Vyskakující reklama na internetu
Napsal: 03 led 2014 09:56
Zdravím, mám problém s neustále vyskakujícími reklamami na internetu.
Používám FF 26.0, Win7.
Zde je log z Farbar Recovery Scanning Tool:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-11-2013 (ATTENTION: ====> FRST version is 40 days old and could be outdated)
Ran by Karek (administrator) on KAREK-PC on 03-01-2014 09:54:48
Running from C:\Users\Karek\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVG) C:\Program Files (x86)\AVG PC TuneUp 2014\TuneUpUtilitiesService64.exe
(AVG) C:\Program Files (x86)\AVG PC TuneUp 2014\TuneUpUtilitiesApp64.exe
(Celartem, Inc., doing business as Extensis.) C:\Program Files (x86)\Extensis\Suitcase Fusion 4\FMCore.exe
(Dropbox, Inc.) C:\Users\Karek\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\RunOnce: [20131224] - C:\Program Files\AVAST Software\Avast\setup\emupdate\11155dff-1ee8-425c-91ad-7283b136fb89.exe /check [181136 2014-01-03] (AVAST Software)
HKCU\...\Run: [FMCore.exe] - C:\Program Files (x86)\Extensis\Suitcase Fusion 4\FMCore.exe [9504768 2013-07-25] (Celartem, Inc., doing business as Extensis.)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_8_800_168_Plugin.exe -update plugin [815496 2013-09-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [747712 2013-11-26] ()
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-12-16] (AVAST Software)
Startup: C:\Users\Karek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Karek\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: WebSparkle - {9f56bab3-2739-40ed-a8d0-1451657a9742} - C:\Program Files (x86)\WebSparkle\WebSparkleBHO.dll No File
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{5F31578C-0FBE-44BE-8993-69BBDF586BD9}: [NameServer]213.46.172.36,213.46.172.37
FireFox:
========
FF ProfilePath: C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tightropeinteractive.com/Plugin - C:\Users\Karek\AppData\Local\TNT2\2.0.0.1599\npTNT2.dll (Search.Us.com)
FF Plugin HKCU: @tnt2ghost.com/Plugin - C:\Users\Karek\AppData\Local\TNT2\2.0.0.1599\npTNT2ghost.dll (Search.Us.com)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Seznam lištička - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: firebug - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\firebug@software.joehewitt.com.xpi
FF Extension: firefox - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\firefox@websparkle.biz.xpi
FF Extension: seo - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\seo@profesional.xpi
FF Extension: seostatus - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\seostatus@rubyweb.xpi
FF Extension: No Name - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\{35379F86-8CCB-4724-AE33-4278DE266C70}
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKCU\...\Firefox\Extensions: [sea-condensed@plugin.org] - C:\Program Files (x86)\The Sea App (Firefox)
FF Extension: The SEA App (C) - C:\Program Files (x86)\The Sea App (Firefox)
Chrome:
=======
CHR Extension: (Docs) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (YouTube) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (avast! Online Security) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2005.45_0
CHR Extension: (Google Wallet) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-16] (AVAST Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG PC TuneUp 2014\TuneUpUtilitiesService64.exe [2099000 2013-10-12] (AVG)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-12-16] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-12-16] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-12-16] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-16] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-12-16] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-12-16] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-12-16] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-16] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-08-31] ()
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG PC TuneUp 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software)
U3 assugv6m; C:\Windows\System32\Drivers\assugv6m.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U4 Update LinkSwift;
U4 Update WebSparkle;
U4 Util LinkSwift;
U4 Util WebSparkle;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-03 09:54 - 2014-01-03 09:54 - 00011696 _____ C:\Users\Karek\Desktop\FRST.txt
2013-12-20 09:49 - 2013-12-20 09:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-20 08:51 - 2013-12-20 08:51 - 00002764 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2013-12-18 11:42 - 2013-12-18 11:42 - 00000951 _____ C:\Users\Public\Desktop\Balsamiq Mockups.lnk
2013-12-18 11:42 - 2013-12-18 11:42 - 00000000 ____D C:\Users\Karek\AppData\Roaming\BalsamiqMockupsForDesktop.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1
2013-12-18 11:42 - 2013-12-18 11:42 - 00000000 ____D C:\Program Files (x86)\Balsamiq Mockups
2013-12-16 14:34 - 2013-12-16 14:34 - 00002164 _____ C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk
2013-12-16 14:34 - 2013-12-16 14:34 - 00000000 ____D C:\Users\Karek\AppData\Roaming\AVG
2013-12-16 14:34 - 2013-12-16 14:34 - 00000000 ____D C:\Program Files (x86)\AVG PC TuneUp 2014
2013-12-16 14:34 - 2013-10-12 00:34 - 00040248 _____ (AVG) C:\Windows\system32\TURegOpt.exe
2013-12-16 14:34 - 2013-10-12 00:33 - 00029496 _____ (AVG) C:\Windows\system32\authuitu.dll
2013-12-16 14:34 - 2013-10-12 00:33 - 00025400 _____ (AVG) C:\Windows\SysWOW64\authuitu.dll
2013-12-16 14:33 - 2013-12-20 08:51 - 00000000 ____D C:\ProgramData\AVG
2013-12-16 14:33 - 2013-12-16 14:33 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-16 14:32 - 2013-12-16 17:16 - 00000000 ____D C:\Users\Karek\AppData\Roaming\Orbit
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\ProgSense
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\GrabPro
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Program Files (x86)\Orbitdownloader
2013-12-16 14:21 - 2013-12-16 14:21 - 00000000 ____D C:\Program Files (x86)\DownloadToolz
2013-12-16 13:23 - 2013-12-16 13:23 - 00000000 ____D C:\Users\Karek\AppData\Roaming\AVAST Software
2013-12-16 13:22 - 2014-01-03 09:16 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-12-16 13:22 - 2013-12-16 13:22 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-16 13:22 - 2013-12-16 13:22 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-16 13:22 - 2013-12-16 13:22 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-16 13:19 - 2013-12-16 13:19 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-16 13:19 - 2013-12-16 13:19 - 00000000 ____D C:\Program Files\AVAST Software
2013-12-12 14:03 - 2013-12-12 14:03 - 00001103 _____ C:\Users\Karek\Desktop\SEO Administrator.lnk
2013-12-12 14:03 - 2013-06-05 10:45 - 00938496 _____ C:\Windows\SysWOW64\semtempl.dll
2013-12-12 14:03 - 2005-05-20 04:26 - 00343040 _____ C:\Windows\SysWOW64\arcdll.dll
2013-12-12 14:03 - 2004-06-14 16:19 - 00003072 _____ C:\Windows\SysWOW64\hashfunc.dll
2013-12-12 13:07 - 2013-12-12 13:07 - 00015327 _____ C:\Users\Karek\Desktop\LM.bat
2013-12-12 13:07 - 2013-11-25 08:41 - 01958440 _____ (Farbar) C:\Users\Karek\Desktop\FRST64.exe
==================== One Month Modified Files and Folders =======
2014-01-03 09:55 - 2014-01-03 09:54 - 00011696 _____ C:\Users\Karek\Desktop\FRST.txt
2014-01-03 09:52 - 2013-09-03 09:12 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-03 09:23 - 2009-07-14 05:45 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-03 09:23 - 2009-07-14 05:45 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-03 09:22 - 2011-04-12 09:34 - 00634308 _____ C:\Windows\system32\perfh005.dat
2014-01-03 09:22 - 2011-04-12 09:34 - 00122898 _____ C:\Windows\system32\perfc005.dat
2014-01-03 09:22 - 2009-07-14 06:13 - 01478586 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-03 09:19 - 2013-08-31 14:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-03 09:18 - 2013-08-31 14:44 - 00000000 ____D C:\Users\Karek\Documents\Soubory aplikace Outlook
2014-01-03 09:17 - 2013-11-27 16:07 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-03 09:17 - 2013-09-13 12:13 - 00000000 ____D C:\Users\Karek\AppData\Roaming\Dropbox
2014-01-03 09:17 - 2013-08-31 15:13 - 00000010 _____ C:\Users\Karek\AppData\Local\.HG88C586-G30G-2HE2-DGDE-8H3E1D530D30
2014-01-03 09:17 - 2013-08-31 15:13 - 00000010 _____ C:\ProgramData\.F464B91F-G49F-3G3D-CFCD-9G7D2C141C96
2014-01-03 09:16 - 2013-12-16 13:22 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2014-01-03 09:16 - 2013-11-27 16:07 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-03 09:16 - 2013-09-13 13:06 - 00000000 ___RD C:\Users\Karek\Dropbox
2014-01-03 09:15 - 2013-08-31 16:04 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-03 09:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-03 09:15 - 2009-07-14 05:51 - 00034138 _____ C:\Windows\setupact.log
2013-12-20 15:25 - 2013-11-26 17:20 - 00001298 _____ C:\Users\Karek\daemonprocess.txt
2013-12-20 15:25 - 2013-08-31 15:42 - 01735887 _____ C:\Windows\WindowsUpdate.log
2013-12-20 15:16 - 2013-09-24 13:30 - 00000000 ____D C:\Users\Karek\AppData\Roaming\Skype
2013-12-20 11:58 - 2013-09-24 08:54 - 00000000 ____D C:\seo projects
2013-12-20 09:49 - 2013-12-20 09:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-20 08:51 - 2013-12-20 08:51 - 00002764 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2013-12-20 08:51 - 2013-12-16 14:33 - 00000000 ____D C:\ProgramData\AVG
2013-12-19 10:04 - 2013-08-31 14:41 - 00136408 _____ C:\Users\Karek\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-19 09:12 - 2009-07-14 05:45 - 04199448 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-18 17:23 - 2013-09-02 08:25 - 00000000 ____D C:\Users\Karek\.ScreamingFrogSEOSpider
2013-12-18 11:42 - 2013-12-18 11:42 - 00000951 _____ C:\Users\Public\Desktop\Balsamiq Mockups.lnk
2013-12-18 11:42 - 2013-12-18 11:42 - 00000000 ____D C:\Users\Karek\AppData\Roaming\BalsamiqMockupsForDesktop.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1
2013-12-18 11:42 - 2013-12-18 11:42 - 00000000 ____D C:\Program Files (x86)\Balsamiq Mockups
2013-12-17 14:31 - 2013-09-02 13:34 - 00001480 _____ C:\Users\Karek\AppData\Local\Adobe Uložit pro web 13.0 Prefs
2013-12-17 08:58 - 2010-11-21 04:47 - 00014766 _____ C:\Windows\PFRO.log
2013-12-16 17:16 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\Orbit
2013-12-16 14:34 - 2013-12-16 14:34 - 00002164 _____ C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk
2013-12-16 14:34 - 2013-12-16 14:34 - 00000000 ____D C:\Users\Karek\AppData\Roaming\AVG
2013-12-16 14:34 - 2013-12-16 14:34 - 00000000 ____D C:\Program Files (x86)\AVG PC TuneUp 2014
2013-12-16 14:33 - 2013-12-16 14:33 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\ProgSense
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\GrabPro
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Program Files (x86)\Orbitdownloader
2013-12-16 14:32 - 2013-11-26 17:19 - 00000000 ____D C:\Users\Karek\AppData\Roaming\OpenCandy
2013-12-16 14:21 - 2013-12-16 14:21 - 00000000 ____D C:\Program Files (x86)\DownloadToolz
2013-12-16 13:23 - 2013-12-16 13:23 - 00000000 ____D C:\Users\Karek\AppData\Roaming\AVAST Software
2013-12-16 13:22 - 2013-12-16 13:22 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-16 13:22 - 2013-12-16 13:22 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-16 13:22 - 2013-12-16 13:22 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-16 13:19 - 2013-12-16 13:19 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-16 13:19 - 2013-12-16 13:19 - 00000000 ____D C:\Program Files\AVAST Software
2013-12-12 14:03 - 2013-12-12 14:03 - 00001103 _____ C:\Users\Karek\Desktop\SEO Administrator.lnk
2013-12-12 14:03 - 2013-09-02 08:18 - 00000000 ____D C:\ProgramData\SeoAdministrator
2013-12-12 14:03 - 2013-09-02 08:18 - 00000000 ____D C:\Program Files (x86)\seoadministrator
2013-12-12 13:07 - 2013-12-12 13:07 - 00015327 _____ C:\Users\Karek\Desktop\LM.bat
2013-12-12 13:07 - 2013-11-25 09:15 - 00000000 ____D C:\FRST
2013-12-10 13:12 - 2013-11-27 16:07 - 00003946 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-10 13:12 - 2013-11-27 16:07 - 00003694 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-10 09:19 - 2013-10-24 08:31 - 00000000 ____D C:\AdwCleaner
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-26 12:22
==================== End Of Log ============================
předem díky za radu.
Karel
Používám FF 26.0, Win7.
Zde je log z Farbar Recovery Scanning Tool:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-11-2013 (ATTENTION: ====> FRST version is 40 days old and could be outdated)
Ran by Karek (administrator) on KAREK-PC on 03-01-2014 09:54:48
Running from C:\Users\Karek\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVG) C:\Program Files (x86)\AVG PC TuneUp 2014\TuneUpUtilitiesService64.exe
(AVG) C:\Program Files (x86)\AVG PC TuneUp 2014\TuneUpUtilitiesApp64.exe
(Celartem, Inc., doing business as Extensis.) C:\Program Files (x86)\Extensis\Suitcase Fusion 4\FMCore.exe
(Dropbox, Inc.) C:\Users\Karek\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\RunOnce: [20131224] - C:\Program Files\AVAST Software\Avast\setup\emupdate\11155dff-1ee8-425c-91ad-7283b136fb89.exe /check [181136 2014-01-03] (AVAST Software)
HKCU\...\Run: [FMCore.exe] - C:\Program Files (x86)\Extensis\Suitcase Fusion 4\FMCore.exe [9504768 2013-07-25] (Celartem, Inc., doing business as Extensis.)
HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_8_800_168_Plugin.exe -update plugin [815496 2013-09-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [747712 2013-11-26] ()
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-12-16] (AVAST Software)
Startup: C:\Users\Karek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Karek\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Octh Class - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: WebSparkle - {9f56bab3-2739-40ed-a8d0-1451657a9742} - C:\Program Files (x86)\WebSparkle\WebSparkleBHO.dll No File
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll ()
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\..\Interfaces\{5F31578C-0FBE-44BE-8993-69BBDF586BD9}: [NameServer]213.46.172.36,213.46.172.37
FireFox:
========
FF ProfilePath: C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tightropeinteractive.com/Plugin - C:\Users\Karek\AppData\Local\TNT2\2.0.0.1599\npTNT2.dll (Search.Us.com)
FF Plugin HKCU: @tnt2ghost.com/Plugin - C:\Users\Karek\AppData\Local\TNT2\2.0.0.1599\npTNT2ghost.dll (Search.Us.com)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Seznam lištička - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
FF Extension: firebug - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\firebug@software.joehewitt.com.xpi
FF Extension: firefox - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\firefox@websparkle.biz.xpi
FF Extension: seo - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\seo@profesional.xpi
FF Extension: seostatus - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\seostatus@rubyweb.xpi
FF Extension: No Name - C:\Users\Karek\AppData\Roaming\Mozilla\Firefox\Profiles\bo3ol8i2.default\Extensions\{35379F86-8CCB-4724-AE33-4278DE266C70}
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKCU\...\Firefox\Extensions: [sea-condensed@plugin.org] - C:\Program Files (x86)\The Sea App (Firefox)
FF Extension: The SEA App (C) - C:\Program Files (x86)\The Sea App (Firefox)
Chrome:
=======
CHR Extension: (Docs) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (YouTube) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (avast! Online Security) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2005.45_0
CHR Extension: (Google Wallet) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Karek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-16] (AVAST Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG PC TuneUp 2014\TuneUpUtilitiesService64.exe [2099000 2013-10-12] (AVG)
==================== Drivers (Whitelisted) ====================
R2 aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [38984 2013-12-16] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [84328 2013-12-16] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-12-16] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-16] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1032416 2013-12-16] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [409832 2013-12-16] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [65264 2013-12-16] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-16] ()
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-08-31] ()
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG PC TuneUp 2014\TuneUpUtilitiesDriver64.sys [14112 2013-09-18] (TuneUp Software)
U3 assugv6m; C:\Windows\System32\Drivers\assugv6m.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
U4 Update LinkSwift;
U4 Update WebSparkle;
U4 Util LinkSwift;
U4 Util WebSparkle;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-03 09:54 - 2014-01-03 09:54 - 00011696 _____ C:\Users\Karek\Desktop\FRST.txt
2013-12-20 09:49 - 2013-12-20 09:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-20 08:51 - 2013-12-20 08:51 - 00002764 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2013-12-18 11:42 - 2013-12-18 11:42 - 00000951 _____ C:\Users\Public\Desktop\Balsamiq Mockups.lnk
2013-12-18 11:42 - 2013-12-18 11:42 - 00000000 ____D C:\Users\Karek\AppData\Roaming\BalsamiqMockupsForDesktop.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1
2013-12-18 11:42 - 2013-12-18 11:42 - 00000000 ____D C:\Program Files (x86)\Balsamiq Mockups
2013-12-16 14:34 - 2013-12-16 14:34 - 00002164 _____ C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk
2013-12-16 14:34 - 2013-12-16 14:34 - 00000000 ____D C:\Users\Karek\AppData\Roaming\AVG
2013-12-16 14:34 - 2013-12-16 14:34 - 00000000 ____D C:\Program Files (x86)\AVG PC TuneUp 2014
2013-12-16 14:34 - 2013-10-12 00:34 - 00040248 _____ (AVG) C:\Windows\system32\TURegOpt.exe
2013-12-16 14:34 - 2013-10-12 00:33 - 00029496 _____ (AVG) C:\Windows\system32\authuitu.dll
2013-12-16 14:34 - 2013-10-12 00:33 - 00025400 _____ (AVG) C:\Windows\SysWOW64\authuitu.dll
2013-12-16 14:33 - 2013-12-20 08:51 - 00000000 ____D C:\ProgramData\AVG
2013-12-16 14:33 - 2013-12-16 14:33 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-16 14:32 - 2013-12-16 17:16 - 00000000 ____D C:\Users\Karek\AppData\Roaming\Orbit
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\ProgSense
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\GrabPro
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Program Files (x86)\Orbitdownloader
2013-12-16 14:21 - 2013-12-16 14:21 - 00000000 ____D C:\Program Files (x86)\DownloadToolz
2013-12-16 13:23 - 2013-12-16 13:23 - 00000000 ____D C:\Users\Karek\AppData\Roaming\AVAST Software
2013-12-16 13:22 - 2014-01-03 09:16 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2013-12-16 13:22 - 2013-12-16 13:22 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-16 13:22 - 2013-12-16 13:22 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-16 13:22 - 2013-12-16 13:22 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-16 13:19 - 2013-12-16 13:19 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-16 13:19 - 2013-12-16 13:19 - 00000000 ____D C:\Program Files\AVAST Software
2013-12-12 14:03 - 2013-12-12 14:03 - 00001103 _____ C:\Users\Karek\Desktop\SEO Administrator.lnk
2013-12-12 14:03 - 2013-06-05 10:45 - 00938496 _____ C:\Windows\SysWOW64\semtempl.dll
2013-12-12 14:03 - 2005-05-20 04:26 - 00343040 _____ C:\Windows\SysWOW64\arcdll.dll
2013-12-12 14:03 - 2004-06-14 16:19 - 00003072 _____ C:\Windows\SysWOW64\hashfunc.dll
2013-12-12 13:07 - 2013-12-12 13:07 - 00015327 _____ C:\Users\Karek\Desktop\LM.bat
2013-12-12 13:07 - 2013-11-25 08:41 - 01958440 _____ (Farbar) C:\Users\Karek\Desktop\FRST64.exe
==================== One Month Modified Files and Folders =======
2014-01-03 09:55 - 2014-01-03 09:54 - 00011696 _____ C:\Users\Karek\Desktop\FRST.txt
2014-01-03 09:52 - 2013-09-03 09:12 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-03 09:23 - 2009-07-14 05:45 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-03 09:23 - 2009-07-14 05:45 - 00021664 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-03 09:22 - 2011-04-12 09:34 - 00634308 _____ C:\Windows\system32\perfh005.dat
2014-01-03 09:22 - 2011-04-12 09:34 - 00122898 _____ C:\Windows\system32\perfc005.dat
2014-01-03 09:22 - 2009-07-14 06:13 - 01478586 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-03 09:19 - 2013-08-31 14:10 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2014-01-03 09:18 - 2013-08-31 14:44 - 00000000 ____D C:\Users\Karek\Documents\Soubory aplikace Outlook
2014-01-03 09:17 - 2013-11-27 16:07 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-03 09:17 - 2013-09-13 12:13 - 00000000 ____D C:\Users\Karek\AppData\Roaming\Dropbox
2014-01-03 09:17 - 2013-08-31 15:13 - 00000010 _____ C:\Users\Karek\AppData\Local\.HG88C586-G30G-2HE2-DGDE-8H3E1D530D30
2014-01-03 09:17 - 2013-08-31 15:13 - 00000010 _____ C:\ProgramData\.F464B91F-G49F-3G3D-CFCD-9G7D2C141C96
2014-01-03 09:16 - 2013-12-16 13:22 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2014-01-03 09:16 - 2013-11-27 16:07 - 00000946 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-03 09:16 - 2013-09-13 13:06 - 00000000 ___RD C:\Users\Karek\Dropbox
2014-01-03 09:15 - 2013-08-31 16:04 - 00000000 ____D C:\ProgramData\NVIDIA
2014-01-03 09:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-03 09:15 - 2009-07-14 05:51 - 00034138 _____ C:\Windows\setupact.log
2013-12-20 15:25 - 2013-11-26 17:20 - 00001298 _____ C:\Users\Karek\daemonprocess.txt
2013-12-20 15:25 - 2013-08-31 15:42 - 01735887 _____ C:\Windows\WindowsUpdate.log
2013-12-20 15:16 - 2013-09-24 13:30 - 00000000 ____D C:\Users\Karek\AppData\Roaming\Skype
2013-12-20 11:58 - 2013-09-24 08:54 - 00000000 ____D C:\seo projects
2013-12-20 09:49 - 2013-12-20 09:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-20 08:51 - 2013-12-20 08:51 - 00002764 _____ C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2013-12-20 08:51 - 2013-12-16 14:33 - 00000000 ____D C:\ProgramData\AVG
2013-12-19 10:04 - 2013-08-31 14:41 - 00136408 _____ C:\Users\Karek\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-19 09:12 - 2009-07-14 05:45 - 04199448 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-18 17:23 - 2013-09-02 08:25 - 00000000 ____D C:\Users\Karek\.ScreamingFrogSEOSpider
2013-12-18 11:42 - 2013-12-18 11:42 - 00000951 _____ C:\Users\Public\Desktop\Balsamiq Mockups.lnk
2013-12-18 11:42 - 2013-12-18 11:42 - 00000000 ____D C:\Users\Karek\AppData\Roaming\BalsamiqMockupsForDesktop.EDE15CF69E11F7F7D45B5430C7D37CC6C3545E3C.1
2013-12-18 11:42 - 2013-12-18 11:42 - 00000000 ____D C:\Program Files (x86)\Balsamiq Mockups
2013-12-17 14:31 - 2013-09-02 13:34 - 00001480 _____ C:\Users\Karek\AppData\Local\Adobe Uložit pro web 13.0 Prefs
2013-12-17 08:58 - 2010-11-21 04:47 - 00014766 _____ C:\Windows\PFRO.log
2013-12-16 17:16 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\Orbit
2013-12-16 14:34 - 2013-12-16 14:34 - 00002164 _____ C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk
2013-12-16 14:34 - 2013-12-16 14:34 - 00000000 ____D C:\Users\Karek\AppData\Roaming\AVG
2013-12-16 14:34 - 2013-12-16 14:34 - 00000000 ____D C:\Program Files (x86)\AVG PC TuneUp 2014
2013-12-16 14:33 - 2013-12-16 14:33 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\ProgSense
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Users\Karek\AppData\Roaming\GrabPro
2013-12-16 14:32 - 2013-12-16 14:32 - 00000000 ____D C:\Program Files (x86)\Orbitdownloader
2013-12-16 14:32 - 2013-11-26 17:19 - 00000000 ____D C:\Users\Karek\AppData\Roaming\OpenCandy
2013-12-16 14:21 - 2013-12-16 14:21 - 00000000 ____D C:\Program Files (x86)\DownloadToolz
2013-12-16 13:23 - 2013-12-16 13:23 - 00000000 ____D C:\Users\Karek\AppData\Roaming\AVAST Software
2013-12-16 13:22 - 2013-12-16 13:22 - 01032416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00409832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2013-12-16 13:22 - 2013-12-16 13:22 - 00205320 _____ C:\Windows\system32\Drivers\aswVmm.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00092544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00084328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00065776 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00065264 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2013-12-16 13:22 - 2013-12-16 13:22 - 00038984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys
2013-12-16 13:22 - 2013-12-16 13:22 - 00001966 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-16 13:19 - 2013-12-16 13:19 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-16 13:19 - 2013-12-16 13:19 - 00000000 ____D C:\Program Files\AVAST Software
2013-12-12 14:03 - 2013-12-12 14:03 - 00001103 _____ C:\Users\Karek\Desktop\SEO Administrator.lnk
2013-12-12 14:03 - 2013-09-02 08:18 - 00000000 ____D C:\ProgramData\SeoAdministrator
2013-12-12 14:03 - 2013-09-02 08:18 - 00000000 ____D C:\Program Files (x86)\seoadministrator
2013-12-12 13:07 - 2013-12-12 13:07 - 00015327 _____ C:\Users\Karek\Desktop\LM.bat
2013-12-12 13:07 - 2013-11-25 09:15 - 00000000 ____D C:\FRST
2013-12-10 13:12 - 2013-11-27 16:07 - 00003946 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-10 13:12 - 2013-11-27 16:07 - 00003694 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-10 09:19 - 2013-10-24 08:31 - 00000000 ____D C:\AdwCleaner
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-26 12:22
==================== End Of Log ============================
předem díky za radu.
Karel