Stránka 1 z 1

ads by keep now

Napsal: 15 úno 2014 09:31
od Tarrant
Zdravím do počítače se mi dostal tenhle hnus.. všude mi skáčou reklamy a po pokusu to odstranit mi přestali funogovat některé stránky na internetu, které se ještě náhodně mění hodinu/den jdou pak zase nejdou a už mi to leze krkem..
Jsem pouze uživatel tak prosím polopatická vysvětlení co s tím :D
asi toho v počítači budu mít víc, ale jsem typ člověka co dokud to nějak funguje tak se o to moc nestará..

Děkuji za pomoc

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-02-2014 01
Ran by Míra at 2014-02-15 09:23:55
Running from C:\Users\Míra\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

1C Company\Space Rangers 2 - Reboot Add-on (x32 Version: - )
20Dollars2Surf 1.1 (x32 Version: - Galactic Brothers LTD)
4500_G510gm_Help (x32 Version: 000.0.439.000 - Hewlett-Packard) Hidden
4500G510gm (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden
4500G510gm_Software_Min (x32 Version: 000.0.423.000 - Hewlett-Packard) Hidden
4Story CZ 4.1.98 (x32 Version: - )
64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
7-Zip 9.20 (x32 Version: - )
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0 - Igor Pavlov)
ABBYY FineReader 11 (x32 Version: 11.0.289 - ABBYY)
Adobe AIR (x32 Version: 3.6.0.6090 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.6.0.6090 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 12 ActiveX (x32 Version: 12.0.0.44 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.44 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (x32 Version: 12.0.0.112 - Adobe Systems, Inc.)
AdobViewer (x32 Version: - AdoBViewweer)
Advanced SystemCare 3 (x32 Version: 3.3.1 - IObit)
Alps Pointing-device for VAIO (Version: - ALPS ELECTRIC CO., LTD.)
AndroidBarre M-B-v1.1 (x32 Version: - Agia3D)
AndroozBarre M-B-v2.12e (x32 Version: - Agia3D)
Armies of Exigo (x32 Version: 1.4 - US - ACTION, s.r.o.)
Ask Toolbar (x32 Version: 1.13.1.0 - Ask.com) <==== ATTENTION
ATI Catalyst Install Manager (Version: 3.0.750.0 - ATI Technologies, Inc.)
Audacity 2.0 (x32 Version: - Audacity Team)
Audio To MP3 Converter 1.00 (x32 Version: - )
Auto Mouse Clicker v3.4 (x32 Version: - MurGee Softwares)
avast! Free Antivirus (x32 Version: 8.0.1497.0 - AVAST Software)
AVS Media Player 3.1 (x32 Version: - Online Media Technologies Ltd.)
AVS Update Manager 1.0 (x32 Version: - Online Media Technologies Ltd.)
Babylon (x32 Version: - Babylon)
Badoo Desktop (x32 Version: 1.6.55.1183 - Badoo)
Balabolka (x32 Version: 2.05 - Ilya Morozov)
Barre v0.1 bęta (x32 Version: - Agia3D)
BatteryBar (remove only) (Version: - )
BearShare (x32 Version: 10.0.0.119267 - Musiclab, LLC)
BearShare (x32 Version: 10.0.0.119267 - Musiclab, LLC) Hidden
bet-at-home.com Poker (x32 Version: - Boss Media AB)
BrowserProtect (x32 Version: - Bit89 Inc) <==== ATTENTION
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
Bundled software uninstaller (x32 Version: - ) <==== ATTENTION
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2010.0113.2257.41150 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0113.2257.41150 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2010.0113.2257.41150 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2010.0113.2257.41150 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0113.2257.41150 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0113.2257.41150 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2010.0113.2257.41150 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2010.0113.2257.41150 - ATI) Hidden
CCC Help Czech (x32 Version: 2010.0113.2256.41150 - Název společnosti:) Hidden
CCC Help Danish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Dutch (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help English (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Finnish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help French (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help German (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Greek (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Italian (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Japanese (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Korean (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Polish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Russian (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Spanish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Swedish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Thai (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
CCC Help Turkish (x32 Version: 2010.0113.2256.41150 - ATI) Hidden
ccc-core-static (x32 Version: 2010.0113.2257.41150 - Název společnosti:) Hidden
ccc-utility64 (Version: 2010.0113.2257.41150 - ATI) Hidden
CCleaner (Version: 3.27 - Piriform)
Claro Chrome Toolbar (x32 Version: 1.0.0.2 - Claro) <==== ATTENTION
Czech Soccer Manager 2002 FE (x32 Version: - )
DAEMON Tools Lite (x32 Version: 4.48.1.0347 - Disc Soft Ltd)
Dead Surf (HKCU Version: 1.0.0.13 - Legend Edition)
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.372.000 - Hewlett-Packard) Hidden
DocMgr (x32 Version: 130.0.000.000 - Název společnosti:) Hidden
DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Dostihy 3000 deluxe 1.1 (x32 Version: - )
downloaiditkEEp (x32 Version: - doownloaDitkeEp) <==== ATTENTION
ESET Online Scanner v3 (x32 Version: - )
Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden
FilesFrog Update Checker (x32 Version: - ) <==== ATTENTION
Foxit Reader (x32 Version: 5.4.5.124 - Foxit Corporation)
Fraps (x32 Version: - )
Fritz10 Service Pack (x32 Version: 10.3 - Chessbase GmbH)
Full Tilt Poker (x32 Version: 4.57.7.WIN.FullTilt.COM - )
GIMP 2.8.0 (Version: 2.8.0 - The GIMP Team)
Google Earth (x32 Version: 7.1.2.2041 - Google)
Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.)
Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden
GotClip Downloader (x32 Version: - )
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Graboid Video 3.21 (x32 Version: 3.21 - Graboid Inc.)
Hamachi 1.0.2.5 (x32 Version: - )
Heroes of Might & Magic V: Hammers of Fate (x32 Version: - )
Heroes of Might and Magic V - Tribes of the East (x32 Version: - )
Heroes of Might and Magic V (x32 Version: - )
High Pulse (x32 Version: 1.00.0000 - High Pulse)
HP Officejet 4500 G510g-m (Version: 13.0 - HP)
HP Update (x32 Version: 4.000.011.006 - Hewlett-Packard)
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
Huawei Drivers (x32 Version: 4.25.00.00 - )
ICQ Toolbar (x32 Version: 3.0.0 - ICQ)
ICQ7.5 (x32 Version: 7.5 - ICQ)
ICQ7.7 (x32 Version: 7.7 - ICQ)
Icy Tower v1.5 (x32 Version: - Free Lunch Design)
iLivid (x32 Version: 1.92 - Bandoo Media Inc) <==== ATTENTION
iMesh (x32 Version: 11.0.0.121814 - iMesh Inc.)
iMesh (x32 Version: 11.0.0.121814 - iMesh Inc.) Hidden
Java 7 Update 17 (x32 Version: 7.0.170 - Oracle)
Java Auto Updater (x32 Version: 2.0.6.1 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 30 (x32 Version: 6.0.300 - Oracle)
JavaFX 2.0.2 (x32 Version: 2.0.2 - Oracle Corporation)
KyuubiBarre (x32 Version: - Kyuubi-System)
League of Legends (x32 Version: 1.3 - Riot Games)
Live Security Platinum (HKCU Version: - )
Macro Recorder (HKCU Version: 5.0.0.147 - Jitbit Macro Recorder)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 4 Client Profile FRA Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 CSY Language Pack (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 CSY Language Pack (Version: 4.5.50709 - Microsoft Corporation) Hidden
Microsoft Office Professional Edition 2003 (x32 Version: 11.0.6361.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft XML Parser (x32 Version: 8.70.1104.04 - Microsoft Corporation) Hidden
Might & Magic Heroes VI (x32 Version: 1.1.1 - Ubisoft)
Module linguistique Microsoft .NET Framework 4 Client Profile FRA (Version: 4.0.30319 - Microsoft Corporation)
Mozilla Firefox 27.0.1 (x86 cs) (x32 Version: 27.0.1 - Mozilla)
Mozilla Maintenance Service (x32 Version: 27.0.1 - Mozilla)
MyBrowserCash version 2.0 (x32 Version: 2.0 - Digital Paper Products, Inc)
Need for Speed™ Carbon (x32 Version: - )
Nero 8 (x32 Version: 8.10.281 - Nero AG)
neroxml (x32 Version: 1.0.0 - Nero AG) Hidden
Network64 (Version: 130.0.374.000 - Hewlett-Packard) Hidden
NoPayPOKER (x32 Version: - )
Norton Security Scan (x32 Version: 4.0.3.24 - Symantec Corporation)
Optimizer Pro v3.2 (x32 Version: - PC Utilities Software Limited) <==== ATTENTION
PackBarre (x32 Version: 4.0.6 - BPMconcept)
Pando Media Booster (x32 Version: 2.6.0.8 - Pando Networks Inc.)
ParadiseCasino (x32 Version: - )
ParadisePoker (x32 Version: - )
pipilajeux (HKCU Version: 1.2.0.3 - Legend Edition)
PlayMillion (x32 Version: - )
Plus500 (x32 Version: - )
Poker 770 (HKCU Version: - )
PokerStars (x32 Version: - PokerStars)
PokerStars.net (x32 Version: - PokerStars.net)
PokerStrategy.com SideKick (HKCU Version: 1.0.51227.1 - PokerStrategy.com)
ProShoPper (x32 Version: - ProShOppEER) <==== ATTENTION
Pub-PTP M-B-v2.02 Bęta (x32 Version: - Agia3D)
QuickTime (x32 Version: 7.69.80.9 - Apple Inc.)
RAR Password Cracker (x32 Version: 4.12 - dnSoft Research Group)
Retroz M-B-v1.1 (x32 Version: - Agia3D)
Rinse (uninstall) (x32 Version: - )
Sada Compatibility Pack pro systém Office 2007 (x32 Version: 12.0.6514.5001 - Microsoft Corporation)
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Scorpions WinCheater (x32 Version: - )
Seznam Software (HKCU Version: - Seznam.cz)
Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.)
Smart Fortress 2012 (HKCU Version: - )
SmartWebPrinting (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Software Bluetooth WIDCOMM (Version: 6.2.1.500 - Broadcom)
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
ssaaveRenEt (x32 Version: - ssAvEErnet)
Status (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Street-Ads Browser Enhancer (x32 Version: - )
Strip Poker Exclusive 4 (x32 Version: - Emotion Design)
SurfBarre GagneDuCash NET (HKCU Version: 1.0.0.7 - GagneDuCash NET)
TenDollars2Surf (x32 Version: - TenDollars2Surf.com)
The General 3.4 (x32 Version: - Sean O'Connor's Windows Games)
The Settlers III Gold Edition (x32 Version: - )
Tiny Media Player v1.0 (x32 Version: 1.0.0.0 - )
Tirocado M-B-v1.1 (x32 Version: - Agia3D)
T-Mobile Internet Manager (x32 Version: 2013-10-31@2013-12-02 - Gemfor s.r.o.)
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
Total Commander (Remove or Repair) (x32 Version: 7.50a - Ghisler Software GmbH)
Traktor 2 (x32 Version: 1.0 - TopQer, s.r.o.)
TrayApp (x32 Version: 130.0.376.000 - Hewlett-Packard) Hidden
TunesBarre version 1.2 (x32 Version: 1.2 - TunesBarre.Com)
TuneUp Utilities (x32 Version: 9.0.3000.136 - TuneUp Software)
TuneUp Utilities (x32 Version: 9.0.3000.136 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (en-US) (x32 Version: 9.0.3000.136 - TuneUp Software) Hidden
Ubisoft Game Launcher (x32 Version: 1.0.0.0 - UBISOFT)
Ulož.to File Manager verze 1.6 (x32 Version: 1.6 - Nodus Technologies s.r.o.)
Unity Web Player (HKCU Version: 2.6.1f3_31223 - Unity Technologies ApS)
VCRedistSetup (x32 Version: 1.0.0 - Nero AG) Hidden
Věčná cesta: Nová Atlantida. Sběratelská edice (x32 Version: 1.0.0.0 - Alawar Entertainment Inc.)
Virtual City Casino (x32 Version: 16.9.0.463 - )
VisioHits.EU v1.0.0 (x32 Version: - Agia3D)
VLC media player 1.0.1 (x32 Version: 1.0.1 - VideoLAN Team)
Vydělávej Počítačem.cz (HKCU Version: 1.0.0.19 - Jan Drozd software)
Warcraft II (DOSBox 0.74 emulation) (x32 Version: - )
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
William Hill Poker (HKCU Version: - )
Windows Driver Package - Broadcom Bluetooth (09/09/2009 6.2.0.9405) (Version: 09/09/2009 6.2.0.9405 - Broadcom)
Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
Youtube Downloader+Convertor (x32 Version: 1.0 - Sweet Plugins)
Z-Barre.com version 1.0 (x32 Version: 1.0 - Z-Barre.com)

==================== Restore Points =========================

09-01-2014 18:13:46 Naplánovaný kontrolní bod
30-01-2014 18:00:54 Naplánovaný kontrolní bod
31-01-2014 14:57:02 Windows Update
13-02-2014 16:16:22 Removed Rinse

==================== Scheduled Tasks (whitelisted) =============

Task: {075E8119-4CD1-4EC1-9764-A3C381DD41A0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-19] (Google Inc.)
Task: {1AB422AF-EF87-4DE4-9E7D-A439CD91BAAB} - System32\Tasks\Automatic troubleshooting => C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-18] (TuneUp Software)
Task: {2E00A18A-A60C-41E5-B173-D125C5D566B0} - System32\Tasks\Games\UpdateCheck_S-1-5-21-4030065873-1877617759-1629828243-1000
Task: {36218C01-79C1-4083-A67B-9B69EE1D3BD9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-04] (Adobe Systems Incorporated)
Task: {380C6B20-958D-491F-8BD7-2588796AE01C} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2009-07-14] (Microsoft Corporation)
Task: {3B3C4FBE-245C-4C3C-A9C2-1769CA337D72} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe <==== ATTENTION
Task: {3F6CCD56-DF3E-487C-B21C-E1B9D796396C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-19] (Google Inc.)
Task: {41B9A859-5134-4271-B9C2-A38B7201B4C0} - System32\Tasks\AVG\PC Tuneup 2011\Integrator\Start On Windows Logon => C:\Program Files (x86)\AVG\AVG PC Tuneup 2011\BoostSpeed.exe
Task: {5978EC2A-AA40-4538-83A3-02A529E49D07} - System32\Tasks\AWC Update => C:\Program Files (x86)\IObit\Advanced SystemCare 3\IObitUpdate.exe [2009-04-24] (IObit)
Task: {923AB2C6-3271-4AED-BF4D-EFE997EA5CA7} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-06-09] (Sun Microsystems, Inc.)
Task: {C31636B2-4F86-40D9-8A49-A57AAAC8D387} - System32\Tasks\Norton Security Scan for Míra => C:\Program Files (x86)\Norton Security Scan\Engine\4.0.3.24\Nss.exe [2013-08-19] (Symantec Corporation)
Task: {D00E6E18-EC97-43CE-AB92-FD979B40ACAE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software)
Task: {DD3BBC6D-17A0-42C4-84DB-8ED0E816756A} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd)
Task: {F1EBB7A9-786D-4485-864B-CBD4F01A33B1} - System32\Tasks\b4639068 => C:\Users\MRA~1\AppData\Local\Temp\\setup1897959432.exe <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AWC Update.job => C:\Program Files (x86)\IObit\Advanced SystemCare 3\IObitUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Norton Security Scan for Míra.job => C:\PROGRA~2\NORTON~2\Engine\403~1.24\Nss.exe

==================== Loaded Modules (whitelisted) =============

2014-02-14 23:15 - 2014-02-14 19:11 - 02272256 _____ () C:\Program Files\AVAST Software\Avast\defs\14021402\algo.dll
2013-10-11 01:31 - 2013-10-03 13:46 - 04203336 _____ () C:\Program Files (x86)\Optimizer Pro\OptProCrash.dll
2013-10-11 01:31 - 2013-10-11 01:31 - 00192152 _____ () C:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll
2014-02-14 20:09 - 2014-02-14 20:09 - 03578992 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-02-04 21:13 - 2014-02-04 21:13 - 16287624 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Windows\Temp:temp
AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4
AlternateDataStreams: C:\ProgramData\TEMP:364682BC
AlternateDataStreams: C:\ProgramData\TEMP:D2397415
AlternateDataStreams: C:\Users\Míra\Downloads:Shareaza.GUID
AlternateDataStreams: C:\Users\Míra\Desktop\Harry Potter and the Deathly Hallows Part 2 2011 TS READNFO XViD - IMAGiNE:Shareaza.GUID
AlternateDataStreams: C:\Users\Míra\Desktop\Heroes of Might and Magic V + Hammers of fate + Tribes of the east vše v cz dabingu:Shareaza.GUID

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== Disabled items from MSCONFIG ==============

MSCONFIG\Services: btwdins => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^20Dollars2Surf.lnk => C:\Windows\pss\20Dollars2Surf.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
MSCONFIG\startupreg: 4StoryPrePatch => C:\Program Files (x86)\Gameforge4D\4Story_CZ\PrePatch.exe
MSCONFIG\startupreg: adobeupdate => "C:\Users\Míra\AppData\Roaming\3 5\l3.lnk"
MSCONFIG\startupreg: adobeupdater => "C:\Users\Míra\AppData\Roaming\3 0\rundll32.exe"
MSCONFIG\startupreg: Badoo Desktop => C:\ProgramData\Badoo\Badoo Desktop\1.6.55.1183\Badoo.Desktop.exe
MSCONFIG\startupreg: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} => "C:\Program Files (x86)\Common Files\Nero\Lib\NMBgMonitor.exe"
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: FullBarre (http://www.argent-barre.com) => C:\Program Files\Full Web\FullBarre\Argent-Barre (www.argent-barre.com)\start.exe
MSCONFIG\startupreg: FullBarre (http://www.tipassbarre.com) => C:\Program Files\Full Web\FullBarre\TipassBarre (www.tipassbarre.com)\start.exe
MSCONFIG\startupreg: MyBrowserCash => C:\Program Files (x86)\MyBrowserCash\MyBrowserCash.exe
MSCONFIG\startupreg: PokerStrategy.com SideKick => "C:\Users\Míra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerStrategy.com\PokerStrategy.com SideKick.appref-ms"
MSCONFIG\startupreg: Regedit32 => C:\Windows\system32\regedit.exe
MSCONFIG\startupreg: SpyEmergency => C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe
MSCONFIG\startupreg: TaskMgr => C:\Users\Míra\AppData\Roaming\Microsoft\taskmgr.exe

==================== Faulty Device Manager Devices =============

Name: Síťový adaptér Ethernet
Description: Síťový adaptér Ethernet
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: Adaptér miniportu Microsoft Virtual WiFi
Description: Adaptér miniportu Microsoft Virtual WiFi
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Základní systémové zařízení
Description: Základní systémové zařízení
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/15/2014 09:00:24 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x000d0022
ID chybujícího procesu: 0x984
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3

Error: (02/15/2014 08:57:22 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00090022
ID chybujícího procesu: 0x7a0
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3

Error: (02/15/2014 08:54:20 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00090022
ID chybujícího procesu: 0x668
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3

Error: (02/15/2014 08:51:18 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00090022
ID chybujícího procesu: 0x984
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3

Error: (02/15/2014 08:48:16 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00090022
ID chybujícího procesu: 0xcc0
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3

Error: (02/15/2014 08:45:14 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x000d0022
ID chybujícího procesu: 0x1330
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3

Error: (02/15/2014 08:42:12 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00090022
ID chybujícího procesu: 0xfbc
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3

Error: (02/15/2014 08:39:10 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00090022
ID chybujícího procesu: 0x11a4
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3

Error: (02/15/2014 08:36:08 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00090022
ID chybujícího procesu: 0xd28
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3

Error: (02/15/2014 08:33:06 AM) (Source: Application Error) (User: )
Description: Název chybující aplikace: ping.exe, verze: 6.1.7600.16385, časové razítko: 0x4a5bc964
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00090022
ID chybujícího procesu: 0x6ac
Čas spuštění chybující aplikace: 0xping.exe0
Cesta k chybující aplikaci: ping.exe1
Cesta k chybujícímu modulu: ping.exe2
ID zprávy: ping.exe3


System errors:
=============
Error: (02/15/2014 09:23:23 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.

Error: (02/15/2014 09:20:42 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.

Error: (02/15/2014 09:19:56 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.

Error: (02/15/2014 09:16:21 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.

Error: (02/15/2014 09:14:31 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.

Error: (02/15/2014 09:12:35 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.

Error: (02/15/2014 09:10:06 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.

Error: (02/15/2014 09:08:18 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.

Error: (02/15/2014 09:05:54 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.

Error: (02/15/2014 09:04:30 AM) (Source: Microsoft-Windows-DNS-Client) (User: NT AUTHORITY)
Description: Při pokusu o načtení souboru místních hostitelů došlo k chybě.


Microsoft Office Sessions:
=========================
Error: (02/15/2014 09:00:24 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c0000005000d002298401cf2a23fa42b6e7C:\Windows\SysWOW64\ping.exeunknown38de96f1-9617-11e3-8891-ae1f0df21b8d

Error: (02/15/2014 08:57:22 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c0000005000900227a001cf2a238da467f1C:\Windows\SysWOW64\ping.exeunknowncc530cf1-9616-11e3-8891-ae1f0df21b8d

Error: (02/15/2014 08:54:20 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c00000050009002266801cf2a23212190a1C:\Windows\SysWOW64\ping.exeunknown5fc7d112-9616-11e3-8891-ae1f0df21b8d

Error: (02/15/2014 08:51:18 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c00000050009002298401cf2a22b4def793C:\Windows\SysWOW64\ping.exeunknownf3506b9e-9615-11e3-8891-ae1f0df21b8d

Error: (02/15/2014 08:48:16 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c000000500090022cc001cf2a224833890bC:\Windows\SysWOW64\ping.exeunknown86f58f44-9615-11e3-8891-ae1f0df21b8d

Error: (02/15/2014 08:45:14 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c0000005000d0022133001cf2a21dbdc081eC:\Windows\SysWOW64\ping.exeunknown1a639c8c-9615-11e3-8891-ae1f0df21b8d

Error: (02/15/2014 08:42:12 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c000000500090022fbc01cf2a216f5008ecC:\Windows\SysWOW64\ping.exeunknownadea3b40-9614-11e3-8891-ae1f0df21b8d

Error: (02/15/2014 08:39:10 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c00000050009002211a401cf2a2102d2aff1C:\Windows\SysWOW64\ping.exeunknown41740e50-9614-11e3-8891-ae1f0df21b8d

Error: (02/15/2014 08:36:08 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c000000500090022d2801cf2a20966a65e5C:\Windows\SysWOW64\ping.exeunknownd4e85d3f-9613-11e3-8891-ae1f0df21b8d

Error: (02/15/2014 08:33:06 AM) (Source: Application Error)(User: )
Description: ping.exe6.1.7600.163854a5bc964unknown0.0.0.000000000c0000005000900226ac01cf2a202a08d2b3C:\Windows\SysWOW64\ping.exeunknown6887182e-9613-11e3-8891-ae1f0df21b8d


CodeIntegrity Errors:
===================================
Date: 2014-02-15 07:51:40.052
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-02-13 17:25:53.795
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-02-13 06:35:45.378
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-02-13 06:27:56.134
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-02-10 16:34:14.363
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-02-08 11:30:05.787
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-02-06 16:49:05.801
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-02-04 19:33:55.085
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-02-02 17:50:11.054
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.

Date: 2014-02-01 15:49:07.290
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\wininet.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 52%
Total physical RAM: 3950.1 MB
Available physical RAM: 1878.22 MB
Total Pagefile: 7898.34 MB
Available Pagefile: 5648.31 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:297.99 GB) (Free:77.94 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: C2B5580D)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Re: ads by keep now

Napsal: 15 úno 2014 09:46
od Márty84
Zdravim :)

Tenhle log mi toho prilis nerekne. Potrebuji ten druhy, co se vytvoril, pripadne log z RSIT http://forum.viry.cz/viewtopic.php?f=13&t=130786

Ale jinak mate pravdu, podle seznamu programu tam bude poradny brajgl :boxed:

Re: ads by keep now

Napsal: 15 úno 2014 09:59
od Tarrant
ok tak tenhle už snad bude správně?

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-02-2014 01
Ran by Míra (administrator) on MÍRA-PC on 15-02-2014 09:23:16
Running from C:\Users\Míra\Desktop
Windows 7 Ultimate (X64) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\SysWOW64\ping.exe
(PC Utilities Pro) C:\Program Files (x86)\Optimizer Pro\OptProSmartScan.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_44.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9636896 2009-12-16] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [208384 2009-11-04] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-08-30] (AVAST Software)
Winlogon\Notify\klogon: %SystemRoot%\System32\klogon.dll [X]
HKLM\...\Policies\Explorer\Run: [25986] - C:\PROGRA~3\LOCALS~1\Temp\msvrvycxq.exe No File
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 1
HKLM\...\Policies\Explorer: [NoComputersNearMe] 0
HKLM\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\Run: [{851CD2CF-94D9-4ccc-AED8-6CB4EB39C1BE}] - C:\Windows\system32\rundll32.exe "C:\Users\Public\{851CD2CF-94D9-4ccc-AED8-6CB4EB39C1BE}.dll",AppStartup UserRun
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\Run: [Optimizer Pro] - C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [135672 2013-09-29] (PC Utilities Pro)
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 0
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\Policies\Explorer: [NoComputersNearMe] 0
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\MountPoints2: {473cbd9e-4f99-11e3-a891-c76b0ac5c6f0} - F:\Autorun.exe
HKU\S-1-5-21-4030065873-1877617759-1629828243-1000\...\MountPoints2: {473cbdac-4f99-11e3-a891-c76b0ac5c6f0} - F:\Autorun.exe
AppInit_DLLs: c:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL => C:\Program Files (x86)\Optimizer Pro\OptProCrash_x64.dll [4508488 2013-10-11] ()
AppInit_DLLs-x32: c:\progra~2\optimi~1\optpro~1.dll => C:\Program Files (x86)\Optimizer Pro\OptProCrash.dll [4203336 2013-10-03] ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... earchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.alawarhry.cz/?pid=22926
HKCU\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = http://www.claro-search.com/?affID=1201 ... dd08c6898b
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yambler.net
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://start.alawarhry.cz/?pid=22926
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM-x32 - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
URLSearchHook: HKLM-x32 - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
URLSearchHook: HKCU - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKCU - ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File
URLSearchHook: HKCU - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.claro-search.com/?q={searchT ... dd08c6898b
SearchScopes: HKCU - bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - Yahoo! URL = http://us.search.yahoo.com/search?p={se ... obit-trans
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = http://www.claro-search.com/?q={searchT ... dd08c6898b
SearchScopes: HKCU - {13884CD1-B20C-4D28-9210-AC47D133A777} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {23B2C7FF-F2A1-4F9E-80A9-0CE0008A3BA9} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
SearchScopes: HKCU - {2F58F36B-3923-4B9D-9D1E-542D1EDAFFAF} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {4315878C-B104-4C92-93C8-E8C41D33E811} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... earchTerms}
SearchScopes: HKCU - {8A244612-A1F7-11E0-95C0-E71F4824019B} URL = http://badoo.com/startpage/?source=bsb&q={searchTerms}
SearchScopes: HKCU - {9093ABBD-7EC8-4021-A981-795E740CE949} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKCU - {F557D84C-D0E5-4282-AFD2-09457B923385} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {F653A884-A066-4325-AD9F-28FD1E38E0F1} URL = http://www.firmy.cz/phr/{searchTerms}?s ... arch_13415
BHO: downloaiditkEEp - {1E056C92-C917-97C5-0696-5B2D4BFB7C3F} - C:\ProgramData\downloaiditkEEp\sg.x64.dll ()
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: No Name - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - No File
BHO: ProShoPper - {AF5CB4FD-CF28-D318-35DF-59AAB8E78400} - C:\ProgramData\ProShoPper\Y.x64.dll ()
BHO: AdobViewer - {B5515A28-DA7E-97F9-AED4-F06B4E501B10} - C:\ProgramData\AdobViewer\fhJtV2R.x64.dll ()
BHO: ssaaveRenEt - {CF15D959-89A4-9B73-2A95-A6FADF384366} - C:\ProgramData\ssaaveRenEt\IoAgj.x64.dll ()
BHO: No Name - {E33CF602-D945-461A-83F0-819F76A199F8} - No File
BHO-x32: downloaiditkEEp - {1E056C92-C917-97C5-0696-5B2D4BFB7C3F} - C:\ProgramData\downloaiditkEEp\sg.dll ()
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - No Name - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File

Hosts: Hosts file not detected in the default directory
Tcpip\..\Interfaces\{B663C248-0750-4CE1-A2D8-842D50E932A1}: [NameServer]

FireFox:
========
FF ProfilePath: C:\Users\Míra\AppData\Roaming\Mozilla\Firefox\Profiles\hjflje20.default-1392308365977
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Míra\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: downloaiditkEEp - C:\Users\Míra\AppData\Roaming\Mozilla\Firefox\Profiles\hjflje20.default-1392308365977\Extensions\cw.3io@voerbabwszc.org [2014-02-13]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-24]
FF HKCU\...\Firefox\Extensions: [{0F827075-B026-42F3-885D-98981EE7B1AE}] - C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension
FF Extension: BrowserProtect - C:\ProgramData\BrowserProtect\2.6.1095.52\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension [2013-03-07]

Chrome:
=======
CHR DefaultSearchKeyword: claro-search.com
CHR DefaultSearchProvider: Claro Search
CHR DefaultSearchURL: http://www.claro-search.com/?q={searchT ... dd08c6898b
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.76\pdf.dll No File
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U17) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.170.2) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Claro Toolbar) - C:\Users\Míra\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcillohgikpecbmgioknapdpcjofaafl [2013-07-06]
CHR Extension: (ssaaveRenEt) - C:\Users\Míra\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldkjeooobhameebfgbbjnmemipmeppim [2013-12-21]
CHR Extension: (Chrome In-App Payments service) - C:\Users\Míra\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-27]
CHR Extension: (downloaiditkEEp) - C:\Users\Míra\AppData\Local\Google\Chrome\User Data\Default\Extensions\picpacajcclmopafgfedcbjebaccnanb [2014-02-13]
CHR Extension: (ProShoPper) - C:\ProgramData\pbfkgnemejmabdaoddfonojppgocgcag [2013-12-22]
CHR HKCU\...\Chrome\Extension: [eibfgbclmgnmffinenpipoibfdoblond] - C:\Users\Míra\AppData\Roaming\Seznam.cz\bin\listicka-chrome-rv-1.5.5.crx [2013-12-22]
CHR HKCU\...\Chrome\Extension: [fkfpcckoflkdgjdobdkpclgngaahgbpi] - C:\Users\Míra\AppData\Roaming\Seznam.cz\bin\listicka-chrome-email-1.3.2.crx [2013-12-22]
CHR HKCU\...\Chrome\Extension: [ghoooididkjbjjldgojdgceoinbhbjmh] - C:\Users\Míra\AppData\Roaming\Seznam.cz\bin\listicka-chrome-slovnik-1.2.3.crx [2013-12-22]
CHR HKCU\...\Chrome\Extension: [mgoblimgpefkcahebgokneaadhahmdah] - C:\Users\Míra\AppData\Roaming\Seznam.cz\bin\Partner-1.2.0.crx [2013-12-22]
CHR HKLM-x32\...\Chrome\Extension: [dcillohgikpecbmgioknapdpcjofaafl] - C:\Users\Míra\AppData\Roaming\Claro\claro.crx [2012-11-01]
CHR HKLM-x32\...\Chrome\Extension: [egnimkioipookhfihpljiedpgjffibpa] - C:\Program Files (x86)\MyBrowserCash\MBC_chrome.crx [2012-02-03]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 70e6ca8c; C:\Program Files (x86)\Optimizer Pro\OptProCrashSvc.dll [192152 2013-10-11] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software)
R2 MbnExt; C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\MbnExt.dll [417128 2013-12-02] (Gemfor s.r.o.)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-10-23] (Nero AG)
S2 ABBYY.Licensing.FineReader.Professional.11.0; No ImagePath
S3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [X]
S2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [X]
S2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [X]
S2 MpsSvc; No ImagePath
S2 StarWindService; No ImagePath
S3 TuneUp.Defrag; No ImagePath
S2 TuneUp.ProgramStatisticsSvc; No ImagePath

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] ()
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] ()
R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-01-02] (Disc Soft Ltd)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [238080 2012-04-23] (Huawei Technologies Co., Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2014-01-02] (Duplex Secure Ltd.)
S3 vaxscsi; C:\Windows\System32\Drivers\vaxscsi.sys [259480 2012-04-13] (Alcohol Soft Co., Ltd.)
U3 aagmn78k; C:\Windows\System32\Drivers\aagmn78k.sys [0 ] (Microsoft Corporation)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 RTHDMIAzAudService; system32\drivers\RtHDMIVX.sys [X]
S1 {F5A06AB4-0F09-4328-B375-BF8E62264ACB}; \??\C:\Users\Public\{F5A06AB4-0F09-4328-B375-BF8E62264ACB}.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-15 09:23 - 2014-02-15 09:23 - 00018450 _____ () C:\Users\Míra\Desktop\FRST.txt
2014-02-15 09:22 - 2014-02-15 09:23 - 00000000 ____D () C:\FRST
2014-02-15 09:21 - 2014-02-15 09:21 - 02152960 _____ (Farbar) C:\Users\Míra\Desktop\FRST64.exe
2014-02-15 09:18 - 2014-02-15 09:18 - 00112107 _____ (forum.viry.cz) C:\Users\Míra\Desktop\VerzeOS.exe
2014-02-14 23:56 - 2014-02-15 00:53 - 00000000 ____D () C:\Users\Míra\Desktop\novy
2014-02-14 20:09 - 2014-02-14 20:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-13 22:04 - 2014-02-13 22:05 - 00000000 ____D () C:\ProgramData\downloaiditkEEp
2014-02-08 20:11 - 2014-02-09 00:18 - 714254890 _____ () C:\Users\Míra\Desktop\Bastardi-1.avi
2014-02-06 19:10 - 2014-02-06 19:10 - 01133552 _____ () C:\Users\Míra\Desktop\SteamSetup.exe
2014-02-02 01:13 - 2014-02-02 01:13 - 00437760 _____ () C:\Users\Míra\Desktop\setup(1).exe
2014-02-02 01:13 - 2014-02-02 01:13 - 00000334 _____ () C:\Users\Míra\Desktop\pipilajeux.appref-ms
2014-02-01 13:35 - 2014-02-01 13:36 - 00000000 ____D () C:\Users\Míra\Desktop\hudba
2014-02-01 11:01 - 2014-02-06 19:01 - 00000000 ____D () C:\Users\Míra\Desktop\barry
2014-01-31 15:57 - 2014-01-16 09:59 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-31 15:41 - 2014-02-15 00:58 - 00002458 __RSH () C:\ProgramData\ntuser.pol
2014-01-31 15:41 - 2014-01-31 15:41 - 00000000 ____D () C:\Users\Míra\AppData\Local\Packages
2014-01-31 15:41 - 2014-01-31 15:41 - 00000000 ____D () C:\ProgramData\jfdblnhikngbhfobejgdpjnojfemdabe
2014-01-31 15:41 - 2014-01-31 15:41 - 00000000 ____D () C:\ProgramData\AdobViewer
2014-01-21 00:14 - 2014-01-21 00:18 - 00000000 ____D () C:\Program Files (x86)\Czech Soccer Manager 2002 FE
2014-01-21 00:14 - 2014-01-21 00:14 - 00000000 ____D () C:\Users\Míra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Czech Soccer Manager 2002 FE
2014-01-18 18:54 - 2014-01-18 18:54 - 01142491 _____ () C:\Users\Míra\Desktop\Marilyn Manson - Sweet Dreams.mp3.rbs
2014-01-18 18:51 - 2014-01-18 19:01 - 00000000 ____D () C:\Users\Míra\Desktop\mp3
2014-01-17 17:13 - 2014-01-17 17:13 - 01069512 _____ (Solid State Networks) C:\Users\Míra\Desktop\install_flashplayer12x32au_mssa_aaa_aih.exe

==================== One Month Modified Files and Folders =======

2014-02-15 09:23 - 2014-02-15 09:23 - 00018450 _____ () C:\Users\Míra\Desktop\FRST.txt
2014-02-15 09:23 - 2014-02-15 09:22 - 00000000 ____D () C:\FRST
2014-02-15 09:21 - 2014-02-15 09:21 - 02152960 _____ (Farbar) C:\Users\Míra\Desktop\FRST64.exe
2014-02-15 09:18 - 2014-02-15 09:18 - 00112107 _____ (forum.viry.cz) C:\Users\Míra\Desktop\VerzeOS.exe
2014-02-15 09:13 - 2012-05-20 22:52 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-15 09:03 - 2012-08-16 12:49 - 00000000 ____D () C:\Users\Míra\AppData\Roaming\Skype
2014-02-15 08:57 - 2012-03-19 22:45 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-15 08:57 - 2012-03-19 22:45 - 00000944 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-15 07:58 - 2009-07-26 19:41 - 08779018 _____ () C:\Windows\system32\perfh005.dat
2014-02-15 07:58 - 2009-07-26 19:41 - 02988424 _____ () C:\Windows\system32\perfc005.dat
2014-02-15 07:58 - 2009-07-14 06:13 - 00006220 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-15 07:56 - 2009-07-14 05:45 - 00010016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-15 07:56 - 2009-07-14 05:45 - 00010016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-15 07:55 - 2011-05-09 18:38 - 00003962 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{8076581A-8459-48DE-9E95-6642E57CEA24}
2014-02-15 07:55 - 2011-05-09 18:13 - 01589816 _____ () C:\Windows\WindowsUpdate.log
2014-02-15 07:53 - 2013-08-10 16:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-15 07:51 - 2013-03-24 08:31 - 00026416 _____ () C:\Windows\setupact.log
2014-02-15 07:51 - 2011-06-03 21:28 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-02-15 07:51 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-15 01:09 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing
2014-02-15 01:07 - 2013-03-24 08:37 - 00000000 ____D () C:\Users\Míra\Desktop\plocha)
2014-02-15 00:58 - 2014-01-31 15:41 - 00002458 __RSH () C:\ProgramData\ntuser.pol
2014-02-15 00:53 - 2014-02-14 23:56 - 00000000 ____D () C:\Users\Míra\Desktop\novy
2014-02-14 20:09 - 2014-02-14 20:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-14 19:13 - 2013-03-24 08:47 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-02-14 06:27 - 2009-07-14 06:08 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-13 22:05 - 2014-02-13 22:04 - 00000000 ____D () C:\ProgramData\downloaiditkEEp
2014-02-13 22:05 - 2013-12-21 21:24 - 00000000 ____D () C:\ProgramData\95cc896e272bb098
2014-02-13 22:04 - 2011-05-16 12:54 - 00000000 ____D () C:\Users\Míra\AppData\Local\CrashDumps
2014-02-13 19:41 - 2013-03-07 00:32 - 00000000 ____D () C:\Users\Míra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserProtect
2014-02-13 19:34 - 2013-12-22 01:57 - 00000000 ____D () C:\ProgramData\ProShoPper
2014-02-13 19:34 - 2013-12-21 21:24 - 00000000 ____D () C:\ProgramData\ssaaveRenEt
2014-02-13 17:19 - 2013-12-31 06:41 - 00000000 ____D () C:\Users\Míra\Desktop\Původní data aplikace Firefox
2014-02-13 17:17 - 2012-05-01 19:14 - 00000000 ____D () C:\Program Files (x86)\Rinse
2014-02-13 16:37 - 2012-02-03 11:49 - 00874496 ___SH () C:\Users\Míra\Desktop\Thumbs.db
2014-02-10 22:34 - 2012-06-26 18:09 - 00000000 ____D () C:\Users\Míra\AppData\Roaming\vlc
2014-02-09 11:26 - 2011-08-27 23:03 - 00000000 ____D () C:\Users\Míra\AppData\Local\Deployment
2014-02-09 00:18 - 2014-02-08 20:11 - 714254890 _____ () C:\Users\Míra\Desktop\Bastardi-1.avi
2014-02-06 19:10 - 2014-02-06 19:10 - 01133552 _____ () C:\Users\Míra\Desktop\SteamSetup.exe
2014-02-06 19:01 - 2014-02-01 11:01 - 00000000 ____D () C:\Users\Míra\Desktop\barry
2014-02-04 21:13 - 2012-05-20 22:52 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-04 21:13 - 2012-05-20 22:52 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-04 21:13 - 2011-07-13 23:26 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-02 14:00 - 2012-07-01 20:44 - 00000000 ____D () C:\agia3d
2014-02-02 01:13 - 2014-02-02 01:13 - 00437760 _____ () C:\Users\Míra\Desktop\setup(1).exe
2014-02-02 01:13 - 2014-02-02 01:13 - 00000334 _____ () C:\Users\Míra\Desktop\pipilajeux.appref-ms
2014-02-02 01:13 - 2013-02-15 14:50 - 00000000 ____D () C:\Users\Míra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Legend Edition
2014-02-01 13:38 - 2011-10-21 10:02 - 00000000 ____D () C:\Users\Míra\AppData\Roaming\dvdcss
2014-02-01 13:36 - 2014-02-01 13:35 - 00000000 ____D () C:\Users\Míra\Desktop\hudba
2014-01-31 15:41 - 2014-01-31 15:41 - 00000000 ____D () C:\Users\Míra\AppData\Local\Packages
2014-01-31 15:41 - 2014-01-31 15:41 - 00000000 ____D () C:\ProgramData\jfdblnhikngbhfobejgdpjnojfemdabe
2014-01-31 15:41 - 2014-01-31 15:41 - 00000000 ____D () C:\ProgramData\AdobViewer
2014-01-31 15:41 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-01-31 15:41 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-01-29 22:26 - 2013-04-01 12:18 - 00000450 ____H () C:\Windows\Tasks\Norton Security Scan for Míra.job
2014-01-21 00:18 - 2014-01-21 00:14 - 00000000 ____D () C:\Program Files (x86)\Czech Soccer Manager 2002 FE
2014-01-21 00:14 - 2014-01-21 00:14 - 00000000 ____D () C:\Users\Míra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Czech Soccer Manager 2002 FE
2014-01-18 19:01 - 2014-01-18 18:51 - 00000000 ____D () C:\Users\Míra\Desktop\mp3
2014-01-18 18:54 - 2014-01-18 18:54 - 01142491 _____ () C:\Users\Míra\Desktop\Marilyn Manson - Sweet Dreams.mp3.rbs
2014-01-17 17:13 - 2014-01-17 17:13 - 01069512 _____ (Solid State Networks) C:\Users\Míra\Desktop\install_flashplayer12x32au_mssa_aaa_aih.exe
2014-01-16 09:59 - 2014-01-31 15:57 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

Files to move or delete:
====================
C:\ProgramData\ms057109EB.dat
C:\ProgramData\unrar.exe
C:\ProgramData\WKr2Uq5.dat


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

TDL4: custom:26000022 <===== ATTENTION!


LastRegBack: 2014-01-30 18:53

==================== End Of Log ============================v

Re: ads by keep now

Napsal: 15 úno 2014 10:18
od Márty84
:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe a ulozte na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: ads by keep now

Napsal: 16 úno 2014 17:12
od Tarrant
tak mi to jelo 8 hpdin v kuse pak jsme musel počítač vypnout.. není něco co by mohlo ten log udělt nějak rychleji nebo třeba zkusit rovnou nějaké programy a pokusit se to nějak odstranit?

Pomohlo by např kdybych přeinstaloval prohlížeč? nebo možná budu v brzké budoucnosti přinstalovávat celý počítač už by to chtělo..

Re: ads by keep now

Napsal: 16 úno 2014 19:28
od Márty84
A to porad bezelo, nebo se to seklo?

Zkuste spustit podle stejneho navodu, ale v nouzovem rezimu a s timto upravenym skriptem.

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
atapi.sys
autochk.exe
cdrom.sys
explorer.exe
hal.dll
scecli.dll
svchost.exe
tcpip.sys
userinit.exe
winlogon.exe
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s

Preinstalovani prohlizece mozna odstrani ten problem, nicmene svinstva je tam vice, takze to je nedostatecne (chvilkove) reseni. Preinstalovani systemu by zabralo, pokud tedy pujdou pryc i data, tedy kompletni format.

Re: ads by keep now

Napsal: 17 úno 2014 06:38
od Tarrant
pořád to běželo zkusím to v tom nouzovém režimu..

Re: ads by keep now

Napsal: 17 úno 2014 09:33
od Márty84
OK

Re: ads by keep now

Napsal: 17 úno 2014 15:37
od Tarrant
hmm tak jsme to nechal jet v nouzovým režimu a logy se mi nevytvořili :(

Re: ads by keep now

Napsal: 17 úno 2014 18:26
od Márty84
:arrow: Udelejte !!!kompletni!!! kontrolu s MBAM http://forum.viry.cz/viewtopic.php?f=29&t=115222 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: ads by keep now

Napsal: 18 úno 2014 16:13
od Tarrant
Tak jsme se nakonec rozhodl pro kompletní přeinstalování, ale moc nevím jak na to..
Resp. nějaké návody jsem si přečetl a případně se přes mobil mohu podívat během přeinstalování, ale mám jiný problém..

Jde o to že jsem při koupi NTB nedostal disk s instalačkou win7, ale na spodní straně NTB mám nálepku kde je poznamenán licenční klíč k aktivaci.. takže předpokládám že někde na disku ta instalačka bude bohužel nevim kde jí hledat? Mohli by jste mi s tímto poradit?

edit:// tak už mi poradili jinde díky za pomoc a rady :)

Re: ads by keep now

Napsal: 18 úno 2014 19:54
od Márty84
No nemate zac :D

Tak treba priste. Mejte se :bye:

:closed: