----a-w- c:\windows\system32\centel.dll
2017-03-20 16:57 . 2016-12-31 15:36 183808 ----a-w- c:\windows\system32\aepic.dll
2017-03-20 16:57 . 2016-12-31 15:36 104960 ----a-w- c:\windows\system32\acmigration.dll
2017-03-20 12:19 . 2017-03-20 12:19 -------- d-----w- c:\programdata\SWCUTemp
2017-03-15 16:20 . 2017-03-20 12:52 -------- d-----w- c:\users\s\AppData\Roaming\SmartSteamEmu
2017-03-14 15:27 . 2017-03-20 12:52 -------- d-----w- c:\users\s\AppData\Roaming\vlc
2017-03-13 07:27 . 2017-03-13 10:39 -------- d-----w- c:\users\s\AppData\Roaming\Mount&Blade Warband
2017-03-06 15:02 . 2017-03-13 08:55 -------- d-----w- c:\program files\MK
2017-03-05 18:31 . 2017-03-05 18:31 -------- d-----w- C:\$AV_ASW
2017-03-05 18:25 . 2017-03-05 18:25 -------- d-----w- c:\users\s\AppData\Roaming\AVAST Software
2017-03-05 17:42 . 2017-03-05 18:26 -------- d-----w- c:\program files\AVAST Software
2017-03-01 22:01 . 2017-03-20 12:52 -------- d-----w- c:\program files\GTA San Andreas
2017-03-01 17:06 . 2017-03-01 17:06 -------- d-----w- c:\windows\IObit
2017-03-01 17:06 . 2017-03-04 15:01 -------- d-----w- c:\users\s\AppData\Roaming\IObit
2017-03-01 17:01 . 2017-03-01 17:01 -------- d-----w- c:\users\s\AppData\Roaming\Profiles
2017-02-24 00:07 . 2017-02-24 00:07 -------- d-----w- c:\windows\system32\{F18D63B5-F945-4736-825F-70129CBFE9C3}
2017-02-23 13:41 . 2017-02-23 13:41 -------- d-----w- c:\programdata\Apple
2017-02-22 12:08 . 2017-03-13 05:58 -------- d-----w- c:\users\s\AppData\Roaming\The Creative Assembly
2017-02-21 11:18 . 2017-02-21 11:18 -------- d-----w- c:\windows\system32\{9571F033-E27D-48CC-917F-4DC705F1B23A}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-03-22 13:12 . 2015-12-10 13:34 802904 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2017-03-22 13:12 . 2015-12-10 13:34 144472 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2017-02-09 16:14 . 2017-03-20 16:59 254464 ----a-w- c:\windows\system32\schannel.dll
2017-02-09 16:14 . 2017-03-20 16:59 141312 ----a-w- c:\windows\system32\rpchttp.dll
2017-01-24 14:31 . 2014-01-19 14:50 281688 ----a-w- c:\windows\system32\PnkBstrB.xtr
2017-01-24 14:29 . 2014-01-19 14:51 281688 ----a-w- c:\windows\system32\PnkBstrB.exe
2017-01-24 07:17 . 2014-01-19 14:51 281688 ----a-w- c:\windows\system32\PnkBstrB.ex0
2017-01-22 19:30 . 2014-01-19 14:51 138032 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2017-01-13 21:02 . 2015-02-14 21:37 395536 ----a-w- c:\windows\system32\EasyAntiCheat.exe
2017-01-09 21:45 . 2017-01-09 21:45 1243391 ----a-w- c:\windows\unins000.exe
2016-12-28 05:17 . 2016-12-29 18:50 475648 ----a-w- c:\programdata\Microsoft\Phone Tools\CoreCon\12.0\1042\NonSDKAddonLangVer.dll
2010-08-03 10:11 819200 --sha-w- c:\windows\System32\xvidcore.dll
2010-08-03 10:11 180224 --sha-w- c:\windows\System32\xvidvfw.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IEService"="c:\users\s\AppData\Local\Microsoft Windows\taskhost.exe" [2017-01-13 89600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2012-04-24 1433692]
"BeatsOSDApp"="c:\program files\IDT\WDM\beats.exe" [2011-08-24 30208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2016-12-12 587288]
.
c:\users\kubaa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2017-1-9 97680]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
.
[HKLM\~\startupfolder\C:^Users^kuba^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
backupExtension=.Startup
path=c:\users\kuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe RGB Color]
2014-06-30 07:10 105 ----a-w- c:\programdata\adobe\Color.vbs
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BeatsOSDApp]
2011-08-24 02:04 30208 ----a-w- c:\program files\IDT\WDM\beats.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2010-03-25 02:50 2516296 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenuEx]
2010-04-02 09:18 1185112 ----a-w- c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
c:\users\s\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2012-10-23 08:25 3108480 ----a-w- c:\program files\DAEMON Tools Pro\DTAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 17:36 30040 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MouseDriver]
2012-12-19 07:42 241152 ----a-w- c:\windows\System32\TiltWheelMouse.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvBackend]
2013-12-10 02:22 2279712 ----a-w- c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShadowPlay]
2013-12-10 02:15 982232 ----a-w- c:\windows\System32\nvspcap.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2016-12-12 18:21 587288 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
2012-04-24 18:38 1433692 ----a-w- c:\program files\IDT\WDM\sttray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB3MON]
2011-12-05 01:14 291096 ----a-w- c:\program files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2017-02-02 06:11 2143936 ----a-w- c:\users\s\AppData\Roaming\uTorrent\uTorrent.exe
.
2;2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
R2 LiveUpdateSvc;LiveUpdate;c:\program files\IObit\LiveUpdate\LiveUpdate.exe [2015-08-06 2909472]
R3 BEService;BattlEye Service;c:\program files\Common Files\BattlEye\BEService.exe [2016-01-23 1056288]
R3 BRDriver;BRDriver;c:\programdata\BitRaider\BRDriver.sys [x]
R3 BRDriver_1_3_3_E02B25FC;BRDriver_1_3_3_E02B25FC;c:\programdata\BitRaider\support\1.3.3\E02B25FC\BRDriver.sys [x]
R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 EasyAntiCheat;EasyAntiCheat;c:\windows\system32\EasyAntiCheat.exe [2017-01-13 395536]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-01-31 102912]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2017-03-23 170200]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2016-05-15 5741064]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hcs.sys [2011-12-05 13592]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2016-03-13 242240]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe [2011-12-08 423136]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-04-11 128280]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-04-11 161560]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-19 411936]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-04-11 363800]
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3hub.sys [2011-12-05 347928]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0;c:\windows\system32\DRIVERS\iusb3xhc.sys [2011-12-05 788248]
S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2011-09-19 91760]
S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECI.sys [2012-04-11 46080]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr fdrespub AppIDSvc QWAVE wcncsvc Mcx2Svc SensrSvc
utcsvc REG_MULTI_SZ DiagTrack
Hecerry REG_MULTI_SZ Hecerry
bilibiliGroupEx REG_MULTI_SZ bilibili
apple_config REG_MULTI_SZ Apple_Cfg
WinSAPSvc REG_MULTI_SZ WinSAPSvc
WPDService REG_MULTI_SZ WPDTSrv
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2017-03-22 18:09 1319256 ----a-w- c:\program files\Google\Chrome\Application\57.0.2987.110\Installer\chrmstp.exe
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 85.132.180.62
.
.
------- Asociace souborů -------
.
inifile="%SystemRoot%\system32\NOTEPAD.EXE" %1
txtfile="%SystemRoot%\system32\NOTEPAD.EXE" %1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-InstallerLauncher - c:\program files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe
MSConfigStartUp-4StoryPrePatch - c:\program files\GameforgeLive\Games\CZE_ces\4Story\PrePatch.exe
MSConfigStartUp-AvastUI - c:\program files\AVAST Software\Avast\AvastUI.exe
MSConfigStartUp-cz.seznam.software - c:\users\s\AppData\Roaming\Seznam.cz\szninstall.exe
MSConfigStartUp-DivXMediaServer - c:\program files\DivX\DivX Media Server\DivXMediaServer.exe
MSConfigStartUp-seznam-listicka-distribuce - c:\program files\Seznam.cz\distribution\szninstall.exe
MSConfigStartUp-Skype - c:\program files\Skype\Phone\Skype.exe
MSConfigStartUp-Steam - c:\program files (x86)\Steam\steam.exe
HKLM_ActiveSetup-installed components - c:\program files\Crossbrowse\Crossbrowse\Application\39.6.2171.95\Installer\chrmstp.exe
AddRemove-1430740694_is1 - c:\gog games\Saints Row 3\unins000.exe
AddRemove-Medieval II - Total War_is1 - c:\program files\SEGA\Medieval II - Total War\unins000.exe
AddRemove-Mozilla Firefox 42.0 (x86 cs) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-MozillaMaintenanceService - c:\program files\Mozilla Maintenance Service\uninstall.exe
AddRemove-Need For Speed Hot Pursuit_is1 - c:\program files\Mr DJ\Need For Speed Hot Pursuit\Uninstall\unins000.exe
AddRemove-Need For Speed Most Wanted Black Edition_is1 - c:\program files\Mr DJ\Need For Speed Most Wanted Black Edition\Uninstall\unins000.exe
AddRemove-Splinter Cell Conviction_is1 - c:\program files\Mr DJ\Splinter Cell Conviction\Uninstall\unins000.exe
AddRemove-Tomb Raider GOTY_is1 - c:\program files\Mr DJ\Tomb Raider GOTY\Uninstall\unins000.exe
AddRemove-U25pcGVyRWxpdGUz_is1 - c:\program files\Sniper Elite 3\unins000.exe
AddRemove-{65BE85A8-13BB-4B4A-B1AF-EC6054292C00}_is1 - c:\program files\The Walking Dead Epizody 1-5\unins000.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\IDT\WDM\STacSV.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\conhost.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\windows\system32\taskhost.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\program files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\DAEMON Tools Pro\DTShellHlp.exe
.
**************************************************************************
.
Celkový čas: 2017-03-23 11:43:24 - počítač byl restartován
ComboFix-quarantined-files.txt 2017-03-23 10:43
.
Před spuštěním: Volných bajtů: 658 097 127 424
Po spuštění: Volných bajtů: 657 846 476 800
.
- - End Of File - - C9F7C9205F5DC52561857EA5F81146B7
A36C5E4F47E84449FF07ED3517B43A31