Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Virus Policie-Španělsko-kam se mi schoval ?Je v notebooku ?

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
jarmilaw
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 říj 2013 22:09

Virus Policie-Španělsko-kam se mi schoval ?Je v notebooku ?

#1 Příspěvek od jarmilaw »

Dobrý večer, psala jsem na http://www.viruskasino.com/2012/12/vas- ... 6806466832 ,tak jen zopakuji: Dobrý den, jste úžasný,můžete, prosím, pomoci i mně? Máme dva notebooky připojené přes WIFI, žijeme ve Španělsku. V červnu dostal virus Policia manželův notebook, to jsme snad vyřešili, ale mi bohužel nedošlo, že i můj notebook je ohrožený, když je to stejná IP adresa. Nejdřív se musím omluvit, jsem naprostý počítačový antitalent. Ale toto mi došlo až teď, kdy jsem si chtěla po 3 měsících od té příhody,prohlédnout nějaké free seriály. A druhý den,tedy dnes, se mi objevila stránka s tím oznámením, Policie,ve španělštině. Stáhla jsem AVG, restartovala poté počítač,ale nic se nenašlo. Teď ještě stále můžu spouštět Internet, ale asi po té době, kdy vyprší jejich lhůta k zaplacení, už to nebude možné. Mám Windows Vista, v počítač mám stažený prohlížeč Internet Expl 34 a taky 64 a taky Google Chrome. Uživatel je jen jeden Můžete mi, prosím, také nějak pomocit? Ještě jsem si stáhla RogueKiller, ten našel 7 infikovaných registračních položek, pak jsem spustila Malwarebytes Anti Malware, rychlou kontrolu, už našel asi 180 souborů. Jen nevím, jestli je můžu všechny odstranit. Také se bojím, aby tyto kontrolly již neovládal ten virus a nedával mi pokyny bůh ví, k čemu. Můžete, prosím, tedy poradit? Děkuji moc. Jarmila
Nejsem si jista, jestli jsem pochopila, co je log. Sorry. Ale toto jsem zkopírovala z FRST:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-10-2013
Ran by Jarmila at 2013-10-29 21:55:00
Running from C:\Users\Jarmila\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: AVG Internet Security 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2014 (Enabled) {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}

==================== Installed Programs ======================

Update for Microsoft Office 2007 (KB2508958) (x32)
2007 Microsoft Office system (x32 Version: 12.0.6612.1000)
Adobe Flash Player 10 ActiveX 64-bit (Version: 10.2.161.23)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Reader X (10.1.8) - Czech (x32 Version: 10.1.8)
Advanced Audio FX Engine (x32 Version: 1.12.05)
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (x32)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (x32)
Amazon Browser Settings (x32 Version: 3.0)
Ashampoo Burning Studio 6 FREE v.6.80 (x32 Version: 6.8.0)
AVG 2014 (Version: 14.0.3615)
AVG 2014 (Version: 14.0.4158)
AVG 2014 (Version: 2014.0.4158)
AVG PC Tuneup 2011 (x32 Version: 10.0.0.26)
AVG SafeGuard toolbar (x32 Version: 17.0.0.12)
BS.Player FREE (x32 Version: 2.57.1051)
Cisco EAP-FAST Module (x32 Version: 2.1.6)
Cisco LEAP Module (x32 Version: 1.0.12)
Cisco PEAP Module (x32 Version: 1.0.13)
ConvertXtoDVD 4.1.18.363 (x32 Version: 4.1.18.363)
Dell Edoc Viewer (Version: 1.0.0)
Dell Touchpad (Version: 13.0.2.0)
Dell Webcam Central (x32 Version: 1.20.10)
Dell Wireless WLAN Card Utility (Version: 5.10.38.30)
FORM studio (x32)
Google Chrome (HKCU Version: 30.0.1599.101)
Google Update Helper (x32 Version: 1.3.21.165)
Intel(R) Graphics Media Accelerator Driver
Intel(R) Rapid Storage Technology (x32 Version: 10.5.0.1029)
Intel® Matrix Storage Manager
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Live! Cam Avatar Creator (x32 Version: 4.6.2303.1)
Malwarebytes Anti-Malware verze 1.75.0.1300 (x32 Version: 1.75.0.1300)
McAfee Security Scan Plus (Version: 3.8.130.8)
Microsoft .NET Framework 1.1 (x32 Version: 1.1.4322)
Microsoft .NET Framework 1.1 (x32)
Microsoft .NET Framework 1.1 Security Update (KB2698023) (x32)
Microsoft .NET Framework 1.1 Security Update (KB2833941) (x32)
Microsoft .NET Framework 1.1 Security Update (KB979906) (x32)
Microsoft .NET Framework 3.5 Language Pack SP1 - csy (Version: 3.5.30729)
Microsoft .NET Framework 3.5 SP1 – jazyková sada – CSY
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile CSY Language Pack (Version: 4.0.30319)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Access MUI (Czech) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Excel MUI (Czech) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (Czech) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (Czech) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Professional Hybrid 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Czech) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Slovak) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (Czech) 2007 (x32 Version: 12.0.4518.1025)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Publisher MUI (Czech) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (Czech) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (Czech) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Suite Activation Assistant (x32 Version: 2.9)
Microsoft Office Word MUI (Czech) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (x32 Version: 5.1.20913.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft_VC100_CRT_SP1_x64 (Version: 10.0.40219.1)
Microsoft_VC100_CRT_SP1_x86 (x32 Version: 10.0.40219.1)
MSI TotalMedia 3.5 (x32 Version: 3.5.58.272)
MSVC80_x64_v2 (Version: 1.0.3.0)
MSVC80_x86_v2 (x32 Version: 1.0.3.0)
MSVC90_x64 (Version: 1.0.1.2)
MSVC90_x86 (x32 Version: 1.0.1.2)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP2 Parser and SDK (x32 Version: 4.20.9818.0)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0)
MyFreeCodec (HKCU)
MyPC Backup (Version: )
PowerDVD DX (x32 Version: 8.2.5024)
QuickBooks Premier: Accountant Edition 2007 (x32 Version: )
QuickBooks Product Listing Service (x32 Version: 2.0.148)
Quickset (Version: 9.4.7)
REALTEK DTV USB DEVICE (x32 Version: 1.00.0000)
RegClean Pro (x32 Version: 6.21)
Roxio Creator Audio (x32 Version: 3.7.0)
Roxio Creator Copy (x32 Version: 3.7.0)
Roxio Creator Data (x32 Version: 3.7.0)
Roxio Creator DE (x32 Version: 10.1)
Roxio Creator DE (x32 Version: 3.7.0)
Roxio Creator Tools (x32 Version: 3.7.0)
Roxio Express Labeler 3 (x32 Version: 3.2.1)
Roxio Update Manager (x32 Version: 6.0.0)
Samsung Kies (x32 Version: 2.6.0.13091_9)
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0)
Skype™ 6.9 (x32 Version: 6.9.106)
Smart MP3 CD Burner 2.3 (x32)
Software602 Form Filler (x32 Version: 4.01)
Software602 Print2PDF (x32 Version: 9.1.11.0418)
SupportSoft Assisted Service (x32 Version: 15)
Switch Sound File Converter (x32)
TaxACT 2008 (x32)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition (x32)
Visual Studio 2008 x64 Redistributables (x32 Version: 10.0.0.2)
Visual Studio 2012 x64 Redistributables (Version: 14.0.0.1)
Visual Studio 2012 x86 Redistributables (x32 Version: 14.0.0.1)
VLC media player 1.1.11 (x32 Version: 1.1.11)
WavePad Sound Editor (x32)
WIDCOMM Bluetooth Software 6.2.0.6600 (Version: 6.2.0.6600)
WinRAR
Zoner Photo Studio 14 (Version: 14.0.1.4)

==================== Restore Points =========================

08-10-2013 13:45:49 Naplánovaný kontrolní bod
09-10-2013 01:01:21 Windows Update
10-10-2013 15:25:00 Windows Update
10-10-2013 17:46:34 Windows Update
12-10-2013 01:01:02 Windows Update
13-10-2013 04:35:47 Naplánovaný kontrolní bod
16-10-2013 04:33:33 Windows Update
18-10-2013 10:31:14 Naplánovaný kontrolní bod
21-10-2013 07:34:48 Naplánovaný kontrolní bod
22-10-2013 10:23:18 Windows Update
22-10-2013 15:55:20 Installed Java 7 Update 45
23-10-2013 02:55:50 Removed Microsoft Silverlight
23-10-2013 07:11:51 Windows Modules Installer
24-10-2013 01:00:15 Windows Update
24-10-2013 21:58:00 Removed Microsoft Silverlight
26-10-2013 01:00:24 Windows Update
29-10-2013 07:19:55 Windows Update
29-10-2013 08:01:07 Installed AVG 2014
29-10-2013 08:04:31 Installed AVG 2014
29-10-2013 15:47:26 RegClean Pro Tue, Oct 29, 13 16:47

==================== Hosts content: ==========================

2006-11-02 13:34 - 2006-09-18 22:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {053431E7-8473-4912-A61D-2AF0EC44DA9C} - System32\Tasks\{14255DC5-91EA-407D-B958-A6A9B99DDD10} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2013-10-02] (Skype Technologies S.A.)
Task: {0AEAFAF6-F116-4A60-AFB4-C8B755A6E975} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {192DDA2D-5815-47B8-983F-65744FEEC03A} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {19BCF413-FAC0-4030-A8CA-150FD3B87F14} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe [2008-01-21] (Microsoft Corporation)
Task: {1ACDAFF8-48D6-4A51-8410-4537F8B068E3} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-24] (Microsoft Corporation)
Task: {1E221D00-6C9F-4D0A-AF4A-45684C5C856F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-24] (Adobe Systems Incorporated)
Task: {1EA74C40-93AB-4051-B6A7-7E916AD5A4CB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000UA => C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-07-02] (Google Inc.)
Task: {1EC8C033-BD80-492D-8A7D-17C686442CCB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-26] (Google Inc.)
Task: {254095AE-FB97-48EA-94A5-D8BF2AB79714} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\System32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {39F70537-DB82-48C0-B963-A4C1878B88C6} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-09-17] (Systweak Inc)
Task: {3B223996-4308-4C4B-BAD9-DF4AF5127F8D} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000Core => C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-07-02] (Google Inc.)
Task: {5A16E5FF-DB52-4470-99EB-8E8B19B4E3CD} - System32\Tasks\{3A7F5D3A-771A-46BB-9EBB-F42860BE4BBC} => Iexplore.exe http://ui.skype.com/ui/0/5.1.0.112/en/a ... adyoffered
Task: {75B17298-8C90-4504-952B-F63496D3DA01} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-09-17] (Systweak Inc)
Task: {7C638E5B-ECE5-4424-A7E5-2C913CA682E9} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {8AE98416-DB30-4822-9D28-2CAFBCC0B5D5} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe [2013-09-17] (Systweak Inc)
Task: {8E54656D-9035-4468-BFEF-3D8359D170D6} - System32\Tasks\{2C02AA08-D6DF-48F2-911F-1CF697EC7EDD} => Iexplore.exe http://ui.skype.com/ui/0/5.3.0.111/en/a ... adedefault
Task: {A2339F9C-3288-41CA-8F2B-B93C236EF4EF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-06-26] (Google Inc.)
Task: {B69C9936-B8A3-4167-A92C-9D8BB4ED9B82} - System32\Tasks\{E8FEAE13-3B82-46F2-9395-0734BD4142D6} => Iexplore.exe http://ui.skype.com/ui/0/5.3.0.120/en/a ... adyoffered
Task: {BDBC923C-E274-4094-840B-A124021DD590} - System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask => C:\Windows\System32\raserver.exe [2008-01-21] (Společnost Microsoft)
Task: {BEED75F0-DF25-4B04-ACF4-7C5ADB46DCB1} - System32\Tasks\{86A6EB9D-CC7E-4907-939A-1E4CBD856770} => Iexplore.exe http://ui.skype.com/ui/0/4.1.0.179/cs/a ... adyoffered
Task: {D3D7AEF6-227A-41E8-BF71-B5244245DE2F} - System32\Tasks\{16ED0D99-0E3E-4A4F-AD8B-2CDA041A1212} => Iexplore.exe http://ui.skype.com/ui/0/6.6.0.106/cs/a ... age=tsMain
Task: {E91D6474-70CC-42BE-80FF-8BED8AF557ED} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\System32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {F9EAD5A2-FECF-411B-BE61-FD7992AC51C9} - System32\Tasks\Launch BCM WLAN Tray => C:\Windows\System32\WLTRAY.EXE [2008-12-21] (Dell Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000Core.job => C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000UA.job => C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe

==================== Loaded Modules (whitelisted) =============

2008-11-18 01:49 - 2008-11-18 01:49 - 00167936 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2009-09-02 12:37 - 2008-12-21 19:35 - 00057856 _____ () C:\Windows\System32\bcmwlrmt.dll
2013-09-19 23:37 - 2013-09-19 23:37 - 00012288 _____ () C:\Program Files (x86)\MyPC Backup\GetText.dll
2013-09-19 23:32 - 2013-09-19 23:32 - 01102336 _____ () C:\Program Files (x86)\MyPC Backup\x64\System.Data.SQLite.dll
2010-01-28 21:21 - 2007-04-19 09:33 - 00035584 _____ () C:\Program Files (x86)\MSI\TotalMedia 3.5\uPiApi.dll
2009-12-03 07:43 - 2009-04-11 07:28 - 00368640 _____ () C:\Windows\SysWOW64\msjetoledb40.dll
2010-01-28 21:21 - 2008-11-26 16:59 - 00131584 _____ () C:\Program Files (x86)\MSI\TotalMedia 3.5\AbilisWinUsb.dll
2010-01-28 21:21 - 2008-10-22 16:01 - 00200704 _____ () C:\Program Files (x86)\MSI\TotalMedia 3.5\VendorCmdRW.dll
2013-10-29 09:13 - 2013-10-29 09:13 - 00519704 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\log4cplusU.dll
2013-10-29 09:13 - 2013-10-29 09:13 - 00142360 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.12\SiteSafety.dll
2009-06-12 09:07 - 2009-06-12 09:07 - 00245248 _____ () C:\Windows\system32\WinTab32.DLL
2009-06-12 09:04 - 2009-06-12 09:04 - 00192512 _____ () C:\Windows\SysWOW64\WinTab32.DLL
2013-10-18 17:47 - 2013-10-09 01:02 - 04055504 _____ () C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\30.0.1599.101\pdf.dll
2013-10-18 17:47 - 2013-10-09 01:02 - 00415184 _____ () C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll
2013-10-18 17:47 - 2013-10-09 01:01 - 01604560 _____ () C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll
2013-10-18 17:47 - 2013-10-09 01:01 - 00698832 _____ () C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\30.0.1599.101\libglesv2.dll
2013-10-18 17:47 - 2013-10-09 01:01 - 00099792 _____ () C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\30.0.1599.101\libegl.dll
2013-10-18 17:47 - 2013-10-09 01:02 - 13584336 _____ () C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4

==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============

Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/29/2013 05:31:05 PM) (Source: LoadPerf) (User: )
Description: WmiApRplWmiApRpl8

Error: (10/29/2013 05:31:05 PM) (Source: LoadPerf) (User: )
Description: Performance16

Error: (10/29/2013 05:31:04 PM) (Source: LoadPerf) (User: )
Description: Performance16

Error: (10/29/2013 09:48:24 AM) (Source: LoadPerf) (User: )
Description: WmiApRplWmiApRpl8

Error: (10/29/2013 09:48:24 AM) (Source: LoadPerf) (User: )
Description: Performance16

Error: (10/29/2013 09:48:23 AM) (Source: LoadPerf) (User: )
Description: Performance16

Error: (10/29/2013 09:39:26 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/29/2013 08:46:32 AM) (Source: LoadPerf) (User: )
Description: WmiApRplWmiApRpl8

Error: (10/29/2013 08:46:32 AM) (Source: LoadPerf) (User: )
Description: Performance16

Error: (10/29/2013 08:46:32 AM) (Source: LoadPerf) (User: )
Description: Performance16


System errors:
=============
Error: (10/29/2013 03:26:19 PM) (Source: bowser) (User: )
Description: Hlavní prohledávač přijal oznámení serveru od počítače COMTREND,
který se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{F4BB3370-61B3-4B50-961B-57D7C53CD202}.
Hlavní prohledávač bude ukončen nebo bude vyvolána volba.

Error: (10/29/2013 03:06:56 PM) (Source: Dhcp) (User: )
Description: Zapůjčení adresy IP 192.168.1.129 pro síťovou kartu s adresou 00225FF01667 byla serverem DHCP 192.168.1.1 odmítnuta. (Server DHCP odeslal zprávu DHCPNACK).

Error: (10/29/2013 02:36:04 PM) (Source: bowser) (User: )
Description: Hlavní prohledávač přijal oznámení serveru od počítače COMTREND,
který se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{F4BB3370-61B3-4B50-961B-57D7C53CD202}.
Hlavní prohledávač bude ukončen nebo bude vyvolána volba.

Error: (10/29/2013 02:35:12 PM) (Source: Dhcp) (User: )
Description: Zapůjčení adresy IP 192.168.1.129 pro síťovou kartu s adresou 00225FF01667 byla serverem DHCP 192.168.1.1 odmítnuta. (Server DHCP odeslal zprávu DHCPNACK).

Error: (10/29/2013 02:08:33 PM) (Source: bowser) (User: )
Description: Hlavní prohledávač přijal oznámení serveru od počítače COMTREND,
který se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{F4BB3370-61B3-4B50-961B-57D7C53CD202}.
Hlavní prohledávač bude ukončen nebo bude vyvolána volba.

Error: (10/29/2013 02:07:39 PM) (Source: Dhcp) (User: )
Description: Zapůjčení adresy IP 192.168.1.128 pro síťovou kartu s adresou 00225FF01667 byla serverem DHCP 192.168.1.1 odmítnuta. (Server DHCP odeslal zprávu DHCPNACK).

Error: (10/29/2013 09:40:09 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: specifické pro aplikacimístníSpuštění{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)

Error: (10/29/2013 09:39:30 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: specifické pro aplikacimístníSpuštění{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT AUTHORITYSYSTEMS-1-5-18LocalHost (pomocí LRPC)

Error: (10/29/2013 09:16:37 AM) (Source: Service Control Manager) (User: )
Description: Windows Defender1600001Restartovat službu

Error: (10/29/2013 09:16:10 AM) (Source: Service Control Manager) (User: )
Description: AVG Firewall3758162007 (0xE0010057)


Microsoft Office Sessions:
=========================
Error: (09/26/2010 07:01:03 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6541.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 323173 seconds with 1800 seconds of active time. This session ended with a crash.

Error: (02/25/2010 06:30:03 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6514.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 11325 seconds with 180 seconds of active time. This session ended with a crash.

Error: (11/01/2009 02:59:20 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 8, Application Name: Microsoft Office Publisher, Application Version: 12.0.6501.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1763 seconds with 1620 seconds of active time. This session ended with a crash.


CodeIntegrity Errors:
===================================
Date: 2013-10-29 21:46:33.023
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-10-29 21:46:31.326
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-10-29 21:46:30.018
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-10-29 21:46:28.371
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsha.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-10-29 21:46:24.160
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsdrivera.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-10-29 21:46:22.691
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsdrivera.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-10-29 21:46:21.312
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsdrivera.sys because the set of per-page image hashes could not be found on the system.

Date: 2013-10-29 21:46:20.185
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\avgidsdrivera.sys because the set of per-page image hashes could not be found on the system.

Date: 2011-12-03 07:55:23.150
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG2012\Drivers\Vista\AVGIDSDriver.sys because the set of per-page image hashes could not be found on the system.

Date: 2011-12-03 07:55:22.523
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG2012\Drivers\Vista\AVGIDSDriver.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 95%
Total physical RAM: 2007.57 MB
Available physical RAM: 83.04 MB
Total Pagefile: 4523.04 MB
Available Pagefile: 406.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:218.2 GB) (Free:62.31 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (RECOVERY) (Fixed) (Total:14.65 GB) (Free:8.33 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 233 GB) (Disk ID: 9A7804DA)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=218 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Dejte mi sem druhy log z FRST, jmenuje se FRST.txt a mel by byt v C:\Users\Jarmila\Downloads
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jarmilaw
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 říj 2013 22:09

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#3 Příspěvek od jarmilaw »

Díky moc, to jsem se asi zrovna nestrefila.Tady je ten druhý :
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-10-2013
Ran by Jarmila (administrator) on JARMILA-NEWPC on 29-10-2013 21:42:06
Running from C:\Users\Jarmila\Downloads
Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
() C:\Windows\System32\WLTRYSVC.EXE
(Dell Inc.) C:\Windows\System32\bcmwltry.exe
(Software602 a.s.) C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Dell Inc.) C:\Windows\System32\WLTRAY.EXE
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(ArcSoft, Inc.) C:\Program Files (x86)\MSI\TotalMedia 3.5\TMMonitor.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Software602) C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe
(Tablet Driver) C:\Windows\System32\Drivers\WTSRV.EXE
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\loggingserver.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcfgex.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Tablet Driver) C:\Windows\SysWOW64\WTClient.exe
(Adobe Systems Incorporated) C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe
(Microsoft Corporation) C:\Windows\SysWOW64\conime.exe
(MyPCBackup.com) C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1780520 2009-05-08] (Synaptics Incorporated)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Windows\System32\WLTRAY.EXE [4119552 2008-12-21] (Dell Inc.)
HKLM\...\Run: [QuickSet] - C:\Program Files\Dell\QuickSet\quickset.exe [3236432 2009-04-23] (Dell Inc.)
HKLM\...\Run: [IAAnotif] - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe [178712 2008-06-15] (Intel Corporation)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [462848 2009-05-11] (IDT, Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehtray.exe [138240 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [Google Update] - C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-07-02] (Google Inc.)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-09-04] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
MountPoints2: {f4693101-9437-11e1-87bc-002556e20ba3} - D:\.\Setup.exe AUTORUN=1
HKLM-x32\...\Run: [PDVDDXSrv] - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128232 2009-02-05] (CyberLink Corp.)
HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [405639 2009-01-09] (Creative Technology Ltd)
HKLM-x32\...\Run: [WTClient] - C:\Windows\\SysWOW64\WTClient.exe [32768 2009-03-17] (Tablet Driver)
HKLM-x32\...\Run: [TQ566808] - "F:\Setup.exe"
HKLM-x32\...\Run: [IR_SERVER] - C:\Program Files (x86)\MSI\REALTEK DTV USB DEVICE\IR_SERVER.exe
HKLM-x32\...\Run: [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [Print2PDF Print Monitor] - C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [222776 2011-04-12] (Software602)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4908592 2013-10-07] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2404376 2013-10-29] ()
Startup: C:\Users\Jarmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (MyPCBackup.com)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/defau ... l=cs&s=bsd
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {F348D141-5E2C-4E6B-9903-539AE406D7A4} URL = http://www.google.cz/search?q={searchTe ... 1I7SKPB_cs
SearchScopes: HKCU - {6FEF6957-C8EC-43FF-9D10-0846C354B60C} URL = http://search.avg.com/route/?d=4e00e8e0 ... =&ychte=us
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={CDD ... 2013-10-29 09:13:48&v=17.0.0.12&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {F348D141-5E2C-4E6B-9903-539AE406D7A4} URL = http://www.google.cz/search?q={searchTe ... 1I7SKPB_cs
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.12\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.12\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/produ ... wsdc64.cab
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/produ ... wsdc32.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search)
Winsock: Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [50176] (Společnost Microsoft)
Winsock: Catalog5-x64 02 %SystemRoot%\system32\napinsp.dll [62976] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 87.216.1.65 87.216.1.66

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Jarmila\AppData\Local\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Software602 Form Filler) - C:\Program Files (x86)\Software602\602XML\Filler\npfiller.dll (Software602 a.s.)
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (Google Docs) - C:\Users\Jarmila\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Jarmila\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Jarmila\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Jarmila\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Skype Click to Call) - C:\Users\Jarmila\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.9.0.12585_0
CHR Extension: (Chrome In-App Payments service) - C:\Users\Jarmila\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
CHR Extension: (Blue Space Sunset Chrome Theme) - C:\Users\Jarmila\AppData\Local\Google\Chrome\User Data\Default\Extensions\nndfdjfoclbidmgpmbelcieibgjjfdog\4.3_0
CHR Extension: (Gmail) - C:\Users\Jarmila\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

==================== Services (Whitelisted) =================

R2 602XML Updater; C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe [84520 2011-03-14] (Software602 a.s.)
R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1358944 2013-09-25] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3538480 2013-10-03] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [301152 2013-09-25] (AVG Technologies CZ, s.r.o.)
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.)
R2 vToolbarUpdater17.0.12; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [1734680 2013-10-29] (AVG Secure Search)
R2 wltrysvc; C:\Windows\System32\WLTRYSVC.EXE [32768 2008-12-21] ()
R2 yksvc; C:\Windows\System32\ykx64mpcoinst.dll [382464 2009-05-12] (Marvell)
S3 aspnet_state; %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [x]

==================== Drivers (Whitelisted) ====================

R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [148792 2013-09-25] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [241464 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [192824 2013-09-02] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [212280 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [294712 2013-09-02] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123704 2013-08-20] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31544 2013-09-08] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [251192 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-10-29] (AVG Technologies)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [275432 2009-04-11] (Společnost Microsoft)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1513320 2013-03-03] (Společnost Microsoft)
S3 RTL2832UBDA; C:\Windows\SysWow64\drivers\RTL2832UBDA.sys [114080 2009-07-06] (REALTEK SEMICONDUCTOR Corp.)
S3 RTL2832UUSB; C:\Windows\SysWow64\Drivers\RTL2832UUSB.sys [38944 2009-07-06] (REALTEK SEMICONDUCTOR Corp.)
S3 RTL2832U_IRHID; C:\Windows\SysWow64\DRIVERS\RTL2832U_IRHID.sys [42912 2009-07-13] (Realtek)
S3 VST64HWBS2; C:\Windows\System32\DRIVERS\VSTBS26.SYS [392704 2008-01-21] (Conexant Systems, Inc.)
S3 VST64_DPV; C:\Windows\System32\DRIVERS\VSTDPV6.SYS [1523712 2008-01-21] (Conexant Systems, Inc.)
S3 ZTEusbMB; C:\Windows\System32\DRIVERS\ZTEusbnmeaext2.sys [119680 2012-05-05] (ZTE Incorporated)
S3 ZTEusbnmeaext; C:\Windows\System32\DRIVERS\ZTEusbnmeaext.sys [119680 2012-05-05] (ZTE Incorporated)
S3 ZTEWMSD_637; C:\Windows\System32\Drivers\ZTEWMSD_637.sys [19968 2012-05-05] (ZTE Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
S3 Tablet2k; "%SystemRoot%\System32\Drivers\Tablet2k.sys" [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-10-29 21:39 - 2013-10-29 21:39 - 00000000 ____D C:\FRST
2013-10-29 21:36 - 2013-10-29 21:37 - 01956538 _____ (Farbar) C:\Users\Jarmila\Downloads\FRST64.exe
2013-10-29 21:32 - 2013-10-29 21:33 - 01089183 _____ (Farbar) C:\Users\Jarmila\Downloads\FRST.exe
2013-10-29 19:11 - 2013-10-29 19:11 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Malwarebytes
2013-10-29 18:49 - 2013-10-29 18:49 - 00000950 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-29 18:49 - 2013-10-29 18:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-29 18:49 - 2013-10-29 18:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-29 18:49 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-10-29 16:58 - 2013-10-29 16:58 - 00002826 _____ C:\Users\Jarmila\Desktop\RKreport[0]_D_10292013_165846.txt
2013-10-29 16:31 - 2013-10-29 21:13 - 00000000 ____D C:\Program Files (x86)\Amazon
2013-10-29 16:30 - 2013-10-29 16:30 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.22108.dll
2013-10-29 16:28 - 2013-10-29 16:29 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-10-29 16:28 - 2013-10-29 16:28 - 00000928 _____ C:\Users\Jarmila\Desktop\MyPC Backup.lnk
2013-10-29 16:28 - 2013-10-29 16:28 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-10-29 16:27 - 2013-10-29 16:27 - 00003044 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2013-10-29 16:27 - 2013-10-29 16:27 - 00002888 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
2013-10-29 16:27 - 2013-10-29 16:27 - 00000288 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
2013-10-29 16:27 - 2013-10-29 16:27 - 00000280 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2013-10-29 16:26 - 2013-10-29 20:42 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Systweak
2013-10-29 16:26 - 2013-10-29 16:26 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2013-10-29 16:26 - 2013-10-29 16:26 - 00000891 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
2013-10-29 16:26 - 2013-10-29 16:26 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2013-10-29 16:26 - 2013-09-17 11:25 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
2013-10-29 15:58 - 2013-10-29 15:58 - 00002769 _____ C:\Users\Jarmila\Desktop\RKreport[0]_S_10292013_155828.txt
2013-10-29 15:47 - 2013-10-29 17:03 - 00000000 ____D C:\Users\Jarmila\Desktop\RK_Quarantine
2013-10-29 09:32 - 2013-10-29 09:32 - 00000000 _____ C:\Users\Jarmila\Documents\Wireless key.txt
2013-10-29 09:27 - 2013-10-25 23:28 - 00080976 _____ C:\Users\Jarmila\Desktop\wirelesskeyview-x64.zip
2013-10-29 09:16 - 2013-10-29 09:16 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\AVG2014
2013-10-29 09:14 - 2013-10-29 09:14 - 00000886 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2013-10-29 09:14 - 2013-10-29 09:14 - 00000000 ____D C:\Users\Jarmila\AppData\Local\AVG SafeGuard toolbar
2013-10-29 09:13 - 2013-10-29 09:13 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\TuneUp Software
2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-10-29 09:06 - 2013-10-29 09:15 - 00000000 ____D C:\ProgramData\AVG2014
2013-10-29 09:06 - 2013-10-29 09:06 - 00000000 ___HD C:\$AVG
2013-10-29 08:39 - 2013-10-29 08:39 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
2013-10-29 08:28 - 2013-10-29 09:42 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Avg2014
2013-10-29 08:28 - 2013-10-29 08:28 - 00000000 ____D C:\Users\Jarmila\AppData\Local\MFAData
2013-10-23 05:29 - 2013-10-29 09:37 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-22 22:42 - 2013-10-22 22:42 - 00000000 ____D C:\Program Files\McAfee Security Scan
2013-10-22 21:53 - 2013-10-22 22:42 - 00001877 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2013-10-22 21:53 - 2013-10-22 21:53 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2013-10-22 17:00 - 2013-10-22 17:00 - 00000000 ____D C:\ProgramData\Oracle
2013-10-22 16:58 - 2013-10-08 06:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-22 16:58 - 2013-10-08 06:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-22 16:58 - 2013-10-08 06:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-22 16:58 - 2013-10-08 06:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-22 16:57 - 2013-10-22 16:58 - 00004746 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-19 07:07 - 2013-10-19 07:07 - 00915368 _____ (Oracle Corporation) C:\Users\Jarmila\Downloads\JavaSetup7u45.exe
2013-10-11 13:54 - 2013-10-11 13:54 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-10-10 16:38 - 2013-09-22 16:43 - 17833984 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-10 16:38 - 2013-09-22 16:01 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-10 16:38 - 2013-09-22 15:42 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-10 16:38 - 2013-09-22 15:36 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-10 16:38 - 2013-09-22 15:33 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-10-10 16:38 - 2013-09-22 15:33 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-10 16:38 - 2013-09-22 15:30 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-10-10 16:38 - 2013-09-22 15:27 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-10 16:38 - 2013-09-22 15:23 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-10-10 16:38 - 2013-09-22 15:22 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-10 16:38 - 2013-09-22 15:21 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-10-10 16:38 - 2013-09-22 15:19 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-10 16:38 - 2013-09-22 15:19 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-10 16:38 - 2013-09-22 15:16 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-10-10 16:38 - 2013-09-22 15:15 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 16:38 - 2013-09-22 15:07 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 16:38 - 2013-09-22 11:29 - 12336128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-10 16:38 - 2013-09-22 11:22 - 09739264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-10 16:38 - 2013-09-22 11:22 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-10 16:38 - 2013-09-22 11:14 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2013-10-10 16:38 - 2013-09-22 11:13 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-10 16:38 - 2013-09-22 11:13 - 01104896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-10 16:38 - 2013-09-22 11:12 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-10-10 16:38 - 2013-09-22 11:09 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-10 16:38 - 2013-09-22 11:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2013-10-10 16:38 - 2013-09-22 11:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-10 16:38 - 2013-09-22 11:06 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2013-10-10 16:38 - 2013-09-22 11:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-10 16:38 - 2013-09-22 11:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-10 16:38 - 2013-09-22 11:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-10 16:38 - 2013-09-22 11:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-10-10 16:38 - 2013-09-22 10:59 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-10 05:22 - 2013-08-29 08:48 - 02775552 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 05:22 - 2013-08-01 05:10 - 00901568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 05:22 - 2013-08-01 04:37 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-10-10 05:22 - 2013-07-20 11:45 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 05:22 - 2013-07-20 11:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 05:22 - 2013-07-12 10:19 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-10 05:22 - 2013-07-04 05:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-10 05:22 - 2013-07-04 05:13 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 05:22 - 2013-07-03 03:55 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 05:22 - 2013-06-29 03:25 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-10 05:22 - 2013-06-29 03:25 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-10 05:22 - 2013-06-29 03:25 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-10 05:22 - 2013-06-29 03:25 - 00007552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-10 05:22 - 2013-06-27 00:00 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 05:22 - 2011-05-05 15:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-10 05:22 - 2011-05-05 15:17 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-10 05:21 - 2013-08-27 04:39 - 01268224 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-10-10 05:21 - 2013-08-27 04:39 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-10-10 05:21 - 2013-08-27 04:39 - 00287232 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-10-10 05:21 - 2013-08-27 04:39 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-10-10 05:21 - 2013-08-27 03:47 - 01029120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2013-10-10 05:21 - 2013-08-27 03:47 - 00219648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2013-10-10 05:21 - 2013-08-27 03:47 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2013-10-10 05:21 - 2013-08-27 03:47 - 00160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2013-10-10 05:21 - 2013-08-27 03:32 - 02002944 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-10-10 05:21 - 2013-08-27 03:30 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-10-10 05:21 - 2013-08-27 03:06 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-10-10 05:21 - 2013-08-27 03:00 - 01556480 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-10-10 05:21 - 2013-08-27 03:00 - 01149952 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-10-10 05:21 - 2013-08-27 02:52 - 01172480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2013-10-10 05:21 - 2013-08-27 02:50 - 00486400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2013-10-10 05:21 - 2013-08-27 02:32 - 00683008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2013-10-10 05:21 - 2013-08-27 02:28 - 01069056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-10-10 05:21 - 2013-06-04 05:16 - 00048128 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 05:21 - 2013-06-04 05:16 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-10 05:21 - 2013-06-04 03:01 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 05:21 - 2013-06-04 02:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-07 19:38 - 2013-10-07 19:38 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-10-07 19:38 - 2013-10-07 19:38 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Samsung
2013-10-07 19:38 - 2013-10-07 19:38 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Samsung
2013-10-07 19:37 - 2013-10-07 19:37 - 00001839 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2013-10-07 19:37 - 2013-10-07 19:37 - 00001829 _____ C:\Users\Public\Desktop\Samsung Kies.lnk
2013-10-07 19:37 - 2013-10-07 19:37 - 00000000 ____D C:\Users\Jarmila\Documents\samsung
2013-10-07 19:35 - 2013-06-21 01:07 - 00203672 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2013-10-07 19:35 - 2013-06-21 01:07 - 00103448 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2013-10-07 19:32 - 2013-10-07 19:32 - 00000000 ____D C:\Program Files (x86)\MyFree Codec
2013-10-07 19:29 - 2013-07-18 13:33 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll
2013-10-07 19:27 - 2013-07-18 13:32 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll
2013-10-07 19:27 - 2013-07-18 13:32 - 00020032 _____ (Devguru Co., Ltd) C:\Windows\SysWOW64\Drivers\dgderdrv.sys
2013-10-07 19:24 - 2013-10-07 19:35 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-10-07 19:24 - 2013-10-07 19:33 - 00000000 ____D C:\ProgramData\Samsung
2013-10-07 19:17 - 2013-10-07 19:17 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Downloaded Installations
2013-10-07 19:08 - 2013-10-07 19:12 - 00000000 ____D C:\Users\Jarmila\SAMSUNG
2013-10-02 11:41 - 2013-10-02 11:42 - 60265144 _____ C:\Users\Jarmila\Downloads\R204603.exe

==================== One Month Modified Files and Folders =======

2013-10-29 21:52 - 2009-10-25 14:15 - 00000000 ____D C:\ProgramData\Skype
2013-10-29 21:51 - 2009-10-25 15:22 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Skype
2013-10-29 21:42 - 2010-06-26 14:25 - 00000954 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-10-29 21:41 - 2006-11-02 16:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-29 21:41 - 2006-11-02 16:22 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-29 21:39 - 2013-10-29 21:39 - 00000000 ____D C:\FRST
2013-10-29 21:37 - 2013-10-29 21:36 - 01956538 _____ (Farbar) C:\Users\Jarmila\Downloads\FRST64.exe
2013-10-29 21:33 - 2013-10-29 21:32 - 01089183 _____ (Farbar) C:\Users\Jarmila\Downloads\FRST.exe
2013-10-29 21:28 - 2013-07-02 19:56 - 00000970 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000UA.job
2013-10-29 21:24 - 2012-04-16 14:44 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-29 21:21 - 2011-06-21 19:32 - 00000000 ____D C:\ProgramData\MFAData
2013-10-29 21:13 - 2013-10-29 16:31 - 00000000 ____D C:\Program Files (x86)\Amazon
2013-10-29 20:42 - 2013-10-29 16:26 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Systweak
2013-10-29 19:40 - 2010-06-26 14:24 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-10-29 19:11 - 2013-10-29 19:11 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Malwarebytes
2013-10-29 18:49 - 2013-10-29 18:49 - 00000950 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-10-29 18:49 - 2013-10-29 18:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-10-29 18:49 - 2013-10-29 18:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-10-29 18:08 - 2009-10-16 13:42 - 00002699 _____ C:\Users\Jarmila\Desktop\Microsoft Office Word 2007.lnk
2013-10-29 17:31 - 2008-01-21 10:32 - 00006908 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-29 17:31 - 2008-01-21 10:31 - 03057170 _____ C:\Windows\system32\perfh005.dat
2013-10-29 17:31 - 2008-01-21 10:31 - 01006796 _____ C:\Windows\system32\perfc005.dat
2013-10-29 17:11 - 2010-11-05 00:08 - 00000000 ____D C:\Users\Jarmila\Documents\Hesla
2013-10-29 17:03 - 2013-10-29 15:47 - 00000000 ____D C:\Users\Jarmila\Desktop\RK_Quarantine
2013-10-29 16:58 - 2013-10-29 16:58 - 00002826 _____ C:\Users\Jarmila\Desktop\RKreport[0]_D_10292013_165846.txt
2013-10-29 16:30 - 2013-10-29 16:30 - 00129536 _____ C:\Users\Public\AlexaNSISPlugin.22108.dll
2013-10-29 16:29 - 2013-10-29 16:28 - 00000000 ____D C:\Program Files (x86)\MyPC Backup
2013-10-29 16:28 - 2013-10-29 16:28 - 00000928 _____ C:\Users\Jarmila\Desktop\MyPC Backup.lnk
2013-10-29 16:28 - 2013-10-29 16:28 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
2013-10-29 16:28 - 2009-10-15 18:53 - 00000000 ___RD C:\Users\Jarmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-10-29 16:27 - 2013-10-29 16:27 - 00003044 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2013-10-29 16:27 - 2013-10-29 16:27 - 00002888 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
2013-10-29 16:27 - 2013-10-29 16:27 - 00000288 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
2013-10-29 16:27 - 2013-10-29 16:27 - 00000280 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2013-10-29 16:26 - 2013-10-29 16:26 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2013-10-29 16:26 - 2013-10-29 16:26 - 00000891 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
2013-10-29 16:26 - 2013-10-29 16:26 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2013-10-29 15:58 - 2013-10-29 15:58 - 00002769 _____ C:\Users\Jarmila\Desktop\RKreport[0]_S_10292013_155828.txt
2013-10-29 15:20 - 2009-09-02 07:05 - 01870740 _____ C:\Windows\WindowsUpdate.log
2013-10-29 09:42 - 2013-10-29 08:28 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Avg2014
2013-10-29 09:41 - 2006-11-02 16:07 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-10-29 09:38 - 2006-11-02 16:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-29 09:37 - 2013-10-23 05:29 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-29 09:35 - 2009-09-02 12:42 - 00006396 _____ C:\Windows\bthservsdp.dat
2013-10-29 09:35 - 2006-11-02 16:42 - 00032568 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-10-29 09:32 - 2013-10-29 09:32 - 00000000 _____ C:\Users\Jarmila\Documents\Wireless key.txt
2013-10-29 09:16 - 2013-10-29 09:16 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\AVG2014
2013-10-29 09:15 - 2013-10-29 09:06 - 00000000 ____D C:\ProgramData\AVG2014
2013-10-29 09:14 - 2013-10-29 09:14 - 00000886 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2013-10-29 09:14 - 2013-10-29 09:14 - 00000000 ____D C:\Users\Jarmila\AppData\Local\AVG SafeGuard toolbar
2013-10-29 09:13 - 2013-10-29 09:13 - 00046368 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx64.sys
2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\TuneUp Software
2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-10-29 09:11 - 2009-10-15 18:52 - 00000000 ____D C:\Users\Jarmila
2013-10-29 09:06 - 2013-10-29 09:06 - 00000000 ___HD C:\$AVG
2013-10-29 09:03 - 2011-06-21 19:45 - 00000000 ____D C:\Program Files (x86)\AVG
2013-10-29 09:01 - 2011-12-15 11:15 - 00000000 ____D C:\Users\Jarmila\Documents\Španělsko
2013-10-29 08:52 - 2013-07-02 19:56 - 00000918 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000Core.job
2013-10-29 08:39 - 2013-10-29 08:39 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
2013-10-29 08:28 - 2013-10-29 08:28 - 00000000 ____D C:\Users\Jarmila\AppData\Local\MFAData
2013-10-25 23:28 - 2013-10-29 09:27 - 00080976 _____ C:\Users\Jarmila\Desktop\wirelesskeyview-x64.zip
2013-10-25 07:10 - 2009-10-16 13:42 - 00002613 _____ C:\Users\Jarmila\Desktop\Microsoft Office Excel 2007.lnk
2013-10-24 15:42 - 2012-04-16 14:44 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-24 15:42 - 2012-04-16 14:44 - 00003766 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-24 15:42 - 2011-06-08 14:28 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-24 15:42 - 2009-10-16 13:59 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Adobe
2013-10-24 14:24 - 2006-11-02 14:33 - 00000000 ____D C:\Windows\rescache
2013-10-24 14:04 - 2013-09-28 09:05 - 00012571 _____ C:\Windows\setupact.log
2013-10-22 22:42 - 2013-10-22 22:42 - 00000000 ____D C:\Program Files\McAfee Security Scan
2013-10-22 22:42 - 2013-10-22 21:53 - 00001877 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2013-10-22 21:53 - 2013-10-22 21:53 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2013-10-22 17:00 - 2013-10-22 17:00 - 00000000 ____D C:\ProgramData\Oracle
2013-10-22 16:58 - 2013-10-22 16:57 - 00004746 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-22 16:58 - 2009-09-02 12:34 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-19 13:45 - 2012-08-11 04:53 - 00000000 ____D C:\Users\Jarmila\Documents\Nové Lublice
2013-10-19 07:07 - 2013-10-19 07:07 - 00915368 _____ (Oracle Corporation) C:\Users\Jarmila\Downloads\JavaSetup7u45.exe
2013-10-18 17:48 - 2013-04-10 08:16 - 00002054 _____ C:\Users\Jarmila\Desktop\Google Chrome.lnk
2013-10-16 20:07 - 2009-10-29 08:29 - 00000000 ____D C:\Users\Jarmila\Documents\Personální
2013-10-12 08:11 - 2009-10-16 14:03 - 00000000 ____D C:\Users\Jarmila\Documents\Inzerce
2013-10-11 13:54 - 2013-10-11 13:54 - 00000000 ____D C:\Users\Public\Documents\CrashDump
2013-10-10 18:47 - 2009-09-02 12:44 - 00000000 ____D C:\Program Files (x86)\Intel
2013-10-10 17:54 - 2006-11-02 16:21 - 00385040 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-10 17:21 - 2009-10-16 13:14 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-10-10 16:48 - 2013-07-23 18:02 - 00000000 ____D C:\Windows\system32\MRT
2013-10-10 16:43 - 2006-11-02 13:35 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-10-09 18:35 - 2010-06-26 14:25 - 00003950 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-09 18:35 - 2010-06-26 14:24 - 00003698 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-09 02:23 - 2013-07-02 19:56 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000UA
2013-10-09 02:23 - 2013-07-02 19:56 - 00003462 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000Core
2013-10-08 06:50 - 2013-10-22 16:58 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 06:46 - 2013-10-22 16:58 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 06:46 - 2013-10-22 16:58 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 06:46 - 2013-10-22 16:58 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-07 19:38 - 2013-10-07 19:38 - 00000000 ____D C:\Users\Public\Documents\NativeFus_Log
2013-10-07 19:38 - 2013-10-07 19:38 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Samsung
2013-10-07 19:38 - 2013-10-07 19:38 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Samsung
2013-10-07 19:37 - 2013-10-07 19:37 - 00001839 _____ C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2013-10-07 19:37 - 2013-10-07 19:37 - 00001829 _____ C:\Users\Public\Desktop\Samsung Kies.lnk
2013-10-07 19:37 - 2013-10-07 19:37 - 00000000 ____D C:\Users\Jarmila\Documents\samsung
2013-10-07 19:35 - 2013-10-07 19:24 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-10-07 19:33 - 2013-10-07 19:24 - 00000000 ____D C:\ProgramData\Samsung
2013-10-07 19:32 - 2013-10-07 19:32 - 00000000 ____D C:\Program Files (x86)\MyFree Codec
2013-10-07 19:27 - 2009-09-02 12:44 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-07 19:17 - 2013-10-07 19:17 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Downloaded Installations
2013-10-07 19:12 - 2013-10-07 19:08 - 00000000 ____D C:\Users\Jarmila\SAMSUNG
2013-10-02 15:49 - 2008-01-21 04:26 - 00075610 _____ C:\Windows\PFRO.log
2013-10-02 15:48 - 2010-06-26 14:24 - 00000000 ____D C:\Program Files\Google
2013-10-02 15:48 - 2010-06-26 14:23 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-02 12:19 - 2010-03-19 11:17 - 00107038 _____ C:\Windows\DPINST.LOG
2013-10-02 11:48 - 2010-03-19 11:06 - 00000000 ____D C:\ProgramData\Installations
2013-10-02 11:42 - 2013-10-02 11:41 - 60265144 _____ C:\Users\Jarmila\Downloads\R204603.exe
2013-10-02 11:34 - 2010-06-26 14:24 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Google
2013-10-02 11:34 - 2010-06-26 14:23 - 00000000 ____D C:\ProgramData\Google
2013-10-02 09:07 - 2009-10-16 14:03 - 00000000 ____D C:\Users\Jarmila\Documents\Zbyslavice
2013-09-30 12:38 - 2012-02-16 13:04 - 00000000 ____D C:\Users\Jarmila\Documents\EKOMA por.centrum 2012
2013-09-29 16:24 - 2012-12-18 12:09 - 00000217 _____ C:\Users\Jarmila\Desktop\http--en.eltiempo.es-torrevieja.html.url
2013-09-29 11:07 - 2011-07-15 11:28 - 00000000 ____D C:\Users\Jarmila\Documents\CITI BANK
2013-09-29 10:29 - 2009-10-16 14:03 - 00000000 ____D C:\Users\Jarmila\Documents\Marcel

Files to move or delete:
====================
C:\Users\Jarmila\AppData\Roaming\desktop.ini
C:\Users\Jarmila\Moje dovolená.exe
C:\Users\Public\AlexaNSISPlugin.22108.dll


Some content of TEMP:
====================
C:\Users\Jarmila\AppData\Local\Temp\BackupSetup.exe
C:\Users\Jarmila\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Jarmila\AppData\Local\Temp\jvd4ng2h.dll
C:\Users\Jarmila\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Jarmila\AppData\Local\Temp\ntdll_dump.dll
C:\Users\Jarmila\AppData\Local\Temp\oi_{CA9AA727-87B2-4E98-A888-21441E2CEFC2}.exe
C:\Users\Jarmila\AppData\Local\Temp\ose00000.exe
C:\Users\Jarmila\AppData\Local\Temp\SkypeSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-29 10:01

==================== End Of Log ============================
Jarmila

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#4 Příspěvek od vyosek »

:cap: Bude toho ted trosku vic, ale to zvladnete - hezky pekne pomalu a v klidu a postupne :| Pokud nebude neco jasneho, tak se ptejte :mrgreen:



--- Priprava a uklid zbytecnosti ---

:arrow: Avg je spise parodie na antivir :arcisit: Dame tam poradny bezpecnostni SW.

:arrow: Odinstalujte Avg a pak pouzijte jeste http://download.avg.com/filedir/util/su ... 4_4116.exe

:arrow: Odinstalujte jeste tyto doplnky a zbytecnosti
  • AVG PC Tuneup 2011
  • AVG SafeGuard toolbar
  • McAfee Security Scan Plus
  • RegClean Pro
  • MyPC Backup
:arrow: Nainstalujte Avast Free http://www.avast.com/get/gWR5mo92



--- Smazani bordelu ---

:arrow: Presunte si FRST64.exe z C:\Users\Jarmila\Downloads primo na Plochu

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
    HKCU\...\Run: [Google Update] - C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-07-02] (Google Inc.)
    HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-09-04] (Samsung)
    HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
    HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung)
    HKCU\...\Run: [WMPNSCFG] - C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
    MountPoints2: {f4693101-9437-11e1-87bc-002556e20ba3} - D:\.\Setup.exe AUTORUN=1
    HKLM-x32\...\Run: [PDVDDXSrv] - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128232 2009-02-05] (CyberLink Corp.)
    HKLM-x32\...\Run: [TQ566808] - "F:\Setup.exe"
    HKLM-x32\...\Run: [Print2PDF Print Monitor] - C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [222776 2011-04-12] (Software602)
    HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4908592 2013-10-07] (AVG Technologies CZ, s.r.o.)
    HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2404376 2013-10-29] ()
    Startup: C:\Users\Jarmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
    
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/defau ... l=cs&s=bsd
    StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
    SearchScopes: HKCU - DefaultScope {F348D141-5E2C-4E6B-9903-539AE406D7A4} URL = http://www.google.cz/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7SKPB_cs
    SearchScopes: HKCU - {6FEF6957-C8EC-43FF-9D10-0846C354B60C} URL = http://search.avg.com/route/?d=4e00e8e0 ... =chrome&q={searchTerms}&lng={language}&iy=&ychte=us
    SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={CDD25EE2-BF91-4139-8703-A70D9E513903}&mid=2183fcb0924a47d1a1dbd16c22b257d0-01bd4caeffe74203d83c06948b43a68c22950bda&lang=cs&ds=AVG&coid=avgtbavg&pr=pr&d=2013-10-29 09:13:48&v=17.0.0.12&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
    SearchScopes: HKCU - {F348D141-5E2C-4E6B-9903-539AE406D7A4} URL = http://www.google.cz/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7SKPB_cs
    BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
    BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
    Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.12\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
    Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search)
    
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
    
    R2 vToolbarUpdater17.0.12; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [1734680 2013-10-29] (AVG Secure Search)
    S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
    S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
    S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
    S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
    S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
    S3 Tablet2k; "%SystemRoot%\System32\Drivers\Tablet2k.sys" [x]
    
    2013-10-29 21:32 - 2013-10-29 21:33 - 01089183 _____ (Farbar) C:\Users\Jarmila\Downloads\FRST.exe
    2013-10-29 16:27 - 2013-10-29 16:27 - 00003044 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
    2013-10-29 16:27 - 2013-10-29 16:27 - 00002888 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
    2013-10-29 16:27 - 2013-10-29 16:27 - 00000288 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
    2013-10-29 16:27 - 2013-10-29 16:27 - 00000280 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
    2013-10-29 16:26 - 2013-10-29 20:42 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Systweak
    2013-10-29 16:26 - 2013-10-29 16:26 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
    2013-10-29 16:26 - 2013-10-29 16:26 - 00000891 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
    2013-10-29 16:26 - 2013-10-29 16:26 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
    2013-10-29 16:26 - 2013-09-17 11:25 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
    2013-10-29 09:16 - 2013-10-29 09:16 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\AVG2014
    2013-10-29 09:14 - 2013-10-29 09:14 - 00000886 _____ C:\Users\Public\Desktop\AVG 2014.lnk
    2013-10-29 09:14 - 2013-10-29 09:14 - 00000000 ____D C:\Users\Jarmila\AppData\Local\AVG SafeGuard toolbar
    2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\TuneUp Software
    2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
    2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
    2013-10-29 09:06 - 2013-10-29 09:15 - 00000000 ____D C:\ProgramData\AVG2014
    2013-10-29 09:06 - 2013-10-29 09:06 - 00000000 ___HD C:\$AVG
    2013-10-22 22:42 - 2013-10-22 22:42 - 00000000 ____D C:\Program Files\McAfee Security Scan
    2013-10-22 21:53 - 2013-10-22 22:42 - 00001877 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
    2013-10-22 21:53 - 2013-10-22 21:53 - 00000000 ____D C:\ProgramData\McAfee Security Scan
    2013-10-29 08:28 - 2013-10-29 09:42 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Avg2014
    2013-10-29 08:28 - 2013-10-29 08:28 - 00000000 ____D C:\Users\Jarmila\AppData\Local\MFAData
    C:\Program Files (x86)\Common Files\AVG Secure Search
    C:\Program Files (x86)\MyPC Backup
    C:\Users\Jarmila\AppData\Roaming\desktop.ini
    C:\Users\Jarmila\Moje dovolená.exe
    C:\Users\Public\AlexaNSISPlugin.22108.dll
    C:\Users\Jarmila\AppData\Local\Temp\BackupSetup.exe
    C:\Users\Jarmila\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
    C:\Users\Jarmila\AppData\Local\Temp\jvd4ng2h.dll
    C:\Users\Jarmila\AppData\Local\Temp\NOSEventMessages.dll
    C:\Users\Jarmila\AppData\Local\Temp\ntdll_dump.dll
    C:\Users\Jarmila\AppData\Local\Temp\oi_{CA9AA727-87B2-4E98-A888-21441E2CEFC2}.exe
    C:\Users\Jarmila\AppData\Local\Temp\ose00000.exe
    C:\Users\Jarmila\AppData\Local\Temp\SkypeSetup.exe
    
    AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000Core.job => C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000UA.job => C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe
    Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe
    
    Hosts:
    
    End
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jarmilaw
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 říj 2013 22:09

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#5 Příspěvek od jarmilaw »

OK, jdu na to. Ale ještě, prosím, než se do toho pustím, mám stále otevřený výsledek kontroly od Malwarebytes,který našel asi 180 kousků malware a já nevím, jestli mám kliknout na Odstranit vybrané nebo ignorovat. Tady je protokol :
Verze: v2013.10.29.08

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Jarmila :: JARMILA-NEWPC [administrátor]

Ochrana: Povolena

29.10.2013 19:16:30
Malwarebytes MBAM-log-2013-10-30 (07-53-25).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 207073
Uplynulý čas: 35 minut, 54 sekund

Nalezené procesy v paměti: 2
C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe (PUP.Optional.AdvancedSystemProtector.A) -> 14432 -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe (PUP.Optional.AmazonTB.A) -> 3568 -> Nebyla provedena žádná instrukce.

Nalezené moduly v paměti: 9
C:\Program Files (x86)\Advanced System Protector\aspsys.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Interop.IWshRuntimeLibrary.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Microsoft.Win32.TaskScheduler.DLL (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\scandll.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\System.Data.SQLite.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\unrar.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Xceed.Compression.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Xceed.FileSystem.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Xceed.Zip.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.

Nalezené klíče v registru: 21
HKCR\CLSID\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{008f6853-9cb4-41c5-a950-39d55e5e06ba} (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCR\TypeLib\{33D0AD98-3347-4A54-8929-5163EBEB9F72} (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{0923E315-2D8B-48CE-A37C-AE9A42F9711C} (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCR\AlxTB2.TBLayoutBHO.1 (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCR\AlxTB2.TBLayoutBHO (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{F443A627-5009-4323-9C1D-7FD598D0D712} (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCR\AlxTB2.AlxHelper.1 (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCR\AlxTB2.AlxHelper (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F443A627-5009-4323-9C1D-7FD598D0D712} (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1 (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IEXPLORE.EXE (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1 (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
HKCR\CLSID\{8D03FA45-4B8C-4427-BE67-EE8885147151} (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCR\Interface\{8D03FA45-4B8C-4427-BE67-EE8885147151} (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKLM\SYSTEM\CurrentControlSet\Services\Updater Service for AMZN (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Amazon Browser Settings (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCU\Software\Alexa Internet\Alexa9\Amazon (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
HKCU\Software\Distromatic\Toolbars (PUP.Optional.AlexaTB.A) -> Nebyla provedena žádná instrukce.
HKCU\Software\Systweak\Advanced System Protector (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
HKCU\Software\Systweak\RegClean Pro (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.

Nalezené hodnoty v registru: 2
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Data: -> Nebyla provedena žádná instrukce.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{EA582743-9076-4178-9AA6-7393FDF4D5CE} (PUP.Optional.AmazonTB.A) -> Data: -> Nebyla provedena žádná instrukce.

Nalezené datové položky v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené složky: 17
C:\Program Files (x86)\Advanced System Protector (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\clamunpack (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Troubleshooter (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Local\Amazon Browser Bar (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\2.1.1000.12150 (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\updates (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\2.1.1000.12150 (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\Backup (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\Logs (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro\Version 6.1 (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.

Nalezené soubory: 130
C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\Moje dovolená.exe (PUP.Optional.Bandoo) -> Nebyla provedena žádná instrukce.
C:\Windows\Tasks\RegClean Pro_UPDATES.job (PUP.Optional.RegCleanerPro.J) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\loading_withWhiteBG.avi (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe.config (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\AppResource.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\asp.ico (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\AspManager.exe (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\aspsys.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\categories.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Chinese_asp_ZH-CN.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Communication.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\danish_asp_DA.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\dutch_asp_NL.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\eng_asp_en.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\filetypehelper.exe (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Finnish_asp_FI.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\french_asp_FR.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\german_asp_DE.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Interop.IWshRuntimeLibrary.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\italian_asp_IT.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\japanese_asp_JA.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Microsoft.Win32.TaskScheduler.DLL (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\norwegian_asp_NO.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\portuguese_asp_PT-BR.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\russian_asp_ru.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\scandll.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\spanish_asp_ES.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\swedish_asp_SV.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\System.Core.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\System.Data.SQLite.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\unins000.dat (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\unins000.exe (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\unins000.msg (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\unrar.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Xceed.Compression.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Xceed.Compression.Formats.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Xceed.FileSystem.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Xceed.Zip.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\clamunpack\clamscan.exe (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\clamunpack\libclamav.dll (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\clamunpack\readme.txt (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Troubleshooter\asp-fixer.com (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Troubleshooter\asp-fixer.exe (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Troubleshooter\asp-fixer.pif (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Troubleshooter\asp-fixer.scr (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Troubleshooter\ASP-Troubleshooter.chm (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Troubleshooter\firefox.com (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Troubleshooter\iexplore.exe (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Advanced System Protector\Troubleshooter\iexplore.lnk (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\TraditionalCn_rcp_zh-tw.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Chinese_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\CleanSchedule.exe (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Cloud_Backup_Setup.exe (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Cloud_Backup_Setup_Intl.exe (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Danish_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Dutch_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\eng_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Finnish_rcp_fi.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\French_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\German_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\greek_rcp_el.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\install_left_image.bmp (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\isxdl.dll (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Italian_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Japanese_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\korean_rcp_ko.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Norwegian_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\polish_rcp_pl.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\portugese_rcp_pt.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Portuguese_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\RCPUninstall.exe (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\RegCleanPro.dll (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\russian_rcp_ru.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Spanish_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\Swedish_rcp.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\systweakasp.exe (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\turkish_rcp_tr.ini (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\unins000.dat (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\unins000.exe (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\unins000.msg (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\RegClean Pro\xmllite.dll (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Windows\Tasks\RegClean Pro_DEFAULT.job (PUP.Optional.RegCleanPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Local\Amazon Browser Bar\protect.xml (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.ini (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\AlxSSBPS.dll (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.Uninstall.exe (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBarSSB.3.0.dll (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\installer.xml (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\search_protect.exe (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\ToolbarUpdaterService.exe (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\uninstall.exe (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\uninstall.ico (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\uninstall.json (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\Program Files (x86)\Amazon Browser Bar\update.xml (PUP.Optional.AmazonTB.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\AddonSafelist (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\log.xslt (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\completedatabase.db (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\Cookies.bin (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\DigSign.bin (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\FilePaths.bin (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\FileSignature.bin (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\Folders.bin (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\Md5.bin (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\Registry.bin (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\SetupSign.bin (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\signatures\StrSetupSign.bin (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\updates\1545completedatabase.zip (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\updates\1552mupdate.zip (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\updates\1553update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\updates\1554update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\updates\1555update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\updates\1556update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\ProgramData\Systweak\Advanced System Protector\updates\1557update.zip (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\ASPStartupManagerErrorLog.txt (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\QDetail.db (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\Settings.db (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\Update.ini (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\2.1.1000.12150\ASPLog.txt (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\Logs\log_29-10-13_07-49-11.xml (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\Advanced System Protector\Logs\SMLog.xml (PUP.Optional.AdvancedSystemProtector.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\eng_rcp.dat (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\ExcludeList.rcp (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\log_10-29-2013.log (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\results.rcp (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\TempHLList.rcp (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000001.rmx (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.
C:\Users\Jarmila\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000001.rxb (PUP.Optional.RegCleanerPro.A) -> Nebyla provedena žádná instrukce.

(konec)
Jarmila

Uživatelský avatar
cernohous13
VIP in memoriam
VIP in memoriam
Příspěvky: 8721
Registrován: 09 pro 2006 06:19
Bydliště: Jablonec nad Nisou
Kontaktovat uživatele:

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#6 Příspěvek od cernohous13 »

Zdravím do oblasti Calpe,

než se ti ozve kolega, tak nejprve proveď podle jeho instrukce Fix v FRST (je tam většina šmejdů odstraňována)
a snad nebudou námitky, když pak provedeš nový scan MBAM :wink:
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím Obrázek

-------------------------------------------------------------------------------------------------
> Podpora fóra <

jarmilaw
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 říj 2013 22:09

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#7 Příspěvek od jarmilaw »

Dobrá, děkuji, jdu na návod a snad se brzy nezaseknu. Jinak, my jsme v Torrevieja, to je trošku jižněji než Calpe :103:

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#8 Příspěvek od vyosek »

Diky kolegovi za vstup :thumbsup:

Aplikujte ten FIXLIST jak bylo psano, na MBAM pak tez dojde :wink:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jarmilaw
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 říj 2013 22:09

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#9 Příspěvek od jarmilaw »

Tak jsem postupovala zdárně až po přesun frst64 na plochu. Při tom se mi někam ztratil a už není v počítači :evil: Takže jsem znovu stáhla FRST64,uložila na plochu, dala Scan a mám zase dva soubory v txt. Můžu teď pokračovat v návodu ? Tzn. otevřít poznámk. blok,atd? Nebo jsem něco zkazila? To jsou nervy :roll: Ale děkuji za trpělivost.Jarmila

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#10 Příspěvek od vyosek »

V poradku, znovu jste ten scan ani delat nemusela...

Nyni vytvorte ten fixlist a provedte opravu jak jsem psal...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jarmilaw
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 říj 2013 22:09

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#11 Příspěvek od jarmilaw »

A je to :
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 30-10-2013
Ran by Jarmila at 2013-10-30 13:57:18 Run:1
Running from C:\Users\Jarmila\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************


Start
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware] - "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKCU\...\Run: [Google Update] - C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-07-02] (Google Inc.)
HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564528 2013-09-04] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-09-04] (Samsung)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
MountPoints2: {f4693101-9437-11e1-87bc-002556e20ba3} - D:\.\Setup.exe AUTORUN=1
HKLM-x32\...\Run: [PDVDDXSrv] - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128232 2009-02-05] (CyberLink Corp.)
HKLM-x32\...\Run: [TQ566808] - "F:\Setup.exe"
HKLM-x32\...\Run: [Print2PDF Print Monitor] - C:\Program Files (x86)\Software602\Print2PDF\Print2PDF.exe [222776 2011-04-12] (Software602)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311152 2013-09-04] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2014\avgui.exe [4908592 2013-10-07] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [vProt] - C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2404376 2013-10-29] ()
Startup: C:\Users\Jarmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk

HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/defau ... l=cs&s=bsd
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - DefaultScope {F348D141-5E2C-4E6B-9903-539AE406D7A4} URL = http://www.google.cz/search?q={searchTe ... 1I7SKPB_cs
SearchScopes: HKCU - {6FEF6957-C8EC-43FF-9D10-0846C354B60C} URL = http://search.avg.com/route/?d=4e00e8e0 ... =chrome&q={searchTerms}&lng={language}&iy=&ychte=us
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={CDD ... 2013-10-29 09:13:48&v=17.0.0.12&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {F348D141-5E2C-4E6B-9903-539AE406D7A4} URL = http://www.google.cz/search?q={searchTe ... 1I7SKPB_cs
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\17.0.0.12\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.12\ViProtocol.dll (AVG Secure Search)

CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx

R2 vToolbarUpdater17.0.12; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe [1734680 2013-10-29] (AVG Secure Search)
S2 BackupStack; C:\Program Files (x86)\MyPC Backup\BackupStack.exe [38440 2013-09-19] (Just Develop It)
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 pccsmcfd; system32\DRIVERS\pccsmcfdx64.sys [x]
S3 Tablet2k; "%SystemRoot%\System32\Drivers\Tablet2k.sys" [x]

2013-10-29 21:32 - 2013-10-29 21:33 - 01089183 _____ (Farbar) C:\Users\Jarmila\Downloads\FRST.exe
2013-10-29 16:27 - 2013-10-29 16:27 - 00003044 _____ C:\Windows\System32\Tasks\RegClean Pro_UPDATES
2013-10-29 16:27 - 2013-10-29 16:27 - 00002888 _____ C:\Windows\System32\Tasks\RegClean Pro_DEFAULT
2013-10-29 16:27 - 2013-10-29 16:27 - 00000288 _____ C:\Windows\Tasks\RegClean Pro_UPDATES.job
2013-10-29 16:27 - 2013-10-29 16:27 - 00000280 _____ C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2013-10-29 16:26 - 2013-10-29 20:42 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\Systweak
2013-10-29 16:26 - 2013-10-29 16:26 - 00003108 _____ C:\Windows\System32\Tasks\RegClean Pro
2013-10-29 16:26 - 2013-10-29 16:26 - 00000891 _____ C:\Users\Public\Desktop\RegClean Pro.lnk
2013-10-29 16:26 - 2013-10-29 16:26 - 00000000 ____D C:\Program Files (x86)\RegClean Pro
2013-10-29 16:26 - 2013-09-17 11:25 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
2013-10-29 09:16 - 2013-10-29 09:16 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\AVG2014
2013-10-29 09:14 - 2013-10-29 09:14 - 00000886 _____ C:\Users\Public\Desktop\AVG 2014.lnk
2013-10-29 09:14 - 2013-10-29 09:14 - 00000000 ____D C:\Users\Jarmila\AppData\Local\AVG SafeGuard toolbar
2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\Users\Jarmila\AppData\Roaming\TuneUp Software
2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-10-29 09:13 - 2013-10-29 09:13 - 00000000 ____D C:\Program Files (x86)\AVG SafeGuard toolbar
2013-10-29 09:06 - 2013-10-29 09:15 - 00000000 ____D C:\ProgramData\AVG2014
2013-10-29 09:06 - 2013-10-29 09:06 - 00000000 ___HD C:\$AVG
2013-10-22 22:42 - 2013-10-22 22:42 - 00000000 ____D C:\Program Files\McAfee Security Scan
2013-10-22 21:53 - 2013-10-22 22:42 - 00001877 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2013-10-22 21:53 - 2013-10-22 21:53 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2013-10-29 08:28 - 2013-10-29 09:42 - 00000000 ____D C:\Users\Jarmila\AppData\Local\Avg2014
2013-10-29 08:28 - 2013-10-29 08:28 - 00000000 ____D C:\Users\Jarmila\AppData\Local\MFAData
C:\Program Files (x86)\Common Files\AVG Secure Search
C:\Program Files (x86)\MyPC Backup
C:\Users\Jarmila\AppData\Roaming\desktop.ini
C:\Users\Jarmila\Moje dovolená.exe
C:\Users\Public\AlexaNSISPlugin.22108.dll
C:\Users\Jarmila\AppData\Local\Temp\BackupSetup.exe
C:\Users\Jarmila\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Jarmila\AppData\Local\Temp\jvd4ng2h.dll
C:\Users\Jarmila\AppData\Local\Temp\NOSEventMessages.dll
C:\Users\Jarmila\AppData\Local\Temp\ntdll_dump.dll
C:\Users\Jarmila\AppData\Local\Temp\oi_{CA9AA727-87B2-4E98-A888-21441E2CEFC2}.exe
C:\Users\Jarmila\AppData\Local\Temp\ose00000.exe
C:\Users\Jarmila\AppData\Local\Temp\SkypeSetup.exe

AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000Core.job => C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000UA.job => C:\Users\Jarmila\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe

Hosts:

End
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\Malwarebytes Anti-Malware => Value not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\KiesPreload => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\KiesAirMessage => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f4693101-9437-11e1-87bc-002556e20ba3} => Key deleted successfully.
HKCR\CLSID\{f4693101-9437-11e1-87bc-002556e20ba3} => Key not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\PDVDDXSrv => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\TQ566808 => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Print2PDF Print Monitor => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\KiesTrayAgent => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => Value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\AVG_UI => Value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\vProt => Value deleted successfully.
C:\Users\Jarmila\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk not found.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\\Default => Value was restored successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6FEF6957-C8EC-43FF-9D10-0846C354B60C} => Key deleted successfully.
HKCR\CLSID\{6FEF6957-C8EC-43FF-9D10-0846C354B60C} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found.
HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F348D141-5E2C-4E6B-9903-539AE406D7A4} => Key deleted successfully.
HKCR\CLSID\{F348D141-5E2C-4E6B-9903-539AE406D7A4} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key deleted successfully.
HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} => Key not found.
HKCR\Wow6432Node\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} => Value not found.
HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
HKCR\Wow6432Node\PROTOCOLS\Handler\viprotocol => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl => Key deleted successfully.
C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx => Moved successfully.
vToolbarUpdater17.0.12 => Service deleted successfully.
BackupStack => Service not found.
IpInIp => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
pccsmcfd => Service deleted successfully.
Tablet2k => Service deleted successfully.
C:\Users\Jarmila\Downloads\FRST.exe => Moved successfully.
"C:\Windows\System32\Tasks\RegClean Pro_UPDATES" => File/Directory not found.
"C:\Windows\System32\Tasks\RegClean Pro_DEFAULT" => File/Directory not found.
"C:\Windows\Tasks\RegClean Pro_UPDATES.job" => File/Directory not found.
"C:\Windows\Tasks\RegClean Pro_DEFAULT.job" => File/Directory not found.
C:\Users\Jarmila\AppData\Roaming\Systweak => Moved successfully.
"C:\Windows\System32\Tasks\RegClean Pro" => File/Directory not found.
"C:\Users\Public\Desktop\RegClean Pro.lnk" => File/Directory not found.
"C:\Program Files (x86)\RegClean Pro" => File/Directory not found.
C:\Windows\system32\roboot64.exe => Moved successfully.
"C:\Users\Jarmila\AppData\Roaming\AVG2014" => File/Directory not found.
"C:\Users\Public\Desktop\AVG 2014.lnk" => File/Directory not found.
C:\Users\Jarmila\AppData\Local\AVG SafeGuard toolbar => Moved successfully.
C:\Users\Jarmila\AppData\Roaming\TuneUp Software => Moved successfully.
"C:\ProgramData\AVG SafeGuard toolbar" => File/Directory not found.
"C:\Program Files (x86)\AVG SafeGuard toolbar" => File/Directory not found.
"C:\ProgramData\AVG2014" => File/Directory not found.
"C:\$AVG" => File/Directory not found.
"C:\Program Files\McAfee Security Scan" => File/Directory not found.
"C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk" => File/Directory not found.
"C:\ProgramData\McAfee Security Scan" => File/Directory not found.
"C:\Users\Jarmila\AppData\Local\Avg2014" => File/Directory not found.
"C:\Users\Jarmila\AppData\Local\MFAData" => File/Directory not found.
C:\Program Files (x86)\Common Files\AVG Secure Search => Moved successfully.
C:\Program Files (x86)\MyPC Backup => Moved successfully.
C:\Users\Jarmila\AppData\Roaming\desktop.ini => Moved successfully.
C:\Users\Jarmila\Moje dovolená.exe => Moved successfully.
C:\Users\Public\AlexaNSISPlugin.22108.dll => Moved successfully.
C:\Users\Jarmila\AppData\Local\Temp\BackupSetup.exe => Moved successfully.
C:\Users\Jarmila\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe => Moved successfully.
C:\Users\Jarmila\AppData\Local\Temp\jvd4ng2h.dll => Moved successfully.
C:\Users\Jarmila\AppData\Local\Temp\NOSEventMessages.dll => Moved successfully.
C:\Users\Jarmila\AppData\Local\Temp\ntdll_dump.dll => Moved successfully.
C:\Users\Jarmila\AppData\Local\Temp\oi_{CA9AA727-87B2-4E98-A888-21441E2CEFC2}.exe => Moved successfully.
C:\Users\Jarmila\AppData\Local\Temp\ose00000.exe => Moved successfully.
C:\Users\Jarmila\AppData\Local\Temp\SkypeSetup.exe => Moved successfully.
C:\ProgramData\TEMP => ":0B4227B4" ADS removed successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1411844188-494998471-412337545-1000UA.job => Moved successfully.
C:\Windows\Tasks\RegClean Pro_DEFAULT.job not found.
C:\Windows\Tasks\RegClean Pro_UPDATES.job not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.


The system needs a manual reboot.

==== End of Fixlog ====
Jarmila

jarmilaw
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 říj 2013 22:09

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#12 Příspěvek od jarmilaw »

Jo a objevil se mi podezřelý email, ten AVAST může zkontrolovat emaily?
Jarmila

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#13 Příspěvek od vyosek »

:arrow: Podezrele maily moc nedoporucuji otevirat. Avast ma mailovy stit, ale jestli bude mit jej v databazi tezko odhadovat...Pokud tedy nevite jestli je duverny, tak bych jej neoteviral - hodne nakaz se siri prave pres maily

:arrow: Jdeme dale, je tam toho jeste dosti - cela zoo i s babkou pokladni :arcisit:

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

jarmilaw
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 říj 2013 22:09

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#14 Příspěvek od jarmilaw »

OK, tak tady to mám :
unkware Removal Tool (JRT) by Thisisu
Version: 6.0.7 (10.15.2013:3)
OS: Windows (TM) Vista Home Premium x64
Ran by Jarmila on st 30.10.2013 at 14:42:21,65
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\scripthelper.exe
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\secman.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\viprotocol.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\distromatic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"



~~~ Chrome

Successfully deleted: [Folder] C:\Users\Jarmila\appdata\local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 30.10.2013 at 15:00:45,73
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
a druhý :
AdwCleaner v3.010 - Report created 30/10/2013 at 15:20:27
# Updated 20/10/2013 by Xplode
# Operating System : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
# Username : Jarmila - JARMILA-NEWPC
# Running from : C:\Users\Jarmila\Desktop\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

[!] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
[!] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
[!] Folder Deleted : C:\Users\Alin\AppData\Roaming\Systweak
File Deleted : C:\Users\Jarmila\AppData\Local\Temp\Uninstall.exe

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1F02FB61-2BE5-4C16-8199-AEAA16EB0342}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Alexa Internet
Key Deleted : HKCU\Software\Myfree Codec
Key Deleted : HKLM\Software\Myfree Codec
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyFreeCodec

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16514


-\\ Google Chrome v

[ File : C:\Users\Jarmila\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [2916 octets] - [30/10/2013 15:13:18]
AdwCleaner[S0].txt - [2805 octets] - [30/10/2013 15:20:27]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2865 octets] ##########
Děkuji
Jarmila

jarmilaw
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 29 říj 2013 22:09

Re: Virus Policie-Španělsko-kam se mi schoval ?Je v notebook

#15 Příspěvek od jarmilaw »

Našel jste tam někde ten virus ? Nebo už není v počítači? Je možné,že zmizel,když jsem po jeho objevení stáhla ten AVG a ještě jsem se podívala na seznam Wirelesskeyview, na klíče, které jsem měla v počítači pro připojení k wifi a tam byl pod názvem Ministerio nějaký klíč a ten jsem odstranila?
Jarmila

Zamčeno