Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Divný Proces

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
kiko22
Návštěvník
Návštěvník
Příspěvky: 116
Registrován: 28 črc 2013 10:42

Divný Proces

#1 Příspěvek od kiko22 »

Dobry den

Dnes sa mi po zapnutí objavil takýto proces. Nikdy predtím som ho nevidel vo svojom ntb.

Je tam nejaká IP a_chrome

Ďakujem, kiko
Ďakujem, Kiko

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divný Proces

#2 Příspěvek od Rudy »

Zdravím!
Jak se ten proces jmenuje?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kiko22
Návštěvník
Návštěvník
Příspěvky: 116
Registrován: 28 črc 2013 10:42

Re: Divný Proces

#3 Příspěvek od kiko22 »

Ďakujem, Kiko

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divný Proces

#4 Příspěvek od Rudy »

Nějaká reklama, ne? Zkuste tento postup: http://forum.viry.cz/viewtopic.php?f=24&t=132509 .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kiko22
Návštěvník
Návštěvník
Příspěvky: 116
Registrován: 28 črc 2013 10:42

Re: Divný Proces

#5 Příspěvek od kiko22 »

Mozem to soustit aj v nudzovom rezime?
Bitdefender mi neda pokoj aj ked som vypol vsetky jeho stity

Edit:Uz nic, podarilo sa mi to spustit v normalnom
Naposledy upravil(a) kiko22 dne 21 říj 2013 19:19, celkem upraveno 1 x.
Ďakujem, Kiko

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divný Proces

#6 Příspěvek od Rudy »

Jistě.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kiko22
Návštěvník
Návštěvník
Příspěvky: 116
Registrován: 28 črc 2013 10:42

Re: Divný Proces

#7 Příspěvek od kiko22 »

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-10-2013
Ran by krist_000 (administrator) on KIKO on 21-10-2013 20:18:23
Running from C:\Users\krist_000\Desktop
Windows 8 (X64) OS Language: 041B
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(SODATSW spol. s .r.o.) C:\Program Files (x86)\StartW8\bin\StartW8Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
() C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
(A-Volute) C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
(Seiko Epson Corporation) C:\Windows\system32\EscSvc64.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
() C:\Program Files (x86)\Google\Update\Install\{78988A87-20A2-432F-B71C-5021610BCB41}\30.0.1599.101_30.0.1599.69_chrome_updater.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.69\Installer\setup.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(SODATSW spol. s r.o.) C:\Program Files (x86)\StartW8\bin\StartW8Button.exe
(SODATSW spol. s r. o.) C:\Program Files (x86)\StartW8\bin\StartW8Menu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Ashampoo Development GmbH & Co. KG) C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Microsoft Corporation) C:\Users\krist_000\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(ROCCAT GmbH) C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\krist_000\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13192848 2012-11-28] (Realtek Semiconductor)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2859344 2012-11-28] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Radio Manager] - C:\Program Files (x86)\SCM\Radio Manager.exe [403848 2012-09-13] (MSI)
HKLM\...\Run: [SCM] - C:\Program Files (x86)\SCM\SCM.exe [399776 2012-09-13] (MSI)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Ashampoo HDD-Control 2 Guard] - C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Guard.exe [3783592 2012-07-30] (Ashampoo Development GmbH & Co. KG)
HKLM\...\Run: [Bdagent] - C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1738968 2013-09-26] (Bitdefender)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Sony PC Companion] - C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [448736 2013-03-18] (Sony)
HKCU\...\Run: [Bitdefender Wallet Agent] - C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [564256 2013-09-26] (Bitdefender)
HKCU\...\Run: [Bitdefender Wallet Application Agent] - C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [621448 2013-09-18] (Bitdefender)
HKCU\...\Run: [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-09-14] (Apple Inc.)
HKCU\...\Run: [SkyDrive] - C:\Users\krist_000\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257136 2013-08-17] (Microsoft Corporation)
HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-09-15] (Apple Inc.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKLM-x32\...\Run: [Super-Charger] - C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [502328 2012-05-23] (MSI)
HKLM-x32\...\Run: [StartW8Button] - C:\Program Files (x86)\StartW8\bin\StartW8Button.exe [52224 2012-12-19] (SODATSW spol. s r.o.)
HKLM-x32\...\Run: [EEventManager] - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [RoccatKonePure] - C:\Program Files (x86)\ROCCAT\Kone Pure Mouse\KonePureMonitor.EXE [569040 2012-11-30] (ROCCAT GmbH)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [Razer Synapse] - C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [442200 2013-09-28] (Razer Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
BootExecute: autocheck autochk * bddel.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bitdefender Wallet - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll (Bitdefender)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF ProfilePath: C:\Users\krist_000\AppData\Roaming\Mozilla\Firefox\Profiles\gy9gugdw.default-1365923927922
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Bitdefender.com/PasswordManager;version=17.8 - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxnp.dll (Bitdefender)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\krist_000\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\atlas-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\azet-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\dunaj-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slovnik-sk.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\zoznam-sk.xml
FF Extension: tab - C:\Users\krist_000\AppData\Roaming\Mozilla\Firefox\Profiles\gy9gugdw.default-1365923927922\Extensions\tab@tim.er.xpi
FF Extension: No Name - C:\Users\krist_000\AppData\Roaming\Mozilla\Firefox\Profiles\gy9gugdw.default-1365923927922\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF HKLM\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: No Name - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman\
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [bdThunderbird@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\bdtbext
FF Extension: No Name - C:\Program Files\Bitdefender\Bitdefender\bdtbext

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Bitdefender 2014) - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxnp.dll (Bitdefender)
CHR Plugin: (Unity Player) - C:\Users\krist_000\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Extension: (Angry Birds) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0
CHR Extension: (Docs) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (FB Refresh) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdlfdaajmclngiomogmleihllaejcnni\2.1.0_0
CHR Extension: (YouTube) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Bitdefender Wallet) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccahoghmggldkcdjiebjkidpfongdfbl\17.16.0_0
CHR Extension: (Google Search) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Porsche) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg\3_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0
CHR Extension: (Gmail) - C:\Users\KRIST_~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx

==================== Services (Whitelisted) =================

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 AHDDC2; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [1518504 2012-07-30] ()
S4 BdDesktopParental; C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe [75584 2013-07-05] (Bitdefender)
S3 DfSdkS; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\DfSdkS64.exe [544768 2009-08-24] (mst software GmbH, Germany)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-11-28] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2012-09-13] (Micro-Star International Co., Ltd.)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [142904 2012-05-23] (MSI)
R2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [853288 2007-09-20] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-09-20] (Nero AG)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [201360 2012-11-28] (Realtek Semiconductor)
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [106472 2013-09-18] (Razer Inc.)
R2 RzMaelstromVADStreamingService; C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzMaelstromVADStreamingService.exe [4241920 2013-09-18] (A-Volute)
S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
R2 StartW8Service; C:\Program Files (x86)\StartW8\bin\StartW8Service.exe [51200 2012-12-19] (SODATSW spol. s .r.o.)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2013-09-18] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1506736 2013-09-26] (Bitdefender)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [727592 2013-07-19] (BitDefender)
R3 avchv; C:\Windows\system32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender)
S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [601360 2013-07-19] (BitDefender)
S0 bdelam; C:\Windows\System32\drivers\bdelam.sys [23456 2012-07-11] (Bitdefender)
R1 BdfNdisf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys [98768 2013-09-18] (BitDefender LLC)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [107008 2013-09-18] (BitDefender LLC)
S3 bdfwfpf_pc; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys [121928 2013-09-26] (Bitdefender SRL)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-07-23] (BitDefender SRL)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [121728 2012-08-27] (Motorola Solutions, Inc.)
S3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [857472 2012-08-29] (Motorola Solutions, Inc.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-05-16] (DT Soft Ltd)
R3 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-09-26] (BitDefender LLC)
S3 ipadtst; C:\Program Files (x86)\MSI\Super-Charger\ipadtst_64.sys [17936 2011-12-12] (Windows (R) Win 7 DDK provider)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4309032 2012-10-19] (Intel Corporation)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [14136 2010-01-18] (MSI)
R3 RZMAELSTROMVADService; C:\Windows\system32\drivers\RzMaelstromVAD.sys [40696 2013-09-18] (Windows (R) Win 7 DDK provider)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-09-26] (BitDefender S.R.L.)
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-21 20:16 - 2013-10-21 20:16 - 00000000 ____D C:\FRST
2013-10-21 20:15 - 2013-10-21 20:15 - 00027136 _____ C:\Windows\system32\bddel.exe
2013-10-21 20:15 - 2013-10-21 20:15 - 00001140 _____ C:\Windows\system32\bddel.dat
2013-10-21 20:14 - 2013-10-21 20:14 - 00112128 ____N (forum.viry.cz) C:\Users\krist_000\Desktop\FRSTLauncher.exe
2013-10-21 20:11 - 2013-10-21 20:11 - 05552488 _____ (Piriform Ltd) C:\Users\krist_000\Downloads\spsetup123.exe
2013-10-21 20:11 - 2013-10-21 20:11 - 01954670 _____ (Farbar) C:\Users\krist_000\Desktop\FRST64.exe
2013-10-21 20:10 - 2013-10-21 20:10 - 00000000 _____ C:\Windows\setuperr.log
2013-10-21 20:10 - 2013-10-21 20:10 - 00000000 _____ C:\Windows\setupact.log
2013-10-20 20:01 - 2013-10-20 20:01 - 00387772 _____ C:\Users\krist_000\Documents\Zulovia.pptx
2013-10-19 19:57 - 2013-10-19 19:57 - 00001087 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2013-10-19 19:57 - 2013-10-19 19:57 - 00000000 ____D C:\Users\krist_000\AppData\Local\VS Revo Group
2013-10-19 19:57 - 2013-10-19 19:57 - 00000000 ____D C:\ProgramData\VS Revo Group
2013-10-19 19:57 - 2013-10-19 19:57 - 00000000 ____D C:\Program Files\VS Revo Group
2013-10-19 19:57 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2013-10-19 19:56 - 2013-10-19 19:57 - 10031224 _____ (VS Revo Group ) C:\Users\krist_000\Downloads\RevoUninProSetup.exe
2013-10-18 16:39 - 2013-10-21 18:42 - 00003576 _____ C:\Windows\System32\Tasks\Bitdefender Autoscan
2013-10-14 20:30 - 2013-10-14 20:30 - 01241882 _____ C:\Users\krist_000\Documents\My Family.pptx
2013-10-11 20:36 - 2013-10-12 09:07 - 00000000 ____D C:\Users\krist_000\Downloads\Skola
2013-10-11 19:30 - 2013-10-11 20:03 - 35927414 _____ C:\Users\krist_000\Downloads\Skola.zip
2013-10-09 10:52 - 2013-07-06 00:02 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-09 10:52 - 2013-07-06 00:01 - 00210560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-09 10:52 - 2013-07-02 03:41 - 00447320 ____N (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2013-10-09 10:52 - 2013-07-02 03:41 - 00337752 ____N (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2013-10-09 10:52 - 2013-07-02 03:41 - 00213336 ____N (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS
2013-10-09 10:52 - 2013-07-01 03:42 - 00623448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-09 10:52 - 2013-07-01 03:42 - 00498008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-09 10:52 - 2013-07-01 03:42 - 00079192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-09 10:52 - 2013-07-01 03:42 - 00021848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-09 10:52 - 2013-06-29 05:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-09 10:52 - 2013-06-29 05:06 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-09 10:52 - 2013-06-22 07:45 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-09 10:52 - 2013-06-22 07:45 - 00054488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2013-10-09 10:51 - 2013-09-23 01:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-09 10:51 - 2013-09-23 01:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-09 10:51 - 2013-09-23 01:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-09 10:51 - 2013-09-23 01:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-09 10:51 - 2013-09-23 01:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-09 10:51 - 2013-09-23 01:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-09 10:51 - 2013-09-23 01:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-09 10:51 - 2013-09-23 01:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-09 10:51 - 2013-09-23 00:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-09 10:51 - 2013-09-23 00:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-09 10:51 - 2013-09-23 00:55 - 00051712 ____N (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-09 10:51 - 2013-09-23 00:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-09 10:51 - 2013-09-23 00:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-09 10:51 - 2013-09-23 00:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-09 10:51 - 2013-09-23 00:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-09 10:51 - 2013-09-23 00:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-09 10:51 - 2013-09-23 00:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-09 10:51 - 2013-08-29 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2013-10-09 10:51 - 2013-08-23 07:11 - 04040192 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-09 10:51 - 2013-07-20 00:13 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 10:51 - 2013-07-20 00:13 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-09 10:51 - 2013-07-06 02:15 - 00652288 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-09 10:51 - 2013-07-04 04:13 - 00541696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-09 10:51 - 2013-07-02 00:14 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbprint.sys
2013-10-09 10:51 - 2013-06-29 05:08 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-09 10:51 - 2013-06-29 05:07 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-09 10:51 - 2013-05-27 01:17 - 00035328 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-09 10:51 - 2013-05-27 00:59 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-09 10:51 - 2013-05-25 05:15 - 00362496 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-09 10:51 - 2013-05-25 04:32 - 00300032 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-09 10:51 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-10-09 10:51 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2013-10-09 10:51 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-09 10:51 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-09 10:51 - 2013-04-29 00:28 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2013-10-09 10:51 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-09 10:51 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-09 10:51 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-09 10:51 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-09 10:51 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-09 10:51 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-09 10:51 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2013-10-09 10:51 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-09 10:51 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-09 10:12 - 2013-10-19 14:05 - 00000191 _____ C:\Users\krist_000\Desktop\List pre Ježiška.txt
2013-10-07 17:06 - 2013-10-07 17:11 - 00000000 ____D C:\Users\krist_000\Downloads\Pes optional file záloha xbox360
2013-10-07 17:04 - 2013-10-07 17:04 - 00000000 ____D C:\Users\krist_000\Downloads\Pes optional file
2013-10-07 16:42 - 2013-10-07 16:49 - 367165361 _____ C:\Users\krist_000\Downloads\WENBOFX v0.1.rar
2013-10-06 19:25 - 2013-10-06 19:25 - 00099133 _____ C:\Users\krist_000\Downloads\The-Hangover-Part-II(0000188049).srt
2013-10-06 15:36 - 2013-10-06 15:36 - 00000000 ____D C:\Users\krist_000\Documents\Sims 3 reg
2013-10-06 07:21 - 2013-10-21 19:26 - 00000954 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-06 07:21 - 2013-10-21 16:08 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-05 21:12 - 2013-10-05 21:11 - 00116697 _____ C:\Users\krist_000\Downloads\The-Hangover(0000143140).srt
2013-10-05 14:40 - 2013-10-05 14:40 - 00000000 ____D C:\ProgramData\RzMaelstromVAD_1.1.47.1552
2013-10-04 08:25 - 2013-10-04 08:26 - 109156441 _____ C:\Users\krist_000\Downloads\Martin-Solveig---The-Night-Out-[EP]-[2012].rar
2013-10-04 08:24 - 2013-10-04 08:25 - 139795505 _____ C:\Users\krist_000\Downloads\Martin-Solveig-–-Smash-(2011)-[iTunes]-[[[UpByNoNa]]].rar
2013-10-02 13:01 - 2013-10-02 13:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-30 16:08 - 2013-09-30 19:53 - 133812736 _____ C:\Users\krist_000\Downloads\GrandTheftAutoV-TheManual.msi
2013-09-28 19:51 - 2013-09-28 19:54 - 12109893 _____ ( ) C:\Users\krist_000\Downloads\Sleeping-Dogs.exe
2013-09-28 19:49 - 2013-09-28 19:54 - 00000000 ____D C:\Program Files (x86)\Saints Row The Third
2013-09-28 18:07 - 2013-09-28 18:58 - 208839320 _____ C:\Users\krist_000\Downloads\Sony-Vegas-Pro-11.0-Full-Verzion-+-Sk-Cz-návod.rar
2013-09-28 16:00 - 2013-10-14 19:10 - 00000000 ____D C:\Users\krist_000\Downloads\Dirt.3-SKIDROW
2013-09-28 15:56 - 2013-09-28 15:56 - 00000000 ____D C:\Users\krist_000\Downloads\The Sims 3 Na plny plyn
2013-09-28 15:55 - 2013-09-28 16:00 - 00000000 ____D C:\Users\krist_000\Downloads\The Sims 3 - Povolání snů
2013-09-28 11:59 - 2013-09-28 11:59 - 00000116 _____ C:\Users\krist_000\Downloads\Key-The-Sims-3-Pets.txt
2013-09-28 11:28 - 2012-03-14 23:10 - 00000000 ____D C:\Users\krist_000\Documents\Electronic Arts
2013-09-27 21:46 - 2013-09-27 21:47 - 09830790 _____ C:\Users\krist_000\Downloads\Watch_Dogs.themepack
2013-09-27 20:46 - 2013-09-27 20:46 - 00000000 ____D C:\Program Files (x86)\Microsoft WSE
2013-09-27 20:13 - 2013-09-27 20:34 - 233363524 _____ C:\Users\krist_000\Downloads\03.-The-Sims-3-Luxusní-bydlení.rar
2013-09-26 18:55 - 2013-09-26 18:57 - 06362175 _____ C:\Users\krist_000\Downloads\FxGuru_20130926_142344.mp4
2013-09-26 18:55 - 2013-09-26 18:56 - 02854943 _____ C:\Users\krist_000\Downloads\FxGuru_20130926_142024.mp4

==================== One Month Modified Files and Folders =======

2015-07-25 04:24 - 2013-08-06 10:41 - 00000000 ____D C:\Users\krist_000\Downloads\Guru3D.com
2013-10-21 20:16 - 2013-10-21 20:16 - 00000000 ____D C:\FRST
2013-10-21 20:15 - 2013-10-21 20:15 - 00027136 _____ C:\Windows\system32\bddel.exe
2013-10-21 20:15 - 2013-10-21 20:15 - 00001140 _____ C:\Windows\system32\bddel.dat
2013-10-21 20:14 - 2013-10-21 20:14 - 00112128 ____N (forum.viry.cz) C:\Users\krist_000\Desktop\FRSTLauncher.exe
2013-10-21 20:11 - 2013-10-21 20:11 - 05552488 _____ (Piriform Ltd) C:\Users\krist_000\Downloads\spsetup123.exe
2013-10-21 20:11 - 2013-10-21 20:11 - 01954670 _____ (Farbar) C:\Users\krist_000\Desktop\FRST64.exe
2013-10-21 20:11 - 2013-07-27 09:46 - 00000806 _____ C:\Users\Public\Desktop\Speccy.lnk
2013-10-21 20:11 - 2013-07-27 09:46 - 00000000 ____D C:\Program Files\Speccy
2013-10-21 20:10 - 2013-10-21 20:10 - 00000000 _____ C:\Windows\setuperr.log
2013-10-21 20:10 - 2013-10-21 20:10 - 00000000 _____ C:\Windows\setupact.log
2013-10-21 20:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2013-10-21 19:57 - 2013-08-20 19:58 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-21 19:54 - 2013-08-06 11:46 - 01101279 _____ C:\Windows\WindowsUpdate.log
2013-10-21 19:26 - 2013-10-06 07:21 - 00000954 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-21 18:42 - 2013-10-18 16:39 - 00003576 _____ C:\Windows\System32\Tasks\Bitdefender Autoscan
2013-10-21 16:12 - 2013-01-29 19:32 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1449852709-4245229944-518367605-1002
2013-10-21 16:09 - 2013-08-23 20:27 - 00001130 _____ C:\Users\krist_000\Desktop\Age of Empires II.lnk
2013-10-21 16:08 - 2013-10-06 07:21 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-21 16:08 - 2013-08-17 20:25 - 00000000 ___RD C:\Users\krist_000\SkyDrive
2013-10-21 16:08 - 2013-07-27 18:08 - 00000583 ____N C:\Users\krist_000\Desktop\Mafia II.lnk
2013-10-20 20:01 - 2013-10-20 20:01 - 00387772 _____ C:\Users\krist_000\Documents\Zulovia.pptx
2013-10-20 18:04 - 2013-02-26 18:07 - 00180516 _____ C:\Windows\system32\perfh01B.dat
2013-10-20 18:04 - 2013-02-26 18:07 - 00047710 _____ C:\Windows\system32\perfc01B.dat
2013-10-20 18:04 - 2013-01-29 19:27 - 06548040 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-20 18:04 - 2012-11-22 13:02 - 00835038 _____ C:\Windows\system32\perfh019.dat
2013-10-20 18:04 - 2012-11-22 13:02 - 00182764 _____ C:\Windows\system32\perfc019.dat
2013-10-20 18:04 - 2012-11-22 12:23 - 00852096 _____ C:\Windows\system32\perfh015.dat
2013-10-20 18:04 - 2012-11-22 12:23 - 00184334 _____ C:\Windows\system32\perfc015.dat
2013-10-20 18:04 - 2012-11-22 12:13 - 00851900 _____ C:\Windows\system32\perfh013.dat
2013-10-20 18:04 - 2012-11-22 12:13 - 00183524 _____ C:\Windows\system32\perfc013.dat
2013-10-20 18:04 - 2012-11-22 11:39 - 00561094 _____ C:\Windows\system32\perfh012.dat
2013-10-20 18:04 - 2012-11-22 11:39 - 00157490 _____ C:\Windows\system32\perfc012.dat
2013-10-20 18:04 - 2012-11-22 10:20 - 00608142 _____ C:\Windows\system32\perfh008.dat
2013-10-20 18:04 - 2012-11-22 10:20 - 00113796 _____ C:\Windows\system32\perfc008.dat
2013-10-20 18:04 - 2012-11-22 10:13 - 00808150 _____ C:\Windows\system32\perfh007.dat
2013-10-20 18:04 - 2012-11-22 10:13 - 00180298 _____ C:\Windows\system32\perfc007.dat
2013-10-20 10:18 - 2013-08-21 16:50 - 00000000 ____D C:\Users\krist_000\AppData\Local\Deployment
2013-10-19 21:12 - 2013-06-03 17:56 - 00000000 ____D C:\Users\krist_000\AppData\Roaming\uTorrent
2013-10-19 21:09 - 2012-11-29 00:32 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-19 21:01 - 2013-03-29 22:15 - 00000000 ____D C:\Users\krist_000\AppData\Roaming\CyberLink
2013-10-19 20:51 - 2013-02-08 18:10 - 00000000 ____D C:\ProgramData\CyberLink
2013-10-19 20:37 - 2013-01-30 15:40 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2013-10-19 20:33 - 2013-05-02 07:48 - 00000000 ____D C:\Program Files (x86)\Origin Games
2013-10-19 20:07 - 2013-01-30 16:10 - 00000000 ____D C:\ProgramData\Electronic Arts
2013-10-19 20:06 - 2013-06-29 12:13 - 00000000 ____D C:\Program Files (x86)\NAMCO BANDAI Games
2013-10-19 19:57 - 2013-10-19 19:57 - 00001087 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2013-10-19 19:57 - 2013-10-19 19:57 - 00000000 ____D C:\Users\krist_000\AppData\Local\VS Revo Group
2013-10-19 19:57 - 2013-10-19 19:57 - 00000000 ____D C:\ProgramData\VS Revo Group
2013-10-19 19:57 - 2013-10-19 19:57 - 00000000 ____D C:\Program Files\VS Revo Group
2013-10-19 19:57 - 2013-10-19 19:56 - 10031224 _____ (VS Revo Group ) C:\Users\krist_000\Downloads\RevoUninProSetup.exe
2013-10-19 19:42 - 2013-04-30 19:51 - 00000000 ____D C:\Users\krist_000\AppData\Roaming\Epson
2013-10-19 14:05 - 2013-10-09 10:12 - 00000191 _____ C:\Users\krist_000\Desktop\List pre Ježiška.txt
2013-10-19 11:17 - 2013-04-01 11:32 - 00000000 ____D C:\Users\krist_000\AppData\Roaming\Skype
2013-10-18 17:47 - 2013-02-17 16:17 - 00000000 ____D C:\Users\krist_000\AppData\Roaming\vlc
2013-10-18 17:28 - 2013-08-31 19:23 - 00002193 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-10-18 16:41 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-10-15 18:06 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\LiveKernelReports
2013-10-14 20:30 - 2013-10-14 20:30 - 01241882 _____ C:\Users\krist_000\Documents\My Family.pptx
2013-10-14 19:10 - 2013-09-28 16:00 - 00000000 ____D C:\Users\krist_000\Downloads\Dirt.3-SKIDROW
2013-10-12 09:07 - 2013-10-11 20:36 - 00000000 ____D C:\Users\krist_000\Downloads\Skola
2013-10-11 20:03 - 2013-10-11 19:30 - 35927414 _____ C:\Users\krist_000\Downloads\Skola.zip
2013-10-10 12:07 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM
2013-10-10 12:04 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-10 12:02 - 2013-03-16 14:02 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 12:02 - 2013-03-16 14:02 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-10 12:02 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI
2013-10-09 11:17 - 2013-01-29 21:55 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-09 11:16 - 2013-08-12 19:54 - 00000000 ____D C:\Windows\system32\MRT
2013-10-09 11:14 - 2013-01-31 09:59 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-09 10:57 - 2013-01-29 20:08 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 10:17 - 2013-08-17 16:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-10-07 17:11 - 2013-10-07 17:06 - 00000000 ____D C:\Users\krist_000\Downloads\Pes optional file záloha xbox360
2013-10-07 17:04 - 2013-10-07 17:04 - 00000000 ____D C:\Users\krist_000\Downloads\Pes optional file
2013-10-07 16:49 - 2013-10-07 16:42 - 367165361 _____ C:\Users\krist_000\Downloads\WENBOFX v0.1.rar
2013-10-06 19:25 - 2013-10-06 19:25 - 00099133 _____ C:\Users\krist_000\Downloads\The-Hangover-Part-II(0000188049).srt
2013-10-06 15:36 - 2013-10-06 15:36 - 00000000 ____D C:\Users\krist_000\Documents\Sims 3 reg
2013-10-06 15:29 - 2013-05-17 19:49 - 00000000 ____D C:\Windows\SysWOW64\directx
2013-10-06 14:37 - 2013-05-16 18:00 - 00000000 ____D C:\Users\krist_000\AppData\Roaming\DAEMON Tools Lite
2013-10-06 07:21 - 2013-04-12 18:03 - 00003926 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-06 07:21 - 2013-04-12 18:03 - 00003690 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-05 21:11 - 2013-10-05 21:12 - 00116697 _____ C:\Users\krist_000\Downloads\The-Hangover(0000143140).srt
2013-10-05 14:40 - 2013-10-05 14:40 - 00000000 ____D C:\ProgramData\RzMaelstromVAD_1.1.47.1552
2013-10-04 08:26 - 2013-10-04 08:25 - 109156441 _____ C:\Users\krist_000\Downloads\Martin-Solveig---The-Night-Out-[EP]-[2012].rar
2013-10-04 08:25 - 2013-10-04 08:24 - 139795505 _____ C:\Users\krist_000\Downloads\Martin-Solveig-–-Smash-(2011)-[iTunes]-[[[UpByNoNa]]].rar
2013-10-02 20:51 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF
2013-10-02 16:40 - 2013-01-29 19:42 - 00000000 ____D C:\Users\krist_000\AppData\Local\Mozilla
2013-10-02 13:01 - 2013-10-02 13:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-10-02 03:38 - 2013-05-20 19:43 - 00694232 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-02 03:38 - 2013-05-20 19:43 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-30 19:53 - 2013-09-30 16:08 - 133812736 _____ C:\Users\krist_000\Downloads\GrandTheftAutoV-TheManual.msi
2013-09-29 11:24 - 2013-05-02 07:43 - 00000000 ____D C:\Program Files (x86)\Origin
2013-09-28 19:58 - 2013-05-17 19:55 - 00000000 ____D C:\Users\krist_000\AppData\Local\SKIDROW
2013-09-28 19:54 - 2013-09-28 19:51 - 12109893 _____ ( ) C:\Users\krist_000\Downloads\Sleeping-Dogs.exe
2013-09-28 19:54 - 2013-09-28 19:49 - 00000000 ____D C:\Program Files (x86)\Saints Row The Third
2013-09-28 18:58 - 2013-09-28 18:07 - 208839320 _____ C:\Users\krist_000\Downloads\Sony-Vegas-Pro-11.0-Full-Verzion-+-Sk-Cz-návod.rar
2013-09-28 16:00 - 2013-09-28 15:55 - 00000000 ____D C:\Users\krist_000\Downloads\The Sims 3 - Povolání snů
2013-09-28 15:56 - 2013-09-28 15:56 - 00000000 ____D C:\Users\krist_000\Downloads\The Sims 3 Na plny plyn
2013-09-28 11:59 - 2013-09-28 11:59 - 00000116 _____ C:\Users\krist_000\Downloads\Key-The-Sims-3-Pets.txt
2013-09-28 11:21 - 2013-07-13 15:07 - 00000000 ____D C:\Users\krist_000\AppData\Local\Axialis
2013-09-28 10:57 - 2013-03-06 14:24 - 00000000 ____D C:\Users\krist_000\Documents\Euro Truck Simulator 2
2013-09-28 08:00 - 2013-09-20 12:04 - 00000058 _____ C:\Windows\nfsc_patch.ini
2013-09-27 21:47 - 2013-09-27 21:46 - 09830790 _____ C:\Users\krist_000\Downloads\Watch_Dogs.themepack
2013-09-27 21:14 - 2013-07-12 14:20 - 00000069 _____ C:\Windows\NeroDigital.ini
2013-09-27 20:46 - 2013-09-27 20:46 - 00000000 ____D C:\Program Files (x86)\Microsoft WSE
2013-09-27 20:34 - 2013-09-27 20:13 - 233363524 _____ C:\Users\krist_000\Downloads\03.-The-Sims-3-Luxusní-bydlení.rar
2013-09-26 18:57 - 2013-09-26 18:55 - 06362175 _____ C:\Users\krist_000\Downloads\FxGuru_20130926_142344.mp4
2013-09-26 18:56 - 2013-09-26 18:55 - 02854943 _____ C:\Users\krist_000\Downloads\FxGuru_20130926_142024.mp4
2013-09-26 17:41 - 2013-08-14 18:56 - 00389240 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\trufos.sys
2013-09-26 17:41 - 2013-08-14 18:56 - 00000000 ____D C:\ProgramData\Bitdefender
2013-09-26 17:40 - 2013-08-14 18:56 - 00150256 _____ (BitDefender LLC) C:\Windows\system32\Drivers\gzflt.sys
2013-09-24 18:10 - 2013-02-06 19:01 - 00000000 ____D C:\Users\krist_000\AppData\Local\Windows Live
2013-09-23 01:28 - 2013-10-09 10:51 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-09-23 01:28 - 2013-10-09 10:51 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-09-23 01:27 - 2013-10-09 10:51 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-09-23 01:27 - 2013-10-09 10:51 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-09-23 01:27 - 2013-10-09 10:51 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-09-23 01:27 - 2013-10-09 10:51 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-09-23 01:27 - 2013-10-09 10:51 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-09-23 01:27 - 2013-10-09 10:51 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-09-23 00:55 - 2013-10-09 10:51 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-23 00:55 - 2013-10-09 10:51 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-23 00:55 - 2013-10-09 10:51 - 00051712 ____N (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-23 00:54 - 2013-10-09 10:51 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-23 00:54 - 2013-10-09 10:51 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-23 00:54 - 2013-10-09 10:51 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-23 00:54 - 2013-10-09 10:51 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-23 00:54 - 2013-10-09 10:51 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-23 00:54 - 2013-10-09 10:51 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll

Some content of TEMP:
====================
C:\Users\krist_000\AppData\Local\Temp\eauninstall.exe
C:\Users\krist_000\AppData\Local\Temp\Need for Speed Most Wanted_uninst.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-09 11:06




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: (OS_Install) (Fixed) (Total:311.66 GB) (Free:136.75 GB) NTFS
Drive d: (Data) (Fixed) (Total:132.5 GB) (Free:117.29 GB) NTFS

Available physical RAM: 1495.58 MB
Total physical RAM: 3985.43 MB
Percentage of memory in use: 62%

==================== MBR and Partition Table ==================

Disk: 0 (Size: 466 GB) (Disk ID: AC38BDF4)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ?

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Users\krist_000\Desktop\FRST64.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\Euro-Truck-Simulator-2-Keygen.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\Game_Booster_v3.7.0.11.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\RazerSurroundInstaller_v1.00.00.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\RevoUninProSetup.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\Sleeping-Dogs.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\spsetup123.exe:BDU

==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Bitdefender Antivirus (Enabled - Up to date) {9B5F5313-CAF9-DD97-C460-E778420237B4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Bitdefender Antispyware (Enabled - Up to date) {203EB2F7-ECC3-D219-FED0-DC0A39857D09}
FW: Bitdefender Firewall (Enabled) {A364D236-8096-DCCF-EF3F-4E4DBCD170CF}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 28_09_2013 (06)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\krist_000\Desktop" je 121 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
Ďakujem, Kiko

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divný Proces

#8 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
AlternateDataStreams: C:\Users\krist_000\Desktop\FRST64.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\Euro-Truck-Simulator-2-Keygen.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\Game_Booster_v3.7.0.11.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\RazerSurroundInstaller_v1.00.00.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\RevoUninProSetup.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\Sleeping-Dogs.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\spsetup123.exe:BDU
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kiko22
Návštěvník
Návštěvník
Příspěvky: 116
Registrován: 28 črc 2013 10:42

Re: Divný Proces

#9 Příspěvek od kiko22 »

Tu je Fixlog
zatiaľ ďakujem za pomoc, Kiko

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-10-2013
Ran by krist_000 at 2013-10-21 20:42:29 Run:1
Running from C:\Users\krist_000\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
AlternateDataStreams: C:\Users\krist_000\Desktop\FRST64.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\Euro-Truck-Simulator-2-Keygen.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\Game_Booster_v3.7.0.11.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\RazerSurroundInstaller_v1.00.00.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\RevoUninProSetup.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\Sleeping-Dogs.exe:BDU
AlternateDataStreams: C:\Users\krist_000\Downloads\spsetup123.exe:BDU
End
*****************

HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
C:\Users\krist_000\Desktop\FRST64.exe => ":BDU" ADS removed successfully.
C:\Users\krist_000\Downloads\Euro-Truck-Simulator-2-Keygen.exe => ":BDU" ADS removed successfully.
C:\Users\krist_000\Downloads\Game_Booster_v3.7.0.11.exe => ":BDU" ADS removed successfully.
C:\Users\krist_000\Downloads\RazerSurroundInstaller_v1.00.00.exe => ":BDU" ADS removed successfully.
C:\Users\krist_000\Downloads\RevoUninProSetup.exe => ":BDU" ADS removed successfully.
C:\Users\krist_000\Downloads\Sleeping-Dogs.exe => ":BDU" ADS removed successfully.
C:\Users\krist_000\Downloads\spsetup123.exe => ":BDU" ADS removed successfully.

==== End of Fixlog ====
Ďakujem, Kiko

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divný Proces

#10 Příspěvek od Rudy »

Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kiko22
Návštěvník
Návštěvník
Příspěvky: 116
Registrován: 28 črc 2013 10:42

Re: Divný Proces

#11 Příspěvek od kiko22 »

Proces uz nie je, pocitac ryhclejsie reaguje.
Chcel by som sa spytat: keď som odinštaloval asi 7 hier, aby bol pocitac ryhclejsi (a to s pomocou revo uninstaller pro!) Nenastala nijaká zmena (po pouziti vaseho super programu FRST Launcheru sa zrychlil). Myslíte si, že počítač má dosť aj teraz?, alebo ze sa s nim nieco stalo?

Ďakujem za pomoc, Kiko
Inac, ten ETS2 keygen, ten som nepouzil a Sleeping dogs tiez....
Ďakujem, Kiko

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divný Proces

#12 Příspěvek od Rudy »

Pokud jste něco odisnatloval, pak to v PC není (zřejmě až na nějaké zbytky). Pokud to nějak nevadí při chodu, neřešte. FRST je čistič, který smaže to, co se mu zadá do skriptu. Měl jste tam nějaké AdWary a zbytečnosti. Nemáte zač!
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kiko22
Návštěvník
Návštěvník
Příspěvky: 116
Registrován: 28 črc 2013 10:42

Re: Divný Proces

#13 Příspěvek od kiko22 »

Noo, teraz si robím do školy veci vo worde a seká sa mi + sa mi seká Firefox. Neviete z čoho by to mohlo byť?

Ďakujem, Kiko
Ďakujem, Kiko

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119531
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Divný Proces

#14 Příspěvek od Rudy »

Zkuste ještě toto:

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:commands
[Purity]
[Emptytemp]
[Empytflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC. Případně ještě defragmentujte disk.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kiko22
Návštěvník
Návštěvník
Příspěvky: 116
Registrován: 28 črc 2013 10:42

Re: Divný Proces

#15 Příspěvek od kiko22 »

Dobry den!
Prepacte, ze som dlho nebol na fore, ale skola nepocka, tu je log z OTM

All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: krist_000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 166454 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 352460010 bytes
->Google Chrome cache emptied: 7466125 bytes
->Flash cache emptied: 3852 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 94709 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 898035771 bytes

Total Files Cleaned = 1 200,00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: krist_000
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 128 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 45775547 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 81714 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 44,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 10242013_125540

Files moved on Reboot...
C:\Users\krist_000\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
C:\Users\krist_000\AppData\Local\Mozilla\Firefox\Profiles\gy9gugdw.default-1365923927922\Cache\_CACHE_001_ moved successfully.
C:\Users\krist_000\AppData\Local\Mozilla\Firefox\Profiles\gy9gugdw.default-1365923927922\Cache\_CACHE_002_ moved successfully.
C:\Users\krist_000\AppData\Local\Mozilla\Firefox\Profiles\gy9gugdw.default-1365923927922\Cache\_CACHE_003_ moved successfully.
C:\Users\krist_000\AppData\Local\Mozilla\Firefox\Profiles\gy9gugdw.default-1365923927922\Cache\_CACHE_MAP_ moved successfully.
C:\Users\krist_000\AppData\Local\Mozilla\Firefox\Profiles\gy9gugdw.default-1365923927922\_CACHE_CLEAN_ moved successfully.
File move failed. C:\Windows\temp\RzMaelstromVADStreamingService.log scheduled to be moved on reboot.
C:\Windows\temp\winstore.log moved successfully.
File C:\Windows\temp\~bd1114.tmp not found!
File C:\Windows\temp\~bd79B3.tmp not found!

Registry entries deleted on Reboot...

Inac, mam otazku, ktora moc nesuvisi s temou topicu ale, ak sa mozem spytat:
Ako robite to, ze napr. Obrazok je uploadnuty TU
tam kde je tu je odkaz na link a ked na to kliknem tak ma to presmeruje na tu danu stranku.

Dakujem, Kiko
Ďakujem, Kiko

Zamčeno